From Sidhant Tamrkar | Product & Market Analysis
AI Cybercrime Is 55% in Africa and 2% in FBI Data. Both Are Right.
On this page
AI cybercrime now accounts for 55% of reported offences across Africa, according to INTERPOL. The FBI, measuring its own 2025 complaint data, puts the equivalent share at 2.2%. Both numbers are honestly derived, and the 25 times gap between them is not a disagreement about attackers. It is a disagreement about denominators. Read the wrong one and you will buy the wrong controls.
Key takeaways
- INTERPOL puts AI in 55% of reported African cybercrime. The figure rests on survey responses from 36 member countries plus partner telemetry, not on forensic attribution of individual cases.
- The FBI's equivalent share is 2.2% of complaints and 4.3% of losses. Its 2025 Internet Crime Report logged 22,364 complaints that referenced AI, carrying $893 million of losses inside a $20.9 billion total.
- The doubling of African losses is a volume story, not a severity story. Reported losses rose 152% and identified victims rose 149%, so the average loss per identified victim moved about 1.4%.
- The controls that follow do not depend on which number is right. Out-of-band verification of payment changes and injection-resistant identity checks defend against the 55% reading and the 2% reading equally.
What INTERPOL actually measured
INTERPOL's African Cyberthreat Assessment Report 2026 states that artificial intelligence is enabling 55% of reported cybercrimes across Africa. The figure comes from survey responses supplied by 36 African member countries, supported by partner telemetry. It is a law enforcement assessment of reported crime, not a forensic finding about individual cases.
The report runs to 40 pages and was published on 3 August 2026. Its data partners are named: Fortinet, Mastercard, the Shadowserver Foundation, S2W and TrendAI. That mix matters, because private telemetry and police reporting see different slices of the same problem.
Neal Jetton, who directs INTERPOL's cybercrime unit, framed the finding in one sentence. AI is automating every stage of a cyber-attack, from reconnaissance and phishing through to extortion and evasion. That is a claim about breadth of use, not about the share of crime that depends on it.
What counts as AI-enabled in this report
The category is wide. It covers AI-written scam messages, automated social engineering, credential harvesting at scale, synthetic identities used to defeat biometric onboarding, and deepfakes used in sextortion and romance fraud. Ransomware families including Qilin and Akira sit inside it too.
Under that definition, one AI-drafted phishing email inside a longer intrusion makes the whole case AI-enabled. That is a defensible way to describe a threat landscape. It is a poor way to size a budget, because it says nothing about how much of the harm the AI component caused.
Two other figures in the report deserve more attention than the headline. 72% of surveyed countries reported the presence of scam centres, concentrated in Southern and West Africa, with victims largely in Europe and North America. Roughly 600,000 digital sextortion detections came from a single partner feed.
Africa also passed 1.1 billion mobile subscribers in 2025, and 17 countries enacted or amended cybercrime legislation during the year. Those numbers describe a market and a legal response. They do not require anyone to accept a specific AI percentage.
The FBI asked a similar question and got 2%
The FBI's Internet Crime Complaint Center published its 2025 report in mid-2026. It recorded 1,008,597 complaints and $20.877 billion in reported losses, a 26% rise on the prior year. For the first time in the report's 25 year history, AI was broken out as its own category.
That category contained 22,364 complaints referencing artificial intelligence, with $893 million of associated losses. Against the totals, that is 2.2% of complaints and 4.3% of losses. Business email compromise cost $3.046 billion in the same year, of which only about $30 million carried a confirmed AI component.
The FBI is explicit that this undercounts. A complaint lands in the AI bucket when the victim noticed AI and said so. Most victims of a well-made synthetic voice or a generated invoice have no way to know what produced it.
Why the two numbers sit 25 times apart
Neither institution is careless, and neither is spinning. Three differences account for almost all of the distance between them.
The denominator is not the same object
INTERPOL's base is reported cybercrime as characterised by national police services. The FBI's base is individual complaints filed by members of the public and businesses. One is a professional judgement about categories of offending. The other is a count of records.
Ratios built on different bases can both be accurate and still cannot be subtracted from each other. Any headline that presents 55% as the global rate of AI cybercrime has silently swapped the denominator.
The attribution method is not the same either
A police service asked whether AI featured in a case type will answer from investigative experience. A complaint form captures only what the victim noticed. Those two instruments have opposite biases: the first tends to over-attribute, the second structurally under-attributes.
My read is that the FBI number is the more misleading of the two, precisely because it looks the most rigorous. A precise count of an unobservable property is still a count of what people happened to notice.
The underlying crime mix differs by region
Africa's reported cybercrime is dominated by online scams, business email compromise, romance fraud and sextortion. Those are social engineering offences, which is exactly where generative tooling helps an attacker most. The FBI's loss table is led by investment fraud at $8.6 billion, a category where the decisive step is a persuasive relationship rather than a generated artefact.
So a higher AI share in Africa is not surprising. A large part of the 55% is a statement about the crime mix, not about African attackers being further ahead.
| Source | Population measured | What counts as AI | Headline |
|---|---|---|---|
| INTERPOL, African Cyberthreat Assessment 2026 | Reported cybercrime across 36 surveyed member countries | Any AI use across the attack chain, as assessed by police services | 55% of reported cybercrimes. |
| FBI IC3, 2025 Internet Crime Report | 1,008,597 complaints filed in the United States | AI referenced in the complaint by the person filing it | 2.2% of complaints, 4.3% of losses. |
| Anthropic, MITRE ATT&CK mapping | 832 accounts banned for malicious cyber activity | Everything, because the population is already AI misuse | 67% of that set used AI to write malware. |
The third row is included to make the denominator problem obvious. Anthropic's population is defined by AI use, so its percentage answers a different question entirely: what attackers do with AI once they have it.
The loss figures say volume, not severity
The most quoted number after the 55% is the money. African cybercrime losses rose from $192 million in 2024 to $484 million in 2025. That is a 152% increase, and it reads as an escalation in the damage a single attack can do.
The report contains the figure that tests that reading. Identified victims rose from 35,000 to 87,000 over the same period, an increase of 149%. Divide one by the other and the average reported loss per identified victim moves from about $5,486 to about $5,563.
That is a change of roughly 1.4%. The doubling of losses is almost entirely a victim-count story. Whatever AI did to African cybercrime in 2025, it did not make the average incident materially more expensive.
Treat that derived figure as directional. INTERPOL does not state that the loss base and the victim base cover an identical set of cases, so the division carries an assumption I cannot verify from the published report. It is still the single most useful thing in the dataset, because it points at a mechanism.
If AI were making individual attacks smarter, you would expect larger single losses. Better pretexting should convert higher-value targets and extract more per success. That is not what the two years show.
What the numbers show instead is the economics of a cheaper attempt. When drafting a convincing lure drops to near zero cost, the rational attacker runs more lures rather than better ones. Defences tuned to catch the sophisticated outlier will underperform against that. Defences that raise the cost or friction of every attempt will do better.
A third measurement, taken from inside the models
There is one more dataset worth putting next to the other two, and it comes from a model provider rather than a police service. Anthropic examined 832 accounts banned for malicious cyber activity between March 2025 and March 2026, and mapped them onto the MITRE ATT&CK framework.
Those accounts produced 13,873 logged malicious actions across 482 distinct techniques. Malware generation was the most common pattern, appearing in 560 of the 832 cases. In one extortion campaign, a single actor used an agentic coding tool to run nearly every stage of an attack, including sizing ransom demands against each victim's finances.
Two movements inside that data stand out. The share of cases rated medium risk or higher rose from 33% in the first six months to 56% in the second, a 1.7 fold increase. At the same time, phishing-assisted techniques fell 8.6% while account discovery rose 8.9%.
Read together, those say attacker use of AI is moving from getting in to operating once inside. That is a different threat than the one the 55% headline describes, and it lands on different controls. It is also why the terms your model provider sets around monitoring and abuse matter operationally, a point covered in the comparison of model provider terms.
The limitation is stated by Anthropic itself. The 832 cases are a subset of accounts banned in the period, chosen because they carried enough detail to assess. It is one vendor's view of its own misuse, which is a narrow and self-selected window.
Where AI changes the attack, and where it does not
Strip out the percentages and three concrete shifts remain. Each one has a control attached, and none of them requires you to settle the 55% question first.
Identity verification is the surface under genuine pressure
INTERPOL flags synthetic identities and deepfakes defeating biometric checks as a named failure. It also names the structural reason those attempts succeed: there is no real-time data sharing between banks, telecoms and law enforcement, so a synthetic identity that fails in one channel is not flagged in the next.
For a software business, the equivalent is your onboarding and account recovery path. Anything that accepts a face, a voice or a document as proof of a human is now accepting a rendered artefact instead. The same reasoning applies to machine identities, which is a separate and larger problem covered in the piece on non-human access and agent identity.
Volume is the change, not sophistication
I think the industry has the sophistication story backwards. The evidence from the loss-per-victim figure, and from the fall in phishing-assisted techniques in Anthropic's set, points at cheaper attempts rather than cleverer ones.
That matters for procurement. A tool sold on detecting the exceptionally convincing deepfake is defending against a case the data does not show growing fastest. A control that adds a verification step to every payment change is defending against the case that is.
The pressure is moving inside the perimeter
Post-compromise activity is where the measured growth is. Once an attacker is inside, AI helps enumerate accounts, read internal documents and write plausible internal messages. Those actions look like normal work to most monitoring.
Two adjacent exposures matter here. Employees pasting company data into unsanctioned tools widens the internal surface, as set out in the analysis of what shadow AI adds to a breach. Connected tooling widens it again, which is the argument in the piece on MCP server supply chain risk.
Where this argument is weakest
This post argues the 55% figure is being read too literally. Here is the case against that position, stated as strongly as I can make it.
The case that 55% is closer to the truth
Police services in the surveyed countries see the case files. Their assessment draws on investigative detail that no complaint form captures, and they have no obvious incentive to inflate a technology attribution. If anything, an under-resourced agency has reason to be conservative about a claim it may be asked to evidence.
The FBI's own caveat cuts the same way. If AI attribution depends on victim recognition, then 2.2% is a floor rather than an estimate. The true US figure could sit far above it, and possibly not far below INTERPOL's. On that reading, the gap is measurement error concentrated in one instrument, not a genuine regional difference.
What I could not verify
I could not read the survey instrument. INTERPOL's published summary does not state the question put to member countries, the response rate, or how partial responses were handled. Without that, nobody outside the organisation can reconstruct the 55%.
I also cannot confirm that INTERPOL's loss figures and victim counts cover the same case population, which is the assumption under the per-victim calculation above. And a report of this kind is a snapshot of reported crime, which excludes everything unreported. In fraud, that share is large and unmeasured.
The controls that survive either number
Here is the practical test. If a control only makes sense in the 55% world, it is a bet on a statistic. If it makes sense in both, it is a control.
| Control | Why it holds either way | Where it fails |
|---|---|---|
| Out-of-band verification for any payment or bank detail change | Defeats a convincing lure whether a human or a model wrote it | Useless if the callback number comes from the same message. |
| Injection-resistant identity checks at onboarding and account recovery | Synthetic media is cheap enough to expect on any channel accepting an image or voice | Adds friction for genuine users, and vendors overstate detection rates. |
| Post-compromise detection on account enumeration and unusual internal access | Matches where measured attacker AI use is actually growing | High false positive load without a tuned baseline. |
| A named owner for every third-party AI integration | Widened internal surface is the common factor across all three datasets | Governs sanctioned tools only, and misses what staff install. |
| Specialist deepfake detection tooling | The right answer where you accept biometric proof at scale | The one row here that is a bet, and most buyers lack the volume to justify it. |
The last row is the concession. If your business verifies identity at high volume, specialist detection stops being optional and the 55% reading becomes the operationally relevant one.
Two further pieces of the same problem are worth reading if you are building the policy rather than the control. Human review placement decides whether any of this is catchable, which is the subject of the piece on where human review actually belongs. And the governance settings across the main enterprise assistants differ more than the marketing suggests, as set out in the enterprise governance comparison. If you operate in the European Union, the disclosure obligations arriving alongside all of this are laid out in the EU AI Act transparency checklist.
Frequently asked questions
What percentage of cybercrime uses AI?
There is no single agreed figure, and the published numbers differ by more than an order of magnitude. INTERPOL says AI enables 55% of reported cybercrimes across Africa. The FBI's 2025 Internet Crime Report counted 22,364 AI-referencing complaints out of 1,008,597, which is 2.2%, and 4.3% of reported losses. The two use different populations and different attribution methods, so neither is a global rate.
What did the INTERPOL African Cyberthreat Assessment Report 2026 find?
The report found that AI is enabling 55% of reported cybercrimes across Africa, that losses more than doubled from $192 million in 2024 to $484 million in 2025, and that 72% of surveyed countries reported scam centres. It draws on survey data from 36 African member countries plus partner telemetry, and describes cybercrime shifting from isolated incidents to an industrialised, cross-border ecosystem.
How much did African cybercrime losses increase in 2025?
Reported losses rose from $192 million to $484 million, an increase of about 152%. Identified victims rose from 35,000 to 87,000 over the same period, an increase of about 149%. Because the two grew at almost the same rate, the average reported loss per identified victim changed only about 1.4%. The escalation is in the number of victims rather than the cost of each incident.
Is AI making phishing attacks more effective?
The measured evidence points to more attempts rather than better ones. Anthropic's mapping of 832 banned accounts found phishing-assisted techniques falling 8.6% across the study year, while post-compromise account discovery rose 8.9%. INTERPOL's flat loss-per-victim figure is consistent with that reading. Generation cost collapsed, so volume rose, while the value extracted from each successful attack stayed broadly flat.
How do deepfakes defeat identity verification?
Synthetic identities and generated media are used to pass biometric onboarding checks, which INTERPOL names as a growing failure mode. The structural weakness it identifies is the absence of real-time data sharing between banks, telecoms and law enforcement. An identity rejected in one channel is not flagged in the next, so an attacker can retry the same synthetic profile until a weaker check accepts it.
What should a small company do about AI-enabled fraud?
Start with the controls that work regardless of which statistic is right. Require out-of-band verification for any change to payment or bank details, using a contact route you already held. Review how account recovery proves a person is real. Then check which internal tools have access to company data and who owns each one. Detection tooling comes after those three, not before.
Where to start this week
Two actions, both small enough to finish in an afternoon.
First, run one test on your own payment change process. Send a request from an external address that impersonates a supplier, and see whether anyone verifies it through a channel that did not come from the message. If I had to choose a single control from this post, that is the one, because it is the step both datasets agree the attacker has to get past.
Second, write down which statistic your last security purchase was justified by, and check its denominator. That habit is worth more than any specific number in this post, and it applies well beyond security, as the review of deployments that returned nothing shows.
References
- INTERPOL, INTERPOL report finds AI linked to more than half of cybercrime in Africa, 3 August 2026. Used for the 55% figure, loss figures, scam centre share, sextortion detections and the Jetton quote.
- INTERPOL, African Cyberthreat Assessment Report 2026, June 2026. The primary document behind every INTERPOL figure cited here.
- Help Net Security, INTERPOL flags AI as the new engine of African cybercrime, 5 August 2026. Used for the identified victim counts of 35,000 and 87,000.
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report, 2026. Used for total complaints, total losses, the AI category and business email compromise figures.
- PYMNTS, FBI flags $893 million in AI-driven scams, 2026. Used to confirm the 22,364 complaint count and the first-time breakout of AI as a category.
- Anthropic, What we learned mapping a year's worth of AI-enabled cyber threats, 2026. Used for the 832 accounts, the malware share, the risk-tier shift and the technique movements.
- Infosecurity Magazine, AI accounts for over half of cybercrime in Africa, says INTERPOL, August 2026. Used for the scope of what the report treats as AI-enabled.
Weakest thing about this source base: INTERPOL has not published the survey instrument behind the 55% figure, so its methodology cannot be reconstructed from outside. The loss-per-victim calculation in this post is my own, and it assumes the loss base and victim base cover the same cases, which the published summary does not confirm.
Related reading