Interpol reports that AI is involved in 55% of cybercrimes across Africa, with financial losses more than doubling to $484 million. Deepfake-based digital extortion cases have surged to approximately 600,000.
A new Interpol report identifies artificial intelligence as the "core operational driver of cybercrime" across the African continent. The findings reveal a sharp escalation in both the scope and sophistication of digital attacks.
Financial damages have more than doubled compared to previous reporting periods, rising from $192 million to $484 million. The increased losses reflect both the growing prevalence of AI-powered attacks and their enhanced effectiveness.
Deepfake technology has emerged as a particularly damaging tool, with approximately 600,000 cases of digital extortion involving synthetic media recorded in the region. These attacks leverage manipulated audio and video to coerce victims into financial transfers or sensitive disclosures.
The report underscores how AI capabilities—ranging from automated vulnerability detection to social engineering automation—have lowered barriers to entry for cybercriminals. Law enforcement agencies across African nations face mounting pressure to develop detection and response capabilities that match the speed and sophistication of AI-driven threats.
A Go-based malware distributed through ClickFix attacks is targeting macOS users to steal cryptocurrency, passwords, and Apple Keychain data. The infostealer campaign combines social engineering with credential harvesting.
A former NSA official has warned against connecting water infrastructure controllers to the internet following suspected Iranian cyberattacks on U.S. water systems.
Security researchers scanning Polish government websites discovered critical vulnerabilities that could expose courts, hospitals, and airports to cyberattacks. The vulnerabilities stem from common software used to manage and display web content.
A critical SQL injection vulnerability in Metabase is being actively exploited in the wild to steal customer data. The zero-day attack has already compromised instances at Framework and Tally.