African Cybercrime Doubled To $484 Million. The Continent Has 20,000 People To Stop It.
On 18 August 2025, a ransomware crew called Qilin claimed it had broken into Uganda Electricity Transmission Company Limited and taken the internal contracts, identity documents, financial statements and service agreements. That is the company that moves power across Uganda.
A year later, almost to the day, a Nigerian firm that builds machines to guard power plants closed the largest seed round in African history.
Between those 2 dates sits the number that ties them. African cybercrime losses went from $192 million in 2024 to $484 million in 2025.
They doubled in 12 months.
Africa did not get careless. It got bigger, far faster than anyone staffed for. The continent carries 1.1 billion mobile subscriptions and pushed $1.1 trillion through digital channels in 12 months, and the guarding was left to whoever was already in the building.
The shortage is people.
INTERPOL put the arithmetic on paper.
The African Cyberthreat Assessment Report 2026, published on 3 August, surveyed 36 member countries and found 55% of reported cybercrime is now AI enabled. Scam centers operate in 72% of them. Deepfakes and synthetic identities are defeating biometric checks. The hardest hit sectors are financial services, telecoms and government, and East Africa is named the hub for infrastructure ransomware and mobile money fraud.
“AI is automating every stage of a cyberattack from reconnaissance and phishing to extortion and evasion.”
Neal Jetton, INTERPOL
The $484 million is a floor. Close to 90% of the countries surveyed named underreporting as a major problem, and INTERPOL separately estimates direct economic damage across Africa in 2025 at nearer $5 billion.
The attackers stopped going for the wallet and started going for the wire.
Kenya absorbed 46,786 denial of service attacks on its telecom networks in H1 2025 alone, plus hundreds of millions of intrusion attempts against government systems, and detected more than 123,000 fraudulent SIM cards. Uganda’s transmission utility was named on a leak site. This is not consumer fraud. This is the layer that carries everything else.
The shortage is people.
Here is where the story turns.
The defense is not missing. It is outnumbered. Africa’s cybersecurity market is worth roughly $770 million in 2026, which against the $1.1 trillion moving through African digital channels is 0.07% of the flow. The continent has around 20,000 certified cybersecurity professionals, 63% of organizations in sub Saharan Africa say they do not have enough, and 92% of law enforcement agencies lack the expertise to work an AI enabled case. Competent firms already do this work from Lagos to Nairobi. There are not enough of them.
The shortage is people.
So let’s look at who is already making them.
The machines got funded on 17 August. Terra Industries, founded in Abuja in 2024 by Nathan Nwachuku and Maxwell Maduka, closed its seed at $52 million. It builds interceptor drones, sentry towers and ground vehicles, and already watches roughly $11 billion of critical assets including power plants and mines. A 2nd plant opens in Ghana in Q4, targeting 50,000 systems a year by 2028.
“Critical infrastructure across the Global South is best protected by systems designed for these environments and built in the regions they protect.”
Nathan Nwachuku
AfricaHackon ran the 1st hacking conference Kenya ever held, on 28 February 2014, founded by Dr Bright Gameli Mawudor, a Ghanaian who took his doctorate in information security in South Korea and built the collective out of Nairobi. It is vendor neutral. It teaches the skill, not somebody’s product.
Its academy runs 6 months in small squads under a mentor, from cryptography to incident response, and certifies at the end. It is taught out of HackHouse Africa in Westlands, which has run over 400 events and carried more than 5,450 builders through its programs.
On 13 August, 4 days before Terra closed its round, AfricaHackon held its 2026 summit at Sarit Expo Centre under a theme chosen before these numbers existed.
From skills to securing systems.
Early tickets were 4,500 shillings. At the door, 7,000.
The answer is not missing, and it is not expensive. It is under subscribed.
Who wins, who is squeezed, and the gap
The winners sell the night shift. Managed security operations for utilities, telecoms and banks. Incident response and digital forensics sold into a 92% expertise gap. Deepfake and identity detection for every KYC desk whose biometrics are being beaten. And manufacturing, which Terra has just proved can be financed here and built here.
The squeezed are the in house IT department asked to be a security team on the side, and the foreign vendor selling licenses with nobody watching the screen at 3am.
The gap is the staffed shift itself. Africa keeps rediscovering the same missing profession. Last time it was the independent verifier who could confirm a building was finished. This time it is the analyst watching the wire while the country sleeps.
It works wherever it is staffed. Kenya sits at Tier 1 on the Global Cybersecurity Index, detected 3.37 billion threat events in Q1 2026, and watched denial of service attacks fall 85.93% to 8.2 million. This is not a continent that cannot defend itself. It is a continent that has not hired enough of the people who can.
That is the conversation waiting at the Business Week Afrika Summit on 1 and 2 October 2026. The builders laying the rails and the builders guarding them have worked in separate rooms, and the bill for that is now published to the shilling. The Summit puts the utility, the telco, the bank, the regulator and the security founder in 1 room, which is where a night shift gets designed.
Secure your seat and join the builders closing the gap: https://apps.little.africa/events/105
Somewhere in Kampala tonight, a substation hums in the dark, and a screen in an empty room logs every attempt to reach it.
