$3bn Cybercrime Losses Put African Businesses on Red Alert as Compliance Risks Mount
Cybercrime losses estimated at $3 billion across Africa since 2019 are putting businesses under growing pressure to strengthen cybersecurity, as digitalisation and tighter regulatory requirements...
Cybercrime losses estimated at $3 billion across Africa since 2019 are putting businesses under growing pressure to strengthen cybersecurity, as digitalisation and tighter regulatory requirements expose organisations to increasingly sophisticated attacks.
A recent report by Kreston Pedabo warned that the rapid adoption of digital payments, cloud services and electronic invoicing is expanding the attack surface for businesses across Nigeria, Ghana and other West African markets.
Drawing on the INTERPOL Africa Cyberthreat Assessment Report 2025, the report said cybercrime accounts for a medium-to-high proportion of reported crime in about two-thirds of surveyed African countries, with the figure reaching roughly 30 per cent in West and East Africa.
Phishing, ransomware, business email compromise and digital sextortion were identified among the persistent threats confronting businesses and public institutions.
Tyna Adediran, Lead, Management Consulting at Kreston Pedabo, said organisations were increasingly being targeted through trusted business relationships rather than sophisticated technical attacks alone.
She cited a case involving a Ghanaian manufacturing distributor that transferred funds to fraudsters after receiving what appeared to be a legitimate payment request from a long-standing supplier. The supplier’s communications had allegedly been monitored by criminals for weeks.
According to Adediran, the incident illustrates how weaknesses in business processes, payment controls and human decision-making can create opportunities for cybercriminals even where technical security systems are in place.
The report also warned that the actual scale of cybercrime across Africa could be considerably higher than available statistics indicate because of gaps in incident reporting, digital evidence collection and coordinated threat intelligence.
Nigeria is meanwhile entering a more stringent cybersecurity compliance environment. The Central Bank of Nigeria introduced its Cybersecurity Self-Assessment Tool in March 2026, strengthening oversight of cybersecurity controls within regulated financial institutions.
Requirements under the Nigeria Data Protection Act also place additional pressure on organisations, including obligations surrounding the reporting of qualifying personal-data breaches.
Adediran said ransomware and targeted phishing attacks could intensify as companies increasingly adopt electronic invoicing and real-time transaction reporting. She pointed to zero-trust security models and stronger identity verification as important components of a modern cybersecurity framework.
The cybersecurity talent shortage is another concern. The report cited an estimated 4.8 million unfilled cybersecurity positions globally, potentially limiting organisations’ ability to prevent, detect and respond to attacks.
In Ghana, cybersecurity governance is also moving further into the boardroom, with regulatory requirements placing greater responsibility on company directors and increasing scrutiny of third-party technology and service providers.
The report recommended stronger oversight of vendors, improved board-level cybersecurity reporting, identification of hidden system vulnerabilities, enhanced protection against social-engineering attacks and regular testing of security controls.
As African businesses become more dependent on digital transactions and interconnected systems, cybersecurity is increasingly becoming a governance, financial, operational and regulatory risk rather than solely an information-technology issue.



No Comment! Be the first one.