AppCraft.Africa

Cyber defence · identity · AI security

The attacker already uses AI. A wall cannot stop what is written fresh each morning.

AI-driven crime in Africa is growing faster than the defences built against it, and those defences were designed for a slower enemy. We do not sell another wall. We build a digital immune system — one that watches continuously, learns from every attack, answers in seconds, and does not depend on any single foreign supplier to keep working.

55%

Of all reported cybercrime in Africa in 2025 was AI-enabled. This is now the normal case, not the exotic one.

INTERPOL — Africa Cyberthreat Assessment, 2026

$5 bn

Direct economic losses across Africa in 2025. Reported financial losses rose 152%; identified victims went from 35,000 to 87,000.

INTERPOL, 2026

+393%

Rise in Africa’s deepfake fraud rate in a single year.

Sumsub — Identity Fraud Report, 2024

What changed

The attack is generated, the target is the person, and your own AI is a door.

01

A convincing attack now costs almost nothing to make.

An employee at the engineering group Arup joined a video call with people who looked and sounded like his chief financial officer and his colleagues. Every one of them was generated. He made 15 transfers totalling about $25.6 million in a single day. No system was breached. No password was stolen. The controls were fine; the human trusted his own eyes. In Southern Africa, 87% of failed biometric checks are now AI-assisted impersonation, not physical forgery.

Hong Kong Police and Arup, 2024 · Smile ID — Digital Identity Fraud in Africa

02

It is not only banks. Governments are being hit in public.

On 18 July 2026 the official website of the President of Kenya was defaced and a ransom of 5 Bitcoin was demanded. It was the third major public-sector cyber incident in Kenya in three years. In 2023 an attack on the eCitizen platform paralysed access to more than 5,000 government services across ministries, counties and agencies. Kenya’s estimated loss to cyberattacks is about 3.6% of GDP.

Daily Nation · ITWeb Africa · INTERPOL — Africa Cyberthreat Assessment, 2026

03

And now AI itself is the newest way in.

Organisations are rushing AI into production without controlling it. Of the organisations that suffered an AI-related security incident, 97% had no proper access controls on their AI. 63% have no AI governance policy at all. One in five breaches involved shadow AI — tools staff adopted with no security approval — and those breaches cost an extra $670,000 each.

IBM — Cost of a Data Breach 2025 · World Economic Forum — Global Cybersecurity Outlook 2026

The conclusion a board should draw

These three facts point the same way. The attack is generated, so it is always new. The target is the person, not the firewall. And the AI you deploy to defend yourself is itself an unguarded door. A static perimeter cannot answer any of that. A living system can.

The approach

We do not build a wall. We build an immune system.

A wall knows one thing: the list of attacks it was built against. An immune system knows what belongs to the body and what does not, and it works that out again every second. That is the only design that survives an enemy who writes new attacks faster than you can list them.

It recognises

Continuous checking of who is acting, from where, on what — behaviour, identity and media, all at once. Not a rule list. A live picture of normal.

It remembers

Every attack seen anywhere in the system becomes a signal everywhere in it, within hours. The second institution hit by a fraud kit should not learn it from scratch.

It responds locally

Blocking, stepping up authentication and freezing a session happen at the point of attack in seconds — before a report reaches a human analyst.

It is distributed

No single organ, no single supplier, no single country holds the whole defence. Removing any one part degrades it; it does not switch it off.

The part that makes it real

Two teams, in permanent competition.

Red team — attacks

  • deepfakes your executives, clones voices
  • forges documents, breaks the login
  • runs prompt attacks against your AI

Your system

  • identity · channels · call centre
  • onboarding · payments · your AI

audited from both sides

Blue team — defends

  • detection, identity controls
  • response, monitoring, governance
  • closes what the red team opened

Every finding becomes a detection the same week.

One of our teams builds and defends. The other attacks the same system, using exactly the tools a real attacker would use today — generated video and voice of your own executives, forged documents, stolen credentials, and prompt attacks against your AI. They compete. What the attacking team finds on Monday becomes a working detection on Friday. You can hire either side, or both, and you can audit your existing supplier from the attacking side. Defence that has never been attacked is an opinion, not a control.

What we deliver

Six lines of work, under one accountable contract.

Identity and access

Multi-factor and biometric authentication and single sign-on — the strong authentication central banks now require, since SMS codes no longer count. Privileged accounts, session recording and vendor access under control. Certificates and public-key infrastructure. Identity threat detection and response. We integrate, localise and operate the whole layer.

Hardware, not only software

Smart cards and readers, biometric scanners and hardware tokens for physical and logical access control — issued, managed and revoked from the same place as digital identity. Control mappings exist for PCI DSS and for regional financial-sector frameworks.

AI-era KYC and media forensics

Our own detectors for generated and edited images, cloned voices and forged financial documents — wired into onboarding, lending, claims and the call centre. Deployed on your premises or as an API. We pair every model with human review and we never promise a fixed catch rate. The image detector runs live in the browser; the voice-clone and forged-document detectors are shown live on a call.

Live in the browser

Security for your AI

Access control on models, defence against prompt injection, removal of personal data before anything leaves the perimeter, discovery of shadow AI already in use, a full audit record of every model call, and a written AI governance policy your regulator can read.

Offensive audit and readiness drills

Penetration testing, red-team exercises, and a deepfake drill against your own executives and call-centre staff — so the first synthetic voice they hear is ours, not a criminal’s.

Sovereign deployment

The whole stack runs inside your perimeter or in-country. Outside vendors are used to check and validate results — never to hold your customer data. Several suppliers do the work; none of them holds the keys.

The wider ambition

One institution can be defended. A continent has to be.

The same fraud kit that hits one bank in Lagos on Monday reaches Nairobi and Johannesburg by Friday. Defending each institution alone means every one of them pays to learn the same lesson. We build the shared layer that removes that waste — and build it so no foreign supplier can switch it off.

Shared signal, private data

Institutions and regulators exchange threat signals — attack patterns, forged-document signatures, voice fingerprints. Customer data never crosses a boundary. What is shared is the shape of the attack, not the identity of a person.

Independent of any AI supplier

Detection runs on several models from several vendors, and on private models on local hardware. A price change, an export rule or a regional block cannot disable a national defence. This is a design requirement, not a preference.

Inside the perimeter, checked from outside

Each institution runs its own copy inside its own network. External vendors serve as a second opinion, under strict limits on what they are allowed to see.

African data, African law

By the end of 2025, 44 of 55 African countries had data-protection laws in force. Several require a regulated institution’s primary data to stay in the country. We design around that, market by market.

Digital Policy Alert — Data Protection in Africa Roundup 2025

The regulator is already moving

Five markets, one direction of travel.

Market Penalty exposure today What supervisors now require
Nigeria ₦10m or 2% of revenue CBN Risk-Based Cybersecurity Framework 2024. A ₦766m fine was issued in 2025.
Kenya KSh 5m or 1% of turnover CBK cybersecurity guidance. Over 110 enforcement decisions issued in 2025.
South Africa R10m and up to 10 years SARB and FSCA Joint Standard 2 of 2024. First fines already issued.
Rwanda 1–5% of turnover, plus prison BNR regulation. A bank’s primary data must stay in Rwanda.
Tanzania TZS 100m, plus criminal liability BoT draft guidelines: board-approved strategy, annual penetration tests, 24-hour reporting.

All five move the same way: strong authentication, privileged-access control, tested defences, 24-hour reporting — each a line item we deliver. Exact penalties are governed by the regulation in force in each jurisdiction.

CBN Framework 2024 · CBK guidance · SARB and FSCA Joint Standard 2 of 2024 · BNR regulation · Bank of Tanzania draft guidelines

Why AppCraft

We build the defence, and we hold the contract.

An engineering studio, not a reseller

Working together since 2011. Over 400 products across four continents, more than 100 in-house engineers in design, backend, machine learning and security. Five ventures past $2m in revenue, one acquired by a tier-one telecom operator in 2025. Headquartered in Tbilisi, Georgia.

Delivered under supervision

Banks, telecom operators and government bodies across the CIS, the Gulf and South-East Asia — markets with strict audit, data-residency and on-premise rules.

One accountable contract

Build, detection, identity and governance under one agreement — not four procurements that blame each other when something fails.

How we start

Three steps, and the first one costs you an afternoon.

01

A risk session

Two to three hours with the people who own identity, fraud and the exposed channels. We agree where you are open.

02

One drill or one pilot

A controlled attack on one channel, or one detection layer deployed on your premises. Small, real, finished in weeks.

03

A written page in 7 days

What we found, what it takes to close it, and what we recommend you do not spend money on.

Tell us which channel you would attack first.

Send a short brief, or write directly. We answer with where we think you are open, what a first drill would look like, and what we would not charge you to fix.

The system you are defending is the one we also build — see the AI engineering page.

Sources. INTERPOL — Africa Cyberthreat Assessment, 2025 and 2026 · IBM — Cost of a Data Breach 2025 · World Economic Forum — Global Cybersecurity Outlook 2026 · Sumsub — Identity Fraud Report · Smile ID — Digital Identity Fraud in Africa · Hong Kong Police and Arup on the 2024 deepfake transfer case · Daily Nation and ITWeb Africa on the July 2026 presidency defacement and the 2023 eCitizen attack · CBN Framework 2024 · CBK guidance · SARB and FSCA Joint Standard 2 of 2024 · BNR regulation · Bank of Tanzania draft guidelines · Digital Policy Alert 2025. Figures are drawn from the public sources listed and are current to August 2026.