South African businesses are confronting a cybersecurity landscape that is evolving faster than the systems designed to protect them.
With Artificial Intelligence (AI)-powered attacks becoming more sophisticated and scalable, the focus of cybercriminals is shifting from technical vulnerabilities to human trust. This new wave of threats, particularly Business Email Compromise (BEC), renders traditional annual security audits dangerously obsolete, leaving companies exposed in a rapidly changing environment.
According to INTERPOL's member-country survey, 55% of cybercrime cases in 2025 involved AI in some capacity. The report says AI is enabling attacks that are faster, more scalable and more difficult to attribute.
Between 2024 and 2025, reported cybercrime-related losses more than doubled, rising from $192 million to $484 million, according to INTERPOL.
INTERPOL describes business email compromise (BEC) as a “financial engine” of transnational cybercrime because, unlike ransomware, it exploits trust, manipulating human behaviour to bypass technical controls.
The report said BEC campaigns have become significantly more sophisticated, with AI being used to generate highly convincing emails that can mimic executive tone, internal jargon and signatures.
“BEC, unlike ransomware which targets systems, exploits trust, manipulating human behaviour to bypass technical controls,” INTERPOL says.
The organisation proves that the danger isn't theoretical.
In an INTERPOL case, fraudsters infiltrated a petroleum company's email systems and impersonated executives to authorise a $7.9 million fraudulent transfer.
TrendAI data cited by INTERPOL showed that 70% of BEC detections in 2025 originated in South Africa, compared with 29% in Nigeria.
INTERPOL also said Microsoft-identified threat actors who are based in South Africa and active since 2017 have primarily targeted US-based enterprises, using compromised email accounts and money-mule networks to divert funds to offshore accounts.
“The scale and sophistication of cyberattacks across Africa are accelerating, especially against critical sectors like finance and energy,” said Neal Jetton, INTERPOL's Director of Cybercrime.
However, individual fraudsters are not the only threat.
INTERPOL's member-country survey found that 72% of African countries reported the presence of scam centres with most of it concentrated in Southern and West Africa.
The report describes these as highly organised, industrialised criminal enterprises with supply chains for recruitment, technology, laundering and evasion.
For Richard Ford, Group CTO at Integrity360, that acceleration exposes a fundamental weakness in the way many businesses approach cybersecurity.
“An annual audit tells you your defences worked on the day someone checked,” Ford said. “It doesn't tell you whether they're still working today, and today's usually when the attack happens.”
The problem is that the attack surface itself is constantly changing, with organisations adding cloud systems, employee devices and third-party applications.
A security test conducted once a year can therefore provide a snapshot of an environment that no longer exists.
“Boards like the certainty of an annual sign-off because it's simple to report,” Ford said. “But simple isn't accurate, and a board that only asks ‘are we secure?' once a year is asking the right question at the wrong frequency.”
But the problem is exacerbated by a shortage of cybersecurity skills across sub-Saharan Africa.
The World Economic Forum's Global Cybersecurity Outlook 2026 found that about 70% of CEOs in the region reported a shortage of skilled professionals needed to meet their cybersecurity objectives.
Ford argues that automation will increasingly have to fill the gap.
“Automated detection and validation doesn't rely on analysts watching a dashboard around the clock. In a market this short of people to do that watching, that's the whole point.”
ashley.lechman@nationalmg.co.za
wendy.jdc@nationalmg.co.za