AI was linked to more than half of the cybercrime cases recorded in Africa in 2025, according to Interpol’s African Cyberthreat Assessment Report 2026.
Southern Africa was reported as the most targeted country on the continent, accounting for 92% of Africa’s ransomware detections and 70% of its business email compromise detections.
As AI makes attacks more convincing and easier to scale, the risk is moving beyond the IT department to the teams that can approve a payment, reset a password or grant access.
“Attackers have adopted AI faster than most organisations have learned to recognise it,” says Riaz Moola, founder and CEO of HyperionDev. “A phishing email used to give itself away with poor spelling or a generic greeting. AI can now produce something that mentions your manager by name and the invoice you’re expecting this week. Some of the warning signs staff were trained to look for are disappearing.”
Moola says cybersecurtity training needs to extend beyond traditional security teams and be tailored to the roles most likely to encounter these attacks:
- Finance teams, which may receive convincing emails asking them to change a supplier’s banking details or approve an urgent payment.
- Executives and their assistants, who can be targeted through impersonation, including cloned voices and images used to request transfers or sensitive information.
- HR and recruitment teams, which may encounter fake candidates using AI-generated CVs and synthetic identities, particularly for roles that provide access to company systems.
- Customer service and call centre staff, who may be targeted by criminals impersonating customers using stolen personal information or other convincing details.
- Legal and compliance teams, which need to understand their responsibilities when a breach occurs, including whether it needs to be reported under POPIA.
“Many of these attacks depend on someone being persuaded to act,” says Moola. “A once-a-year awareness session doesn’t prepare people for increasingly convincing, role-specific attacks. Finance, HR and customer service teams need to understand what an AI-enabled attack looks like in the context of their own work.”
That could mean training finance employees to independently verify changes to banking details before making a payment, teaching HR teams how to validate candidate identities, or helping call centre staff recognise attempts to bypass customer verification using stolen information or cloned voices.
Moola also believes businesses can look internally when addressing the cybersecurity skills gap.
“The people who understand your payment processes, your customers and your systems already work for you,” he says. “Training a finance clerk to identify a fraudulent supplier request, or giving a customer service agent a pathway into a cybersecurity role, can help businesses build capability while retaining valuable organisational knowledge.”
Security teams still carry the technical defence, and their work is changing as attackers adopt AI.
“Every AI tool that helps defenders is also available to attackers,” concludes Moola. “Start with the teams that handle money, people and customer data. That’s where attackers are starting too.”