Cybercrime in Africa: what the 2026 INTERPOL report really tells organisations
Published in June 2026, theAfrican Cyberthreat Assessment Report from INTERPOL aggregates responses from thirty-six African countries together with telemetry from private partners. It has been commented on for its figures. Its real value lies in what it says about the law : its introduction approaches the threat not through technology but through the state of the legislation, the maturity of specialised units and the degree of accession to international conventions.
The diagnosis fits in a single sentence, which the report applies to data breaches: they "are not a technical failure, they are a governance failure". The bulk of the remedies therefore lie in rules, contracts and organisation, not in tooling.
A report that speaks law before it speaks technology
Where one might have expected an inventory of malware, INTERPOL opens with a survey of the legal landscape. Four responding countries out of five have a dedicated cybercrime statute ; the rest rely on ageing general provisions. But legislation alone is not enough: what sets resilient states apart is specialised national units, digital forensics laboratories and judges trained in electronic evidence. A properly equipped criminal justice chain, not an isolated statute.
2025 bore this out: seventeen countries adopted or amended cyber legislation. Côte d'Ivoire passed a digital security law aligned with international standards; Zambia defined online harassment, data protection and digital fraud; Mauritius created a national cyber-resilience agency; Angola, a national cybersecurity centre with regulatory powers. Cybersecurity is migrating from the technical register to that of enforceable rules.
The threat map, and what it reveals about the applicable law
Figure 1 calls for a legal reading. The top three categories (online scams, sextortion and cyberharassment, identity theft and financial fraud) account for close to half of reported cases. These are precisely the offences whose definitions vary most: some jurisdictions still exclude cryptojacking, online harassment, deepfake production or online human trafficking. So many legal safe havens for networks that relocate their operations within days.
West Africa is the continent's most active region for business email compromise. Under Operation Sentinel, the report documents an attempted diversion of $7.9 million targeting an oil company from Senegal; the receiving account was frozen in time. Cape Verde and Nigeria are among the countries most exposed to ransomware, and almost every respondent reports mobile money fraud.
"So long as data protection is not treated as a national security imperative (with enforceable standards, independent oversight and mandatory notification) every digital service in Africa will remain a potential point of entry."
2026 INTERPOL report, chapter on data breaches.
Three international instruments, one shared imperative of harmonisation
The report is organised around three instruments. The Malabo Convention of the African Union, to which several national statutes now refer explicitly. The Budapest Convention, to which only thirteen African states are parties and whose most useful mechanisms remain unevenly operational. Finally, the United Nations Convention against Cybercrime, signed in Hanoi in October 2025 and already signed by twenty-one African states.
Their existence settles nothing. The gap between accession and implementation is widening: no unified regional framework for exchanging digital evidence, mutual legal assistance slowed by uncertain points of contact, retention periods that diverge from one operator to the next. Close to a third of countries are calling for urgent reform on digital evidence, cross-border access to data and the criminalisation of AI-enabled fraud.
Data protection authorities and cybersecurity authorities: the missing link
In most states, two regulators coexist: thenational data protection authority, which supervises the lawfulness and security of processing, and thenational cybersecurity agency or the national incident response team, which handles the threat. Their cooperation with law enforcement is rated high in East Africa, moderate in West Africa, uneven in Southern Africa and little developed in Central Africa; standardised procedures for handing over evidence are almost everywhere lacking.
For a business, the consequence is direct: a single incident triggers two regimes. An intrusion followed by the exfiltration of client files is at once a security incident, notifiable to the competent agency, and a personal data breach, notifiable to the protection authority, with distinct deadlines, recipients and content. Those that cope are the ones handling both strands in a single case file.
A data breach is not an outage; it is a failure of governance
The vulnerabilities exploited in 2025 were "neither exotic nor new": unpatched routers, vulnerable virtual private networks, misconfigured document platforms, all publicly documented. The leak that exposed half a million customers of a Namibian telecoms operator came down to an administration portal reachable from the public internet.
This data feeds everything else: African-origin content is growing sharply on underground marketplaces, identity documents, SIM card codes, banking credentials, mobile money accounts. A breach is never an isolated event; it is the raw material of the frauds to come. The question is no longer whether the organisation was a "victim", but whether it implemented the appropriate technical and organisational measures that every piece of legislation in the region already requires of it.
AI shifts the boundary between lawfulness and security
More than one case in two involves artificial intelligence. The most destabilising use is not autonomous malware but thesynthetic identity : fabricated personas capable of defeating biometric checks and know-your-customer procedures. In legal terms the blow is twofold, since it undermines both the effectiveness of identity verification and the very justification for the biometric processing meant to deliver it. Anyone collecting biometric data on the basis that it is more reliable must now be able to demonstrate as much.
Hence INTERPOL's recommendation: build capability against adversarial AI rather than buy tools, recognising a synthetic voice, a forged identity, an automated phishing pattern. It converges with a classic obligation, the documented awareness training of exposed personnel, whose importance a large share of incidents in Central and West Africa serves to underline.
What this changes in practice for your organisation
A threat report is only worth what it translates into obligations. Six workstreams emerge from INTERPOL's findings, to be taken forward now under a combined data and cybersecurity regime:
- Map processing activities and the exposed attack surface. The record of processing activities on one side, the inventory of exposed interfaces and administrator accounts on the other: the two must be read together.
- Write a single incident procedure with two outputs. Who characterises the incident, who notifies the data protection authority, who notifies the cybersecurity agency, within what deadlines, and with what evidence of diligence.
- Frame processor obligations contractually. Responsibility cannot be outsourced: security obligations must be stipulated, auditable and coupled with notification deadlines.
- Secure cross-border data flows and check the formalities required in every jurisdiction where you operate.
- Formalise anti-fraud controls on payment transfers (dual authorisation for any change of bank details, confirmation through a channel other than email) and document the training of finance teams.
- Check your sectoral status. Operators of essential services, electronic communications, financial institutions, virtual asset service providers: audit, retention and reporting regimes accumulate.
The legal fragmentation INTERPOL denounces explains the importance of regional initiatives: the revision of the ECOWAS supplementary act on data protection, adopted on 19 July 2026, and the regional cybersecurity coordination mechanism approved at the same summit, answer it point by point.
Data drawn from theINTERPOL African Cyberthreat Assessment Report 2026 (June 2026), based on responses from 36 African countries for 2025. These reflect reported incidents: the report notes that under-reporting remains substantial.
Where do you really stand?
Assess the maturity of your framework in ten minutes and leave with a prioritised action plan.
Take the self-assessmentAMELEGAL can support you
Mapping processing activities and the exposed attack surface, an incident procedure linking data protection and cybersecurity, processor contracts, framing cross-border flows, formalities before national authorities, appointing and training the officer, and preparing for sectoral regimes.
Source: INTERPOL, African Cyberthreat Assessment Report 2026, June 2026. Figure 1 translated by AMELEGAL. This article provides general information and does not constitute legal advice. AMELEGAL