By TechBytes Africa Staff
INTERPOL published its African Cyberthreat Assessment Report 2026 on Monday from Lyon, and the headline figure has travelled fast: artificial intelligence is enabling 55% of reported cybercrimes across the continent. The 40 page assessment draws on survey data from 36 African member countries and describes a shift from isolated criminal incidents to what it calls an industrialised, borderless ecosystem.
The financial number is worse than the percentage. Cybercrime losses in Africa have more than doubled since 2024, from US$192 million to US$484 million, driven primarily by AI facilitated scams, credential harvesting and automated social engineering.
But the most consequential paragraph in the report has been largely skipped in the coverage so far, and it is the one Zimbabwean banks, mobile money operators and lenders should read twice.
Criminals have stopped stealing identities and started manufacturing them
The report finds that attackers have moved beyond stealing existing credentials to creating entirely synthetic identities. By combining real personal data with fabricated elements, these AI generated digital personas can defeat even advanced biometric verification systems. INTERPOL states they have been used to open bank accounts, secure mobile loans and register SIM cards under false names.
Consider what that means in a market like Zimbabwe’s, where the entire growth story of digital financial services rests on removing friction from onboarding.
Wallet registration here is deliberately frictionless by design. Providers advertise paperless signup with no requirement to submit an identity document copy, completed in about a minute from any network. That design choice is why financial inclusion has moved as fast as it has, and it is a genuinely good thing. It is also precisely the surface that a synthetic identity is built to walk through.
Add the second element. Nano lending and micro credit products, which are now a growth engine for Zimbabwean fintech platforms, are approved algorithmically against thin data on customers with no formal credit history. A lending decision made in seconds against a synthetic applicant is a loss that surfaces only when repayment fails, by which time the persona has been discarded.
Then the third. SIM registration under a false name breaks the assumption underneath almost every fraud control in the market, because a mobile number is treated as an identity anchor for wallet access, one time passwords and account recovery.
None of this means Zimbabwean institutions are being defeated at scale today. The report does not make country specific claims of that kind. It means the attack technique now documented across 36 countries is aimed squarely at the architecture Zimbabwe has spent three years building, and the local evidence base for whether it is happening here does not exist publicly.
Southern Africa is not a bystander
Two regional findings land close to home.
The report states plainly that Southern Africa’s very high connectivity makes it a magnet for global threat actors seeking maximum disruption. That inverts the usual framing. Better infrastructure is normally reported as an unqualified good, and here it is listed as the reason the region attracts attention.
Second, 72% of surveyed countries reported the presence of scam centres, with the highest concentration in Southern and West Africa. Scam centres are organised operations, not opportunistic individuals, and their concentration in this region has had almost no coverage in the Zimbabwean press.
Elsewhere the pattern differs. East Africa has emerged as a hub for mobile money fraud and ransomware aimed at infrastructure. Business email compromise and romance scams are prolific in Central and West Africa. On business email compromise specifically, the report notes that AI is now used to generate highly convincing correspondence, and that Africa based threat actors are targeting victims in Europe and North America through infrastructure spread across multiple jurisdictions.
The report also records the scale of image based abuse enabled by synthetic media, citing some 600,000 sextortion detections logged by TrendAI, one of several private partners that contributed data.
The blind spot is institutional, not technical
The recommendation with the most immediate application is not about buying tools. INTERPOL identifies the absence of real time data sharing between banks, telecommunications operators and law enforcement as a dangerous blind spot in the fight against financial fraud.
That is a description of how most African markets are organised, Zimbabwe included. A bank sees a suspicious account. An operator sees a suspicious SIM. A police unit sees a report from a victim. None of the three sees the other two in time to act, and a synthetic identity exists in the gaps between them. Fixing it requires a data sharing arrangement between institutions that currently have no operational reason to talk to each other daily, and doing that lawfully in Zimbabwe means routing it through the Data Protection Authority rather than around it.
The report’s other recommendations are standardised digital forensic capability, stronger cross border cooperation, investment in AI literacy among law enforcement officers, and formal public private partnerships.
That AI literacy point deserves emphasis, because the report is blunt that AI readiness among law enforcement agencies across the continent remains alarmingly low while cybercrime legislation stays fragmented.
What is actually working
The assessment is not a document of despair, and the enforcement record is the reason.
Four INTERPOL coordinated operations, Serengeti 2.0, Contender 3.0, Sentinel and Red Card 2.0, together produced more than 1,500 arrests, the seizure of hundreds of devices and the recovery of over US$100 million.
Neal Jetton, Director of INTERPOL’s cybercrime unit, put the case for cooperation directly, saying that AI is automating every stage of an attack from reconnaissance and phishing through to extortion and evasion, but that criminal infrastructure can be identified, disrupted and dismantled when countries work together.
Legislative movement is real too. Seventeen countries enacted or amended cybercrime legislation during 2025, including an online reporting platform in Senegal built to improve the response to online offences affecting children.
The assessment forms part of INTERPOL’s African Joint Operation against Cybercrime, funded by the United Kingdom’s Foreign, Commonwealth and Development Office, with data contributed by Fortinet, Mastercard, the Shadowserver Foundation, S2W and TrendAI.
What to watch in Zimbabwe
Whether any Zimbabwean institution publishes synthetic identity fraud numbers. Right now nobody does, which means the sector cannot tell the difference between not having the problem and not measuring it.
Whether the regulators build a shared fraud signal. Zimbabwe’s regulator has real standing on data protection and runs a Data Protection Officer training programme with the Harare Institute of Technology. A bank, telco and police data sharing framework is a harder and more valuable next step than another awareness campaign.
Whether onboarding controls change. Zimbabwe’s digital inclusion gains came from removing friction, and the honest tension is that the same friction was a control. The answer is better verification rather than slower verification, but somebody has to fund it.
And whether the legal instruments get updated. The governing continental framework, the African Union Convention on Cyber Security and Personal Data Protection, was drafted against early 2010s definitions and does not explicitly contemplate AI driven social engineering or synthetic identity creation. Zimbabwe’s own Cyber and Data Protection Act inherits that vintage. We will return to this in a separate piece.
The full 40 page report is available free from INTERPOL and is worth reading in the original rather than through anyone’s summary, including ours.

