AI-powered scams: what INTERPOL reveals and how to protect yourself
On 3 August 2026, INTERPOL published its 2026 African Cyberthreat Assessment. The finding is clear: artificial intelligence is now involved in 55% of reported cybercrimes on the continent, and losses related to cybercrime have more than doubled since 2024, rising from 192 to 484 million dollars.
Chad is not spared. According to a study by the Institute for Security Studies (ISS) published on 11 August 2026, scammers there specifically target young people looking for work and vulnerable individuals, especially via SMS and phone calls. Here is what you need to know, followed by good practices to adopt depending on your level: beginner, intermediate or advanced.
The Essentials
- More than one in two cybercrimes reported in Africa uses AI: flawless messages, imitated voices, fake videos.
- In Chad, scams mainly happen via SMS, calls and messaging apps: fake job offers, false winnings, bogus advisers.
- The best protection remains simple: never share a code, verify through another means, take your time.
What the INTERPOL report reveals
Drawn from the responses of 36 African countries, the report describes cybercrime having evolved from isolated acts into a genuinely organised, borderless system. In 2025, online scams remained the most reported cybercrime, and 72% of surveyed countries reported "scam centres", where teams run mass scams.
The report also highlights regional trends. In Central and West Africa, business email compromise (BEC), which involves hacking or impersonating professional messaging systems, and romance scams are particularly widespread: they target both businesses and individuals. Finally, sextortion and online harassment, often supported by "deepfakes" (images, videos or voices generated by AI), remain very prevalent.
In Chad: SMS, calls and fake job offers
According to the ISS, scammers take advantage of the rapid digital growth in Cameroon and Chad to trap young job seekers with fake offers posted on WhatsApp and Facebook. In Chad, where internet connection is less widespread, they favour compromised SMS messages and calls. Victims lose their savings by paying "fees" in advance; in the most severe cases, some are taken abroad and exploited.
These scams almost always follow the same scenario: a promise (a job, a scholarship, winnings, a gift), a sense of urgency, followed by a request for money or a code. Among the most common variations: the fake agent from your operator claiming your Mobile Money secret code, the transfer received "by mistake" that you are asked to refund, or the relative writing to you from a new number for an urgent expense.
The authorities are organising themselves: in June 2026, a decree appointed the heads of a new cybercrime combat unit within ANSICE, the National Agency for Computer Security and Electronic Certification.
Why AI makes these scams more dangerous
- Flawless messages, in polished French and tailored to each individual based on what they post on social media. The old reflex of thinking "there are mistakes, so it's a scam" is no longer enough.
- Imitated voices: a short recording, a voice note for example, can be enough to imitate the voice of a loved one or a manager.
- Fake videos of public figures promoting "guaranteed" investments or miraculous investment platforms.
- Volume: AI makes it possible to target thousands of people at once. As a result, according to INTERPOL: faster attacks, on a larger scale and more difficult to detect, both for victims and platforms.
What you can do, depending on your level
Beginner level: good habits for everyone
- Never share a code: Mobile Money secret code, code received by SMS for WhatsApp, bank validation code. Neither your operator, your bank, nor a loved one should ever ask you for it.
- Enable two-step verification on WhatsApp (in settings, under the Account section): this adds a personal six-digit code, which is requested when installing WhatsApp on a new phone. The code received by SMS is then no longer enough to take over your account.
- Beware of urgency: "last chance", "your account will be blocked", "send quickly"... Urgency is used to stop you from thinking.
- Verify by another means: a loved one asks you for money via message or voice note? Call them back on their usual number before sending anything.
- A job, a scholarship or a visa cannot be bought: an offer that demands "processing fees" in advance is almost always a scam.
- Check your balance in the app or your operator's menu before "refunding" a transfer received by mistake: the SMS may be fake.
If you are a victim, act quickly: contact your operator's or bank's customer service to block the transaction or account, change your passwords, keep the evidence (screenshots, numbers, receipts) and file a complaint. Talk about it around you: silence benefits scammers.
Intermediate level: businesses, NGOs and government bodies
- Verify every unusual payment request: an urgent transfer or a change of a supplier's bank details must be confirmed by calling a previously known number, never the one provided in the message.
- Require two validations above an amount that you set, even when the request seems to come from management.
- Agree on a code word for urgent requests made by phone: a voice can now be imitated.
- Enable multi-factor authentication on your organisation's messaging services, online bank accounts and social media pages.
- Raise awareness regularly: short reminders based on real examples are better than a long presentation once a year.
- Make reporting easier: everyone must know who to forward a suspicious message to, without fear of being judged.
Advanced level: IT teams
- Protect your domain name against spoofing with SPF, DKIM and DMARC, gradually moving from simple monitoring (p=none) to quarantine, and then to rejection.
- Choose phishing-resistant authentication for sensitive accounts: security keys or passkeys rather than SMS codes.
- Monitor email systems: unusual logins, new automatic forwarding rules, access from unexpected countries. These are classic signs of hacking prior to invoice fraud.
- Protect workstations: regular updates, next-generation antivirus (EDR) and tested offline backups.
- Prepare your incident response: who decides, who to notify (management, bank, operator, authorities), how to preserve evidence.
- Train your teams with phishing simulations, and measure progress over time.
Key Takeaways
AI does not create new vulnerabilities: it exploits existing ones faster and on a wider scale, namely trust, urgency and shared codes. A code should never be given away, a money request must always be verified, and an important account must be protected by two-factor authentication.
To raise awareness among your teams or review the security of your accounts and email, discover our Cybersecurity and Corporate Training services.
Sources : INTERPOL, 2026 assessment of cyberthreats in Africa (3 August 2026) ; ISS, "Digital deception: online job scams and cybercrime in Cameroon and Chad" (11 August 2026) ; Alwihda Info, ANSICE cybercrime unit (1 June 2026).