60 بالعربي

What if Lies Became Provable and the Truth Became Deniable?

Dr. Khalid Saqr
September 20, 2026
8 min
What if Lies Became Provable and the Truth Became Deniable?

Summary

When a fake crisis can be fabricated, a government statement forged, or public panic ignited in just a few hours, how do you know if what angered you is real? And what if your fear was the goal all along?

In August 2026, Interpol presented a figure that succinctly summarizes much of what awaits digital security in the coming year. Artificial intelligence is now present in 55% of reported cybercrimes in Africa, while cybercrime-related losses rose from $192 million to $484 million since 2024. Most importantly, 72% of the 36 African countries surveyed by the organization reported the presence of scam centers within their territories.

Digital crime has thus entered the phase of large-scale practice, where the cost of an attack drops while its speed and reach to a vast number of victims increase.

The attack surface that an attacker can rapidly reach is also expanding. The number of mobile phone subscribers on the dark continent surpassed 1.1 billion in 2025. Interpol recorded nearly 600,000 cases of digital Sextortion, while four international operations coordinated by Interpol led to more than 1,500 arrests and the recovery of over $100 million. These numbers mean that the problem is no longer a group of scattered hackers, but rather a criminal economy possessing the labor force, financial infrastructure, and tools needed for expansion.

Fraud campaigns previously required translators, designers, operators, and dozens of electronic accounts on social media networks. Today, Generative AI tools can write misleading content, tailor it according to the victim's age, job, and language, emulate voices, generate images and videos, and assist criminals in gathering pre-intrusion intelligence. Interpol tracks automation across stages starting from Reconnaissance and Phishing, reaching extortion and attempts to evade detection systems.

Because of this, boundaries are now blurring between a Cyberattack, Information Warfare, and Psychological Operations – PSYOPS. An attack might begin with a Deepfake clip, amplified by fake accounts, and within hours, victims reach a page designed to steal passwords or money. Conversely, an attacker might take the opposite route, first hacking a legitimate email and then mixing stolen files with artificially generated content. It then becomes difficult to refute the story because some of its elements are indeed true.

Here emerges a shift far more dangerous than the crime of fabrication itself: a criminal can succeed without persuading victims to believe their narrative. Sometimes, it is enough to render people incapable of knowing which narrative to believe. When deepfake technology spreads widely, the owner of a fake recording can promote it, and the owner of a real recording can claim it is fake. Researchers call this phenomenon the Liar’s Dividend—that is, the gain achieved by a liar when evidence itself becomes subject to doubt.

Africa enters this phase with an existing information infrastructure capable of being exploited. The Africa Center for Strategic Studies documented 189 disinformation campaigns in 2024—nearly four times the number recorded in 2022—targeting at least 39 countries, with nearly half of these nations targeted by three or more campaigns. The average number of campaigns in conflict-affected countries reached five, serving as an important indicator of the relationship between political and security instability and the ease of penetrating the information sphere. The center also estimated the number of internet users on the continent at around 600 million, with active social media users exceeding 400 million.

The problem has thus become a matter of speed as well, because an operator of disinformation campaigns can produce dozens of iterations of the same message and test them—just as e-commerce companies run A/B Testing on two different ads—and then double down on broadcasting the version that triggers greater anger, fear, or engagement among victims. A rumor about a bank, a government official, or a security incident can turn into a live experiment where the system learns from society's reaction and adapts its messaging by the hour.

Kenya already reveals the scale of pressure a digital nation can face even before adding this type of automation. The Kenyan National Computer Incident Response Team registered over 842 million cyber threat events between July and September 2025, which then spiked to nearly 4.56 billion events over the following three months—a 441% increase. The recent period alone included more than 4.37 billion attempts linked to system attacks, around 71 million malware events, and over 58 million Distributed Denial of Service (DDoS) events. While these numbers do not mean billions of successful breaches occurred, they represent events and attempts detected by monitoring systems, illustrating the immense automated pressure networks deal with.

These figures take on even greater significance as the Kenyan general elections are scheduled for August 10, 2027. The Africa Center for Strategic Studies had documented nine disinformation campaigns targeting Kenya in its 2024 map, five of which originated domestically. The convergence of the election date with the scale of digital usage and automated threats provides sufficient reason to expect increased spending on cyber surveillance, content verification, electoral system protection, and rumor response before and during voting.

Nigeria presents an even larger test in terms of scale, with the Communications Commission recording 124.4 million broadband subscriptions in July 2026, compared to around 92.2 million in January 2024. Furthermore, the voter register published by the Electoral Commission contains over 93.4 million voters. The Nigerian information sphere was already subjected to coordinated campaigns during the 2023 elections, according to the Africa Center for Strategic Studies. The current timetable published on the Electoral Commission's website sets January 16, 2027, for presidential and legislative elections, and February 6 for state elections. Thus, a massive digital audience, widespread political competition, and huge mobile communications and financial markets will converge in a short period—an environment making spear phishing, impersonation operations, and synthetic content risks that can hardly be assumed absent.

However, exposure to risk does not equal helplessness in confronting it. The Global Cybersecurity Index 2024 issued by the International Telecommunication Union measures five pillars: legal, technical, organizational, capacity development, and international cooperation. Ghana achieved the highest ranking, Tier 1 – Role-modelling, scoring 20 out of 20 across four of the five pillars, along with 19.27 in capacity building. Morocco also landed in the first tier, with 20 in legal, organizational, and cooperation, and 19.38 in capacity building. Meanwhile, South Africa and Zambia were placed in Tier 2 – Advancing, while Nigeria was classified under Tier 3 – Establishing. These scores do not predict the number of attacks that will occur, but they measure something far more useful for comparing the capabilities of African nations: a state's institutional capacity to absorb and respond to shocks.

Undoubtedly, the year 2027 will push these capabilities toward regional cooperation. The Economic Community of West African States (ECOWAS) has begun preparing a cybersecurity and cybercrime strategy for the period 2027–2032, while already operating a regional platform for cooperation, information sharing, and coordinated response. Consequently, the exchange of Indicators of Compromise – IoCs—technical indicators revealing attacks—is likely to become faster among West African nations, along with an expansion in joint training and cross-border digital evidence mechanisms.

The African Union is moving along the same path. It adopted the Continental Strategy on Artificial Intelligence in 2024, and in 2025 urged member states to develop national strategies and laws, conduct periodic AI risk assessments, update regulatory frameworks, and establish a continental governance mechanism. Therefore, 2027 will see a higher probability of legislation linking cybersecurity directly to artificial intelligence, rather than addressing the two domains through separate laws.

Can we predict what will happen next year?

We can certainly build a more conservative model than traditional statistics-based forecasting. Such a model can account for four variables: the size of the digital audience, observed cyber pressure, prior exposure to disinformation, and institutional capacity according to the ITU index. It then adds a "temporal shock" when a major national event with a pre-announced date occurs.

This equation gives Nigeria and Kenya the most defensible scenario. The model demonstrates that risk in both countries will center around Hybrid Information-Cyber Operations—operations that blend synthetic content with account impersonation, phishing, and data breaches. It is highly probable that the run-up to and duration of elections will be accompanied by increased verification measures, protection of institutional and public figure accounts, monitoring of fake content, and coordination between electoral bodies, telecommunications companies, and platforms. This is a forecast of the risk and response environment, not a judgment on any political party or election outcome.

For Ghana and Morocco, readiness data points to a different scenario. The shift is likely to focus on proactive regulation, system testing, digital identity, and institutional training, as the legal, regulatory, and collaborative infrastructure is already stronger according to the ITU. In South Africa and Zambia, 2027 is likely to revolve around narrowing the gap between technical infrastructure and human capacity building; the index placed both countries in Tier 2, with capacity development remaining a clear area for improvement.

As for West Africa as a region, a specific institutional direction can be predicted with higher confidence: regional response will increase at the expense of isolated national efforts with the commencement of the 2027–2032 strategic cycle. The first proof of this transition's success will be evident in the speed of sharing attack data and evidence, rather than in the number of conferences held or agreements signed.

Here, the metric changes. It will no longer be enough to know how many attacks occurred or how many accounts were deleted. The Mean Time to Verify—the average time required to verify high-impact digital material—will become a security metric in its own right. A country that needs five hours to prove a recording is fake will enter the crisis after millions have already viewed it. A country that reduces this time to minutes changes the entire dynamic of the attack.

When the creation of audio, video, and fabricated narratives becomes near-instantaneous, truth alone is no longer enough. It must arrive in time.

Share Article
Keywords