As more Africans bank, shop and work online, cybercriminals have followed. Mobile money fraud, SIM swaps, phishing, fake investment schemes, business email compromise and ransomware affect individuals, small businesses and governments across the continent. The good news is that a handful of basic habits block most attacks. This guide explains the main threats and what to do about them.
The most common threats
1. Phishing and social engineering
Fraudsters impersonate banks, mobile money operators, employers, delivery companies or government agencies through SMS, WhatsApp, email or phone calls, trying to trick you into revealing PINs, passwords or one-time codes. Learn the warning signs in How to Spot Phishing and Mobile Money Scams.
2. SIM swap fraud
Criminals persuade or bribe someone to transfer your phone number to a new SIM, then use it to receive your banking codes. See SIM Swap Fraud: How It Works and How to Protect Yourself.
3. Account takeover
Weak or reused passwords let attackers break into email, social media and WhatsApp accounts, then scam your contacts. Two-factor authentication is the best defence; read Two-Factor Authentication Explained.
4. Investment and online shopping scams
Ponzi schemes, fake crypto platforms and non-existent online shops promise high returns or bargain prices. If returns are guaranteed and very high, it is almost certainly a scam.
5. Business email compromise
Attackers hijack or imitate a supplier’s or executive’s email and ask for payment to a new bank account. Always confirm payment changes by phone using a number you already have.
6. Ransomware
Malicious software encrypts an organisation’s files and demands payment. Hospitals, utilities, government agencies and companies in Africa have all been hit. See Ransomware: What African Businesses Need to Know.
7. Malicious apps
Fake apps, including predatory loan apps and pirated software, can steal data or money. Install apps only from official stores and check the permissions they request.
Ten habits that stop most attacks
- Never share PINs, passwords or one-time codes with anyone, including “customer care”
- Use a unique password for every important account, stored in a password manager
- Turn on two-factor authentication, preferably with an authenticator app
- Set a SIM PIN and ask your operator about extra protection against SIM swaps
- Keep your phone, computer and apps updated
- Install apps only from official app stores
- Back up important files to the cloud or an external drive
- Check links before clicking and type bank addresses yourself
- Verify payment requests through a second channel
- Lock your phone with a PIN, pattern or biometrics
Extra steps for small businesses
- Give each employee their own account; remove access when people leave
- Use business email with two-factor authentication enforced
- Keep offline or immutable backups and test restoring them
- Train staff to recognise phishing and fake payment requests
- Know your data protection obligations, including breach reporting; see Data Protection Laws in Africa
- Write a simple incident plan: who to call, how to isolate systems, how to notify customers
What to do if you are a victim
- Contact your bank or mobile money provider immediately using official numbers to block accounts and attempt to reverse transactions
- Change passwords and sign out other sessions
- Report to the police and your national cybercrime or CERT unit where available
- Warn your contacts if your accounts were used to scam others
- Keep evidence: screenshots, numbers, transaction references
Cybersecurity as a career
Africa needs far more cybersecurity professionals than it has. If you are interested in the field, see our digital skills roadmap.

