Urgent.News

What's breaking now, across thousands of outlets.

AI

INTERPOL warns AI could turn stolen Kenyan data into fake identities

Kenyan consumers face a growing cybercrime threat in which criminals can combine stolen personal information with artificial intelligence to create convincing fake identities, according to INTERPOL. The warning is contained in the INTERPOL African Cyberthreat Assessment Report 2026, which says criminals are increasingly using AI not only to steal information but also to create synthetic […]

INTERPOL has issued a warning that AI technology could be used by cybercriminals to transform stolen personal data from Kenyan consumers into convincing fake identities. According to the INTERPOL African Cyberthreat Assessment Report 2026, criminals are increasingly leveraging AI not only for stealing information but also for crafting synthetic identities that can potentially deceive verification systems.

A synthetic identity is not simply fabricated; it can combine genuine personal details of real individuals with fabricated data, creating a new digital persona that appears legitimate to automated systems.

The report highlights that AI has been employed to generate such synthetic identities that bypass Know Your Customer (KYC) checks, potentially enabling criminals to exploit stolen personal information in new ways. This development is especially significant in Kenya, where digital services like banking, mobile money, and telecommunications heavily rely on identity verification.

INTERPOL notes that artificial intelligence is becoming deeply embedded in cybercrime, with 55% of cybercrime cases recorded in 2025 involving AI to some extent. Criminals have been using AI for various activities including reconnaissance, phishing, extortion, and evading detection systems.

The report also underscores AI's role in creating synthetic identities capable of evading KYC checks. It further explains that criminals can utilize AI to generate personalized phishing messages and malware designed to bypass conventional security measures. For Kenyan consumers, the implication is that personal information, even when not directly obtained like passwords or logged-in accounts, can become highly valuable.

Personal data such as names, identification details, telephone numbers, and other information can be combined with fabricated data to construct an identity that looks legitimate to verification systems. This poses a distinct risk compared to traditional account takeover, where attackers typically aim to gain control of existing accounts or SIM cards.

Kenya has already faced substantial issues with identity-related cybercrime. The country witnessed a staggering 327% increase in SIM-swap fraud in 2025, which underscores vulnerabilities in telecom-based authentication methods. SIM swapping involves transferring a victim's mobile number to a SIM card under the control of a criminal.

A successful swap allows the attacker to intercept calls or messages used for account verification. Furthermore, INTERPOL identifies a lack of real-time information sharing among banks, telecommunications companies, and law enforcement as a significant blind spot. Financial institutions can detect suspicious transactions but often lack the technical channels or legal authority to immediately halt SIM swaps or freeze accounts without court orders.

The issue extends beyond SIM cards, as data breaches have become a breeding ground for various forms of cybercrime, including identity theft, business email compromise, ransomware, and mobile fraud. Kenya is among African countries with numerous exploitable vulnerabilities, such as outdated or unpatched routers, vulnerable VPNs, and misconfigured web-based systems.

INTERPOL's warning underscores that the rise of AI is fundamentally altering the value of stolen personal information. It is no longer necessary for criminals to have complete sets of a victim’s credentials; fragments of legitimate information can be combined with fabricated details to create a synthetic identity. This makes personal data invaluable even after the immediate breach has occurred.

Moreover, when identity information is scattered across multiple organizations like banks, telecommunications companies, and digital platforms, the challenge becomes even greater.

Written by urgent.news from People Daily Kenya's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at peopledaily.digital →

More in AI

More from Tuesday 18 August →