INTERPOL published the fourth edition of its Africa Cyberthreat Assessment in May 2025, warning of a sharp rise in cybercrime across the continent and describing ransomware detections concentrated in South Africa, Egypt, Nigeria and Kenya.
Intergovernmental Assessment Is A Better Source Than Most
This desk applies heavy discounts to vendor telemetry at 26-0513 and to leak-site counts at 25-1230, on the grounds that the publisher is selling something.
A policing assessment aggregating national reporting has different incentives. It is not complete — under-reporting across the region is severe, and the four filters at 25-0502 apply in full — but it is compiled from law enforcement returns rather than product sensors.
It also produces the only continental picture that exists. Without it, this corpus would have no basis for saying anything about Africa at all.
The Detection Concentration Tracks Digitisation, Not Vulnerability
South Africa, Egypt, Nigeria and Kenya leading ransomware detection counts is what you would expect from the continent’s largest and most digitised economies — the same reading applied to Brazil, Mexico and Argentina at 25-1116 and to China and India at 25-1206.
A detection count is also a function of how many security products are deployed to detect with. Countries with more commercial security spending generate more detections at any level of underlying activity.
What The Corpus Can And Cannot Take From It
Direction, sector concentration and the shape of the criminal economy: yes. Comparative national risk: no, for the reasons at 25-1117.
This file is graded high because it accurately records what a named intergovernmental body published. That is separate from whether the underlying national data is complete, which it is not.
Built on INTERPOL’s published assessment, listed below. Detection counts derive from contributing security vendors and national reporting with varying coverage. Corrections: corrections@forensicpost.com.