South Africa is the flashlight
#cybersecurity #southafrica #INTERPOL #AI #OnyxAudit
Before we start
I have been following this, Interpol and other organisations for a very long time now, and this is as about as close to home as it gets for myself and the those whom I work with. So while I remain impartial, this body of work possibly means the most to me in terms of volume and scope.
The facts below are INTERPOL's. The interpretation is mine.
On 3 August, INTERPOL published its African Cyberthreat Assessment Report 2026. Within hours the wires had their number: 55 per cent of reported cybercrime in Africa is now AI-enabled. Losses doubled to USD 484 million. And for anyone reading from here, the figure that mattered: South Africa accounts for 92 per cent of all ransomware detections on the continent.

That last number is going to be quoted in budget debates, procurement motivations and ministerial speeches for the next twelve months. It is worth understanding what it actually says.
1. The measurement problem
South Africa is not necessarily the most attacked country in Africa. It is the most observed.
The headline rankings are built from commercial sensor networks. South Africa leads on ransomware, phishing, vulnerability detections and DDoS. Those figures describe where sensors are seeing activity. They do not describe where crime is happening. Those are different claims and the report presents them as one.
The report undercuts itself on this. It states that 89 per cent of respondents identified underreporting as a pervasive problem, with countries citing no formal reporting mechanisms, fear of reputational damage, and uncertainty over legal obligations. South Africa is one of only four African countries with a mandatory 72-hour disclosure rule.

So the paradox writes itself. The country that measures most looks worst. The countries that measure nothing look clean.
The stress test is Cabo Verde. Population under 600,000. The report lists it as the second-highest ransomware detection count in Africa at 16,997, sitting at 4 per cent of the continental total. Work that backwards. If 16,997 is 4 per cent, the total is around 425,000, which puts South Africa's 92 per cent share near 391,000.
INTERPOL's 2025 assessment reported 17,849 ransomware detections in South Africa, attributed to Trend Micro. The 2026 report no longer prints South Africa's count directly. Its published percentages imply a figure approaching 391,000, attributed to TrendAI, the rebranded enterprise security unit of the same company. Same vendor, same telemetry lineage, a roughly twentyfold implied change in one year, and no continuity note anywhere in either report.
There are smaller tells. Figure 4 carries the label "Kenya 1%" twice. Egypt, second on the continent in the 2025 edition at 12,281 detections, does not appear in the 2026 regional breakdown at all, because the report now covers four regions and North Africa is not one of them. That change is not flagged, which makes any year-on-year comparison invalid without a footnote nobody wrote.
None of this proves the report is wrong. It demonstrates that detection volume and real-world prevalence cannot be treated as interchangeable, and this report treats them as interchangeable.

The blind spot is not South Africa. South Africa is the flashlight. The blind spot is everything outside the beam.
2. The capability gap
Criminals adopted AI faster than investigators did.
The report leads with 55 per cent of cybercrime cases involving AI in some capacity. Broken down, that is 47 per cent "occasionally" and 8 per cent "frequently", drawn from a survey of member countries.
Pages later, the same report explains why those investigators struggle to identify AI-generated material at all:
- 92 per cent of agencies cite a lack of technical expertise as the primary barrier to adopting AI tools
- Only 8 per cent of intelligence analysts have advanced AI expertise
- Only 22 per cent of digital forensic units have working knowledge of AI-driven threats
- 94 per cent report insufficient digital forensics tools
- 78 per cent report inadequate budgets
- Only 17 per cent of countries run cybercrime units above 100 personnel, and many operate under 10
- Most frontline officers have not been trained to distinguish authentic from synthetic media
Read those two things together. The 55 per cent figure was produced by asking investigators how much AI they were seeing. The report then says those investigators are not equipped to recognise it.
This is the report's strongest contribution, and it is not the 55 per cent. It is the admission. The institutions supplying this data were candid about their own staffing, budgets, training and forensic gaps in a way that reflects badly on them and well on their honesty. That candour is the most valuable material in the document.
It is also why the headline number is worse, not better. They had the real story and led with the other one.
The report is not documenting how much AI criminals use. It is documenting how fast defenders are losing the race. That gap, not AI itself, is the story.

A related caution for anyone quoting this report onward. PromptLock, the AI-assisted ransomware strain, appears twice. On page 24 it is an emerging strain that autonomously writes and executes its own code, spelled "PrompLock". On page 27 it is described as a concept created in academia, not seen in the wild. Same document, two claims, and only one of them makes a headline.
3. Fragmentation
Africa does not have one cyber battlefield. It has dozens.
Cybercrime ignores borders. Law does not.
Legal definitions differ between jurisdictions, and some exclude cryptojacking, cyberstalking, deepfake creation and online human trafficking entirely. Only 13 African nations have ratified the Budapest Convention. Twenty-one had signed the Hanoi Convention at time of drafting. Half of surveyed countries report significant problems in multi-jurisdictional cases. Mutual legal assistance runs on timescales criminals do not respect, and no interoperable digital identity system exists across the continent.
South Africa has comparatively mature legislation. It does not help enough. Attacks originate, transit and monetise across multiple jurisdictions, and the report's own framing of the region is that the challenge is not a lack of policy but gaps in implementation. South Africa built a wall in a field with no fence.
One note on that maturity. The report credits "South Africa's Cybersecurity Act". South Africa has the Cybercrimes Act 19 of 2020, commenced December 2021. The cybersecurity provisions were split out of the original Cybercrimes and Cybersecurity Bill before enactment. The statute named in the report does not exist under that name.
And fragmentation is not only the problem the report describes. It is the reason the report's rankings do not work. You cannot meaningfully rank countries on reported crime when 17 per cent of them have no dedicated legal definition of the crime.
4. Who owns the instruments
This is the conversation almost nobody is having.
The report contains two different kinds of evidence.
The 36 member countries supplied detailed information about themselves: staffing, budgets, legislation, capability, reporting mechanisms, institutional constraints. Those numbers are valuable precisely because they are self-critical.
The statistics that became headlines came from elsewhere. Ransomware detections, phishing prevalence, vulnerability exposure, botnet distribution, sextortion volume, attack vectors and dark web activity are sourced to TrendAI, Fortinet, FortiGuard Labs, Mastercard, the Shadowserver Foundation and S2W. The assessment is funded by the United Kingdom's Foreign, Commonwealth and Development Office. All of this is stated openly on page 7.
The 36 member countries measured themselves. Foreign commercial telemetry measured both the threats against them and the threats attributed to them. Those are different kinds of evidence, answering different questions, yet they appear side by side as though they describe the same reality.
That is not a metaphor. It is the layout. The report contains 18 figures. Seven come from the member country survey. Eight come from foreign commercial partners. They alternate through the document in identical house style, same palette, same caption format, with nothing signalling that they are different categories of evidence. Two carry no source attribution at all.
Neither dataset is wrong. The danger is treating them as if they measure the same thing, because those rankings will shape funding decisions, policy priorities and public perception across the continent.
Africa increasingly understands its own capacity. It still relies heavily on external instruments to measure its digital battlefield.

Sources
- INTERPOL African Cyberthreat Assessment Report 2026, June 2026, interpol.int
- INTERPOL African Cyberthreat Assessment Report 2025, June 2025, interpol.int
- Cybercrimes Act 19 of 2020, Republic of South Africa
Clayton Bax
Published under ONYX Digital Intelligence Following the #OnyxAudit methodology.
- X: @onyxaudit
- Email: onyxdigitalintelligence85@protonmail.com
- https://github.com/Baximus855
- @Onyx_Digital@mastodon.social
"Adjacent to true is not true."
Truth has no flag nor favour, only a standard. And it's heavy"