SOC status: Operational/Continuous monitoring active

Acronis MDR / XDR available +230 5254 7558

MediumReportTLP: CLEARCBN-2026-033 · 26 Aug 2026

INTERPOL on Africa: AI in more than half of reported cybercrime, and a Black Axe network dismantled

Two INTERPOL publications this month bear directly on Mauritian businesses. Reported losses across the continent more than doubled to USD 484 million, and an eight-month operation against West African BEC networks produced 58 arrests across 22 countries.

At a glance

Affected

Any Mauritian organisation that pays suppliers on emailed instructions — management companies, trust companies, freight forwarders, hotel groups, professional services.

Impact

Business email compromise remains the primary revenue technique of these networks, and adversary-in-the-middle tooling defeats one-time-code MFA, which is still common in the local market.

Action

Move payment-change verification off email to a callback on a pre-registered number, deploy FIDO2 or passkeys for anyone who can authorise payments, and require dual authorisation for new beneficiaries.

Client status

We include supplier-payment fraud in every tabletop exercise we facilitate. It is the control gap most often found in Mauritian finance functions.

Detail

INTERPOL's African Cyberthreat Assessment Report, published on 3 August, links artificial intelligence to 55% of reported cybercrime across the continent — applied across reconnaissance, phishing content and extortion rather than at any single stage. Reported losses more than doubled since 2024, from USD 192 million to USD 484 million. The report draws on survey data from 36 African member countries plus telemetry from Fortinet, Mastercard, the Shadowserver Foundation, S2W and TrendAI.

Three weeks later INTERPOL announced the results of Operation Jackal IV, an eight-month action against West African organised crime networks, principally Black Axe: 58 arrests, 263 suspects identified, 22 countries. South Africa accounted for the largest national share — 39 arrests, USD 2.67 million seized, 257 bank accounts blocked. Romanian authorities attributed EUR 143 million in global investment-scam losses to the network they disrupted; in Italy a single account laundered EUR 845,000 across 560 transactions.

Why a Mauritian board should care

Black Axe's core revenue technique is business email compromise against organisations that move money on emailed instructions. That is the daily operating mode of a great deal of the Mauritian economy — management companies settling client disbursements, freight forwarders paying overseas carriers, hotel groups paying foreign suppliers.

There is a second exposure that gets less attention. The South African seizure figures show these networks bank and launder within the SADC region. A Mauritian financial institution can therefore be exposed twice: once as the fraud victim, and once as an unwitting correspondent in someone else's laundering chain.

The AI finding compounds it. Mauritian staff have historically relied on linguistic tells — awkward English, odd French — to spot fraudulent instructions. Generated text removes that signal entirely, and INTERPOL's investigators documented adversary-in-the-middle tooling alongside the social engineering, which defeats one-time-code MFA.

Two controls, in order of value

First: no bank-detail change is actioned on the strength of an email, ever. A callback to a number already held on file, made by someone other than the person who received the request, with a mandatory cooling-off period before the first payment to a new account. This single procedure defeats the overwhelming majority of BEC attempts and costs nothing but discipline.

Second: FIDO2 security keys or passkeys for anyone who can authorise or amend a payment. A proxy phishing kit cannot replay a hardware-bound credential. One-time codes are no longer adequate for treasury functions.

The regulatory tail

Where a compromise results in unauthorised disclosure of personal data, the Data Protection Act 2017 requires notification to the Data Protection Office within 72 hours. Suspicious transaction reporting sits separately under Mauritian anti-money-laundering law. Both clocks start before you have finished understanding what happened, which is why the notification decision belongs in the incident plan rather than in the incident.

If you find evidence of this activity, do not begin remediation before preserving evidence — console and appliance audit logs are frequently short-retention and will roll off. Acronis MDR provides around-the-clock detection and response for covered estates; otherwise reach us through the contact page and we will advise on preservation before containment.

Sources

Cybernalyst's analysis and recommendations are our own. The underlying research is credited below — please read the original reporting.

  1. INTERPOL report finds AI linked to more than half of cybercrime in AfricaINTERPOL·3 August 2026
  2. AI Accounts for Over Half of Cybercrime in Africa, Says InterpolPhil Muncaster·Infosecurity Magazine·4 August 2026
  3. 58 arrests in global effort to dismantle West African organized crime groupsINTERPOL·25 August 2026
  4. Interpol targets Black Axe's illicit financial web in latest international stingGreg Otto·CyberScoop·25 August 2026