Cyberthreats detected across Africa in 2025 highlight a diverse range of methods used by threat actors to execute digital attacks, according to findings from the INTERPOL African Cyberthreat Assessment Report 2026.

Attack types—defined as the specific methods utilised to carry out a cyberattack—show a heavy reliance on malicious software and social engineering tactics.

Ransomware attacks emerged as the single largest threat category, accounting for 28 per cent of all detected incidents on the continent.

Traditional malware attacks followed closely, representing 22 per cent of total detected cyberthreats. Combined, these two categories comprise half of the attack vector landscape in the region.

Social engineering tactics also constitute a substantial portion of detected incidents. Email social engineering accounted for 15 per cent of attacks, while pretexting social engineering made up 9 per cent.

Preliminary attack stages were prominently recorded as well, with reconnaissance and weaponisation comprising 14 per cent of total cyberthreat detections across Africa.

Other attack vectors accounted for smaller, distinct shares of overall detected activity. Denial of service attacks represented 6 per cent of incidents.

Meanwhile, mobile service attacks and the exploitation of legitimate tools each accounted for 3 per cent of detected threat methods.

The metrics underscore how modern cyber intrusions rely on varied tactics, ranging from direct software exploitation to human-targeted social engineering and initial system reconnaissance.