The problem is no longer only whether a system can be hacked
For years, organisations were taught to ask whether an email was genuine, whether a caller was who they claimed to be, whether a document had been altered, or whether a website looked legitimate.
Artificial intelligence is changing those assumptions.
A convincing phishing message can be generated quickly. A criminal can imitate the communication style of an executive. Audio and video can be manipulated or generated. Personal information can be combined with fabricated details to create a more convincing identity. Automated tools can also accelerate reconnaissance, social engineering and vulnerability discovery.
Kenya is not watching this from a distance
The threat is not simply a futuristic scenario. Kenya's cybersecurity authorities have been warning about the changing threat environment and the growing role of AI in fraud and cyber attacks.
The Communications Authority of Kenya's National KE-CIRT/CC has reported that social engineering attacks—including phishing, vishing, smishing and AI-generated deepfake scams—have intensified. Its cybersecurity reporting has specifically described AI-generated emails and voice impersonation of executives being used to facilitate fraud and business email compromise. The Authority has promoted phishing-resistant authentication, including passkeys and biometrics, together with awareness focused on voice deepfakes. Read the National KE-CIRT/CC report.
The Communications Authority has also warned that generative AI can make fraudulent content more credible and that machine learning and automation can help malicious actors develop adaptive malware and other threats. See the Communications Authority advisory.
NC4, Kenya's national computer and cybercrimes coordination body, provides incident reporting, cyber-hygiene guidance, response coordination and resilience resources for organisations and critical entities. Its current guidance stresses immediate containment, preservation of evidence, reporting and recovery after incidents. See NC4 guidance.
AI phishing: the message can look right even when it is wrong
Traditional phishing often contained obvious clues: poor grammar, unusual wording, suspicious links or inconsistent branding. Those clues are becoming less dependable.
AI can help attackers produce polished messages, adapt language to the target and scale personalised social engineering. Kenya's National KE-CIRT/CC has specifically identified increased AI-enabled automation alongside phishing and social engineering. See the latest available National KE-CIRT/CC threat-vector report.
For a finance team, procurement officer or business owner, the consequence is practical: the old rule of “look carefully at the email” is no longer sufficient for high-value decisions.
High-risk requests should be independently verified using a trusted channel, especially where the request involves payments, credentials, access changes, bank details, supplier changes or sensitive information.
Voice cloning changes the meaning of “I spoke to them”
Voice cloning creates a particularly difficult social-engineering problem because people naturally use voice familiarity as a trust signal.
Consider a simple business scenario. A finance employee receives a voice message that appears to come from a senior executive. The request is urgent. The name and profile photograph are familiar. The voice sounds right. The message asks for a payment or supplier-account change.
The security control cannot simply be “listen carefully.” The stronger control is independent verification of the transaction.
This is why AI-driven fraud is not only a technology problem. It is also a business-process problem involving authority, approval workflows, identity assurance and separation of duties.
Deepfakes: when seeing is no longer proof
Deepfakes can manipulate or generate realistic audio, video and imagery. Kenya's cyber-security guidance has previously highlighted the use of audio deepfakes in social-engineering scams and the difficulty of distinguishing manipulated media from genuine content. See the National KE-CIRT/CC deepfake guidance.
The business lesson is not that every video call is fake. It is that visual or audio familiarity should not be the sole authentication factor for a high-impact action.
Organisations should combine identity controls, transaction controls, independent confirmation, strong authentication and monitoring rather than relying on one signal.
Mobile money makes digital trust especially important in East Africa
East Africa's digital economy has a distinctive feature: mobile money is deeply integrated into everyday commercial and personal transactions. That creates enormous convenience, but it also creates a valuable target for fraudsters.
INTERPOL's African Cyberthreat Assessment Report 2026 identifies East Africa as a hub for mobile-money fraud and infrastructure-targeted ransomware. The report says AI is linked to 55% of reported cybercrime across Africa and describes the increasing use of AI in phishing, social engineering, business email compromise and synthetic identities. Read INTERPOL's 2026 African Cyberthreat Assessment.
INTERPOL also reports that criminals are combining real personal information with fabricated elements to create synthetic identities that can be used to open accounts, obtain mobile loans and register SIM cards under false names. This is a fundamental digital-trust problem: identity itself can become an attack surface.
What INTERPOL says is changing across Africa
INTERPOL's 2026 assessment describes cybercrime across Africa as increasingly industrialised and borderless. Its analysis draws on information from 36 African member countries and identifies AI-enabled scams, credential harvesting and automated social engineering among the forces driving increased cybercrime losses. It also highlights the need for stronger information sharing among banks, telecommunications providers and law-enforcement agencies.
That matters for businesses because an attack may no longer fit neatly inside the boundary of one organisation. A compromised identity, mobile number, supplier relationship, cloud account or payment process can connect several organisations in a chain.
AI is also changing the speed of vulnerability discovery
AI-powered deception is only one side of the problem. AI can also accelerate technical discovery and exploitation.
EY's Africa Cybersecurity Threat Outlook 2026 identifies two important AI-related shifts: AI-enabled deception, including deepfakes and synthetic identities, and AI-accelerated vulnerability discovery and exploitation. EY notes that African organisations often face patch-management constraints caused by legacy platforms, maintenance windows and operational environments that cannot easily be patched.
The implication is important: organisations cannot assume that a vulnerability will remain harmless simply because it has not yet been exploited in their environment.
That makes continuous exposure management, prioritised remediation, segmentation, strong identity controls and continuous monitoring increasingly important. Read the EY Africa Cybersecurity Threat Outlook 2026.
The biggest change: identity is becoming a primary security boundary
EY's 2026 Africa threat outlook describes identity as a primary attack surface. That is a useful way to understand the shift.
A traditional security programme may concentrate heavily on firewalls, antivirus and network perimeter controls. Those remain important. But modern organisations also need to ask:
- Who is this user?
- How was the identity authenticated?
- What access does the identity have?
- Can a privileged action be independently verified?
- What happens if an account is compromised?
- Can unusual behaviour be detected quickly?
- Can the organisation contain the incident and preserve evidence?
This is why digital trust has to be designed across the whole technology environment—not added as a single AI-detection product.
What Kenyan organisations should change now
1. Verify high-impact requests independently
Use an established second channel for payment changes, credential requests, supplier changes and privileged actions. Do not rely on the apparent identity of the message alone.
2. Strengthen authentication
Use phishing-resistant MFA where practical, protect privileged accounts and reduce unnecessary administrative access.
3. Test applications and APIs
VAPT and application security testing can identify weaknesses before attackers combine them with stolen identities or social-engineering access.
4. Segment critical systems
Do not allow one compromised account or endpoint to provide a simple route into the whole environment.
5. Improve endpoint and email protection
Use layered controls for endpoints, email, identities and web access, supported by monitoring and clear escalation procedures.
6. Establish an AI-use policy
Define what employees may put into public AI services, how sensitive data is handled and which AI applications require security review.
7. Monitor continuously
Security controls should generate useful signals and support timely investigation rather than waiting for an annual audit.
8. Prepare for the first 72 hours
Know who contains an incident, who preserves evidence, who reports it, who communicates with customers and who coordinates recovery.
Do not respond to AI threats by buying “another AI tool”
The answer to AI-enabled cybercrime is not automatically another AI product.
A more durable approach is to understand the organisation's actual exposure, identify the attack paths that matter, strengthen identity and access controls, test applications and infrastructure, segment critical systems, improve monitoring and establish clear response procedures.
AI can then be used where it genuinely improves defensive capability—for example, security analytics, detection, vulnerability prioritisation, automation and incident triage.
What this means for CEOs, CFOs, CIOs and IT managers
The board-level question is changing from “Do we have cybersecurity?” to “Can we demonstrate that the controls protecting our people, identities, applications, transactions and critical systems work when an attacker deliberately tries to defeat them?”
For a finance leader, that may mean stronger payment verification. For an IT manager, it may mean identity hardening, network segmentation and endpoint protection. For a development team, it may mean application and API security testing before go-live. For a CISO or risk leader, it may mean continuous exposure management, monitoring and evidence-based assurance.
Quest's approach is to connect these layers rather than treat cybersecurity as a collection of disconnected products.
From AI risk to measurable cyber resilience
AI has changed the threat landscape, but it has also made one cybersecurity principle more important: know what matters, test it, protect it, monitor it and be ready to respond.
Organisations in Kenya and across Africa do not need to predict every future AI attack. They need to reduce the opportunities an attacker can exploit today and build controls that can adapt as the threat changes.
That starts with understanding the organisation's current exposure.
Is your organisation ready for AI-enabled deception?
Quest Technologies helps organisations assess cyber exposure across identities, networks, applications, endpoints and business processes, then translate findings into practical security improvements.
Cybersecurity • Secure Networking • Digital Risk Assurance
Kenya & East Africa
Authoritative sources and further reading
- INTERPOL — African Cyberthreat Assessment Report 2026
- Communications Authority of Kenya / National KE-CIRT/CC — Cyber Security Report Q4 2024/2025
- Communications Authority of Kenya / National KE-CIRT/CC — Cyber Security Report Q2 2025/2026
- NC4 Kenya — National cybersecurity coordination, incident reporting and resilience guidance
- NC4 — Kenya Faces Growing Cybercrime Pressure as Digital Threats Escalate
- EY — Africa Cybersecurity Threat Outlook 2026
Editorial note: Threat statistics and observations in this article are attributed to the organisations and reports cited above. They describe reported or assessed cyber activity and should not be interpreted as proof that every organisation or every incident uses AI.
