A padlock secures a computer keyboard. As cyber threats evolve, businesses and individuals face growing risks to their digital security. Photo Credit: FlyD/Unsplash
Getting your Trinity Audio player ready...

By Liz Anyango

Nairobi, Kenya: A message arrives on your phone. It appears to come from your bank. It looks genuine, uses the right logo and may even sound like the kind of message your bank normally sends. You click the link.

That simple action could give a cybercriminal access to information they need to steal money, impersonate you or gain entry into other accounts.

Now, that same message could be created using artificial intelligence, making it more convincing and allowing criminals to produce thousands of similar messages in a short time.

This is the changing face of cybercrime, and the threat is no longer only about criminals sending more attacks. Artificial intelligence is helping them make those attacks faster, more scalable and harder to detect.

The scale of the shift is becoming clearer across Africa. The 2026 INTERPOL African Cyberthreat Assessment Report says artificial intelligence is linked to 55% of reported cybercrime across the continent, with criminals using AI to automate activities from phishing and reconnaissance to extortion and evasion.

“Kenya is already seeing the scale of the wider cyber threat”

Between October and December 2025, more than 4.5 billion cyber-threat events were detected by Kenya’s National Computer Incident Response Team Coordination Centre (KE-CIRT/CC), according to its quarterly cybersecurity report.

The numbers may sound distant from everyday life. But behind them are the emails that look like they came from your bank, the messages asking you to click a link, the fake investment opportunities and the social media accounts designed to trick people into handing over money or personal information.

Now artificial intelligence is adding another layer to the problem.

For Filippo Monticelli, Senior Vice President, EMEA South at Fortinet, a global cybersecurity company that provides solutions for detecting, preventing and responding to cyber threats, this is where the next major cybersecurity challenge lies.

“The fact that incidents will happen is certain,” Monticelli says.

His point is not that organisations should give up trying to prevent attacks. Rather, as criminals become more sophisticated, organisations must also become better at detecting threats, responding quickly and containing damage when an attack gets through.

This is particularly important because artificial intelligence can help criminals operate at a scale that would have been difficult for an individual attacker.

Think of it this way: instead of a criminal manually writing ten convincing scam messages, AI can help create hundreds of personalized messages in a much shorter time. A convincing email can be produced, altered for different victims and sent at scale.

Filippo Monticelli, Senior Vice President, EMEA South at Fortinet, addresses journalists during a press briefing. Fortinet provides cybersecurity solutions that help organisations detect, prevent and respond to cyber threats.

Monticelli warns that the threat could become even greater as criminals increasingly use what are known as autonomous or “agentic” systems, where AI can carry out parts of a task with limited human supervision.

The concern is not only about stolen passwords or fraudulent transactions.

As Kenya’s economy becomes more dependent on digital systems, an attack on one organisation can have consequences beyond that organisation. The growing interconnection between financial institutions, telecommunications companies, energy providers, government systems and other critical infrastructure means a cyberattack can quickly affect services beyond its initial target.

Monticelli says the interconnected nature of these systems makes every sector vulnerable.

“There’s no specific sector which is safe nowadays,” he says.

This means cybersecurity is no longer simply a problem for an organisation’s IT department.

For ordinary Kenyans, these risks are already tangible. Safaricom’s M-PESA, one of the country’s most widely used digital financial services, has had to strengthen its defences against fraud including SIM-swap attacks and social engineering.

In a previous Talk Africa article, we looked at how Safaricom’s M-PESA Fintech 2.0 upgrade is using artificial intelligence to detect suspicious activity and strengthen fraud prevention as mobile money becomes increasingly central to the economy.

Africa is facing the same challenge as digital services expand across the continent. INTERPOL says Africa will have more than 1.1 billion mobile subscribers in 2025, while cybercriminals are increasingly exploiting mobile money platforms, social media and other digital services.

The scale of organised cybercrime was demonstrated earlier this year when authorities in 16 African countries took part in an INTERPOL-coordinated operation targeting online scams. The operation resulted in 651 arrests and the recovery of more than US$4.3 million, while investigations uncovered scams linked to more than US$45 million in financial losses. 

In Kenya, 27 people were arrested in connection with fraudulent investment schemes.

The response, therefore, cannot depend on technology alone.

Monticelli argues that Africa also needs to invest in skills and education, including teaching people basic “cyber hygiene” from an early age.

The principle is simple: just as people learn basic habits to protect their physical health, internet users need basic habits to protect themselves online.

That could mean stopping before clicking an unexpected link, checking whether a request for money is genuine, protecting accounts with stronger authentication and questioning information that appears too good, or too alarming to be true.

And there is another emerging challenge for Kenya: the 2027 General Election.

Artificial intelligence is making it easier to create convincing fake photographs, videos, voices and messages. A fabricated video of a political leader, for example, could be shared thousands of times before the public gets a chance to establish whether it is genuine.

The Independent Electoral and Boundaries Commission has identified cybersecurity, AI-driven misinformation and deepfakes among emerging threats that could affect the 2027 election.

For journalists, this creates a new responsibility but Monticelli says AI can also be part of the solution.

Rather than simply fearing AI-generated misinformation, he advises journalists and other users to use AI defensively to analyse information, check sources and identify inconsistencies, while still applying human judgement.

That Last Part is Important

AI can help verify information, but it should not become the journalist’s replacement for verification.

As Kenya moves deeper into the digital age, the cybersecurity question is therefore becoming less about whether an attack will happen and more about how prepared the country is when it does.

Technology will continue to evolve. So will the criminals using it.

Kenya’s strongest defence may ultimately depend not only on better systems, but on better prepared institutions, skilled professionals and citizens who know when to stop, question and verify before they click.

LEAVE A REPLY

Please enter your comment!
Please enter your name here