BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

1,605 arrests across Africa: How the continent fought back against infrastructure cyberattacks

In August 2025, operators at Uganda’s Electricity Transmission Company Limited watched their network monitoring screens freeze. A ransomware variant had compromised the systems governing the

AnonymousCryptoCompass newsroom
August 3, 2026
8 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for defi coverage.

In August 2025, operators at Uganda’s Electricity Transmission Company Limited watched their network monitoring screens freeze. A ransomware variant had compromised the systems governing the national power grid. Service was restored only through backup protocols, but the incident confirmed what law enforcement across the continent had already suspected: African cyberattacks had moved beyond theft into sabotage.

The shift is documented in granular detail in INTERPOL’s African Cyberthreat Assessment Report 2026, compiled from 36 member countries and private sector telemetry. The portrait is not of isolated hackers but of an industrialised ecosystem targeting the physical infrastructure that economies depend on.

Seven months before Uganda’s grid flickered, the South African Weather Service suffered a suspected ransomware attack that corrupted critical meteorological data systems, and the disruption rippled outward into aviation routing and maritime navigation services. In Nigeria, the Customs Service was hit in August 2025 by a ransomware variant that paralysed cargo clearance at major ports, generating an estimated $18 million in storage fees and import delays. In Namibia, the national telecommunications provider lost 500,000 personal and financial records after an unsecured administrative portal was exposed to the public internet, while a separate attack by the Akira group targeted Paratus Telecom, disrupting core network services.

1,605 arrests across Africa: How the continent fought back against infrastructure cyberattacks Screenshot (INTERPOL cyberattacks report)

The financial toll is stark. Reported cyberattack losses across Africa more than doubled between 2024 and 2025, climbing from $192 million to $484 million, and the documented victim count rose from 35,000 to 87,000. INTERPOL estimates the true direct economic damage at roughly $5 billion in 2025, against a continental cybersecurity expenditure of $15.3 billion that same year. The defences are growing, but the attacks are growing faster.

What distinguishes the current wave is its concentration on critical infrastructure. FortiGuard Labs telemetry revealed that threat actors are deploying automated reconnaissance tools capable of scanning tens of thousands of systems per second, targeting outdated routers, vulnerable VPNs, and misconfigured cloud services. The Shadowserver Foundation identified more than 6,000 exploitable vulnerabilities across Africa in 2025, concentrated in South Africa, Kenya, and Nigeria. The Sliver command-and-control framework, an open-source tool weaponised by criminal actors, was used to deploy novel ransomware strains, and Cameroon alone recorded 40.5 million botnet detections in 2025, the second highest in Africa, while Angola showed similarly high levels of compromised device activity.

Yet the most visible failures may be the least reported. According to the INTERPOL survey, 89% of member countries cited underreporting as a pervasive challenge. Only Nigeria, Kenya, South Africa, and Mauritius mandate breach disclosure within 72 hours, many agencies lack formal incident reporting mechanisms, and victims often fear reputational damage. The result is a landscape where the known attacks are almost certainly a fraction of the real total.

1,605 arrests across Africa: How the continent fought back against infrastructure cyberattacks Screenshot (INTERPOL cyberattacks report)

The institutional response has been forceful and unprecedented in scale. In 2025, INTERPOL and member countries conducted a series of coordinated multinational operations that represent the largest cybercrime crackdown in African history.

Operation Serengeti 2.0, conducted early in the year, targeted illegal cryptocurrency mining operations, scam centres, and ransomware infrastructure across Angola, South Africa, and Uganda. It dismantled more than 1,200 malicious servers, seized 1,800 devices, and resulted in 120 arrests, disrupting networks responsible for $300 million in losses.

Operation Contender 3.0, spanning July and August, focused on romance scams and digital sextortion across 14 African countries. It yielded 260 arrests, the seizure of more than 1,200 devices, the identification of 1,500 victims, and the dismantling of 81 online crime networks, with an estimated $2.8 million in illicit proceeds recovered.

Operation Sentinel, running from October to November, was the largest coordinated operation to date, spanning 19 nations and targeting BEC, digital extortion, and ransomware. It produced 574 arrests, the recovery of approximately $3 million, the takedown of more than 6,000 malicious links, and the decryption of 30 terabytes of ransomware-encrypted data in Ghana alone.

Operation Red Card 2.0, from December 2025 to January 2026, targeted high-yield investment fraud, mobile money scams, and fake loan applications across 16 countries. It resulted in 651 arrests, the recovery of $4.3 million, the seizure of 2,341 devices, and the takedown of 1,442 malicious IPs and domains, uncovering scams responsible for $45 million in losses affecting 1,247 victims.

1,605 arrests across Africa: How the continent fought back against infrastructure cyberattacks Screenshot (INTERPOL cyberattacks report)

But the report makes clear that operations alone cannot close the gap. The survey found that 72% of African countries reported the presence of scam centres operating within their borders, concentrated heavily in Southern and West Africa. INTERPOL explicitly links these centres to human trafficking and transnational organised crime, describing facilities where victims are held against their will and forced to conduct scams, and the romance scam and the trafficking case are increasingly the same.

Read also: Investigation: How 69,000 daily stolen phones are used to drain bank accounts of Nigerians

The systemic vulnerabilities extend to the foundations of digital finance. In Kenya, SIM swap fraud surged 327% in 2025, with more than 123,000 fraudulent SIM cards issued and an estimated $3.8 million drained from mobile wallets, and Tanzania and Rwanda reported similar patterns. The root cause was institutional: telecom employees working without real-time biometric verification and reporting systems so fragmented that victims must navigate between banks, telecoms, and police who do not share data with one another in real time.

Law enforcement capacity remains unevenly distributed.

  • 94% of agencies reported insufficient digital forensics tools,
  • 78% cited inadequate budgets, and only
  • 17% of countries maintain cybercrime units with more than 100 personnel.
  • 72% reported slow data exchange between agencies, while 89% identified cross-border cooperation as the single largest barrier to successful investigations.

AI readiness is alarmingly low. While 55% of cybercrime cases in 2025 involved AI in some capacity, only 8% of intelligence analysts across the continent possess advanced expertise in identifying AI-generated content, and frontline officers generally lack training to distinguish authentic media from synthetic voice clones or deepfaked video. The report notes that while 33% of agencies have begun using AI for threat detection, the majority still rely on manual processes.

1,605 arrests across Africa: How the continent fought back against infrastructure cyberattacks Screenshot (INTERPOL cyberattacks report)

In 2025, 17 countries enacted or amended cybercrime laws. Kenya advanced legislation specifically targeting SIM swaps, Zambia enforced its Cyber Crimes Act, Angola established a National Cybersecurity Centre, and Senegal allocated $24 million to digital sovereignty initiatives. But implementation remains the critical next step, and legal harmonisation across borders is still incomplete.

When Uganda’s power grid came back online in August 2025, the attackers had not been caught, the vulnerabilities they exploited had not been patched, and the legal frameworks required to pursue them across jurisdictions remained tangled in administrative delays and divergent data protection regulations. The grid recovered because the utility had backups, though the underlying fragility remained exactly where it was, and the report suggests that more systems are one unsecured portal, one fraudulent SIM, or one ransomware variant away from going dark.

What this cyberattack report means for the average African

For most Africans, the report’s $5 billion headline is abstract. The more immediate reality is the mobile money notification that never arrives, the SIM card swapped without consent, or the WhatsApp voice note that sounds exactly like someone you trust. The INTERPOL data suggests that the continent’s fastest-growing fraud vectors do not require victims to be wealthy or careless, only to be connected. With more than 1.1 billion mobile subscriptions and $1.1 trillion in digital transactions recorded in 2025, the attack surface is now the phone in your pocket.

The survey found that mobile money fraud was reported by 97% of the countries surveyed, and Kenya’s 327% surge in SIM swap fraud shows how quickly a single compromised telecom employee can drain a shopkeeper’s daily takings before lunch. The report notes that only four countries mandate breach disclosure within 72 hours, which means the average user often has no warning that their data is already circulating on dark web forums, where S2W data showed a 62% year-over-year increase in African-origin stolen content. You do not need to click a phishing link to become a victim, you only need to have a phone number and a national ID.

Then there is the AI factor. Deepfake investment scams, synthetic identity fraud, and automated sextortion campaigns are no longer targeting corporations and high-net-worth individuals. They are targeting anyone with a social media profile and a mobile wallet. The cyberattack report’s most sobering finding for ordinary users may be institutional rather than technical: banks, telecoms, and police do not share fraud data in real time, and 89% of surveyed countries say cross-border cooperation is their biggest investigative barrier. For the average African, that translates to a simple, frustrating truth. If the money leaves your account on a Friday afternoon, the systems designed to protect you may not talk to each other until Monday and by then, the trail is cold.