AI is making attacks more convincing, putting finance, HR, customer service and other non-technical teams increasingly at risk.
AI was linked to more than half of the cybercrime cases recorded in Africa in 2025, according to INTERPOL’s African Cyberthreat Assessment Report 2026. Southern Africa was
reported as the most targeted country on the continent, accounting for 92% of Africa’s ransomware detections and 70% of its business email compromise detections.
As AI makes attacks more convincing and easier to scale, the risk is moving
beyond the IT department to the teams that can approve a payment, reset a password or grant access.
“Attackers have adopted AI faster than most organisations have learned
Some of the warning signs staff were trained to look for are disappearing.”
Moola says cybersecurtity training needs to extend beyond traditional
security teams and be tailored to the roles most likely to encounter these attacks:
-
Finance teams, which may receive
convincing emails asking them to change a supplier’s banking details or approve an urgent payment. -
Executives and their assistants,
who can be targeted through impersonation, including cloned voices and images used to request transfers or sensitive information. -
HR and recruitment teams, which
may encounter fake candidates using AI-generated CVs and synthetic identities, particularly for roles that provide access to company systems. -
Customer service and call centre staff,
who may be targeted by criminals impersonating customers using stolen personal information or other convincing details. -
Legal and compliance teams, which
need to understand their responsibilities when a breach occurs, including whether it needs to be reported under POPIA.
“Many of these attacks depend on someone being persuaded to act,” says
Moola. “A once-a-year awareness session doesn’t prepare people for increasingly convincing, role-specific attacks. Finance, HR and customer service teams need to understand what an AI-enabled attack looks like in the context of their own work.”
That could mean training finance employees to independently verify changes
Moola also believes businesses can look internally when addressing the
cybersecurity skills gap.
“The people who understand your payment processes, your customers and
your systems already work for you,” he says. “Training a finance clerk to identify a fraudulent supplier request, or giving a customer service agent a pathway into a cybersecurity role, can help businesses build capability while retaining valuable organisational
knowledge.”
Security teams still carry the technical defence, and their work is changing
as attackers adopt AI.
“Every AI tool that helps defenders is also available to attackers,” concludes
Moola. “Start with the teams that handle money, people and customer data. That’s where attackers are starting too.