The INTERPOL African Cyberthreat Assessment 2024, in plain language

INTERPOL's African Cyberthreat Assessment is the closest thing the continent has to an official annual picture of cybercrime, built on member-country police data and private-sector intelligence. This analysis summarises the 2024 edition's headline findings in qualitative terms — for precise figures, consult the report itself.

The pattern

The 2024 assessment describes a threat landscape dominated not by exotic technology but by crimes against people: scams, phishing and business email compromise sit at the top of what African law-enforcement agencies actually see and receive complaints about. Alongside them, the report flags ransomware as a growing threat to African organisations — including critical infrastructure and public bodies — and notes the rise of digital extortion in its various forms. Two structural themes run underneath: cybercrime represents a meaningful and growing share of reported crime in African member countries, and significant underreporting and capacity gaps mean the official picture almost certainly understates the reality.

How it plays out

Read as a whole, the assessment sketches a consistent operating model for the region's most damaging crime:

Social engineering first. Online scams — from phishing and romance fraud to investment scams propagated over messaging platforms — are the most reported category. The initial access technique of choice across the continent is a message to a human, not an exploit against a machine.

BEC as the high-value tier. The report treats business email compromise as one of the region's most financially damaging schemes, with West African criminal networks documented operating at transnational scale — consistent with the casework behind Operations Falcon and Delilah.

Ransomware moving in. Detections and reported incidents across African countries indicate ransomware operators increasingly see African organisations — banks, utilities, government services — as viable targets, aided by rapid digitisation that has outpaced security investment.

An enforcement response taking shape. The assessment also documents the counter-movement: joint operations coordinated through INTERPOL's African Joint Operation against Cybercrime, growing national cybercrime units, and deepening cooperation with private threat-intelligence firms.

Who it targets

Everyone, unevenly. Citizens bear the volume of scams; organisations bear the concentrated losses of BEC and ransomware. The report's implicit warning for African businesses is that rapid digital adoption — mobile-first workforces, new payment rails, cloud services — has widened the attack surface faster than controls and skills have followed, and that small and mid-sized organisations are far from beneath attackers' notice.

Breaking the pattern

  • Invest where the report says the crime is: the human layer. If phishing, scams and BEC dominate, awareness, simulation and verification processes are frontline controls, not nice-to-haves.
  • Treat BEC as a board-level financial risk with specific controls: out-of-band payment verification, mailbox hardening, finance-team drills.
  • Prepare for ransomware now — offline backups, tested recovery, and staff who recognise the phishing emails that most often deliver the initial foothold.
  • Report incidents to law enforcement. The assessment is explicit that underreporting weakens the collective response; the joint operations that produce arrests run on victim reports.
  • Benchmark yourself annually against the threat picture, not against last year's programme.

Sources

  • INTERPOL, African Cyberthreat Assessment Report (2024)
  • INTERPOL public communications on the African Joint Operation against Cybercrime (AFJOC)

The report's message is that the human layer is where Africa's cyber losses concentrate — find out how yours would hold with our free Human Risk Maturity Assessment.