Skip to main content
Moïse B. Selph
Security3 min read

The number is the least interesting part

Forty minutes on air on Africa Pulse, taking apart INTERPOL’s latest continental assessment: AI is behind 55% of Africa’s reported cybercrime, and losses have doubled in two years. Those figures travel well. What they don’t capture is tempo.


I spent forty minutes on air explaining why the number is the least interesting part.

INTERPOL’s continental assessment puts AI behind 55% of reported cybercrime in Africa. Reported losses up from roughly $192 million to $484 million in two years. Scam centres active in 72% of surveyed countries.

Those figures travel well. What they don’t capture is tempo.

That’s where the conversation kept landing on Africa Pulse this week — not on what criminals are doing, but on how quickly they can now do it, and how slowly everything built to stop them moves by comparison.

Three things I kept coming back to on air.

Scam operations have stopped being artisanal

A business email compromise attempt used to need someone who could write convincingly in the target’s language, read an org chart, pick the right moment. All three are automated now, and the ten-thousandth attempt costs no more than the first. Volume stopped being a constraint.

Mobile money is where the continent is most exposed and least defended

It carries a large share of African transaction volume, often for people with no other banking relationship at all. Fraud there isn’t a line in a reconciliation file. It’s someone’s month.

And the institutional response still runs on human tempo

Cross-border cooperation measured in months. Legal texts drafted for an era when the attacker was a person. Investigators who are competent and badly outnumbered.

That’s the actual gap. Not a technology gap — a clock-speed gap.

What it means depends on where you sit.

Governments: the bottleneck isn’t legislation, it’s the delay between an incident and a usable response. A law that takes eleven months to activate is a law the attacker can plan around.

Banks and fintechs: a verification process designed to catch a careless human forger will not catch a coherent machine-made file. Testing KYC against synthetic identities has stopped being a research exercise.

Companies: the weak point is a supplier’s inbox long before it’s your firewall.

And for anyone using a phone to move money: the old warning signs are gone. Bad spelling, a clumsy photo, a strange turn of phrase — all cheap to fix now. Confirming through a second channel is the one habit that still holds.

I’d rather hear from practitioners than repeat statistics. If your institution has already had to rewrite a control because it was built for a human attacker, tell me how that went.

See also — Africa Pulse, the Ifrikya FM programme where this text was born — the video is online there.

Moïse Bienheureux Selph anchors the news and hosts Africa Tech on Ifrikya FM. He is the founder of Lobaka.