Rwanda's rapid digitalisation is widening its exposure to cyber threats as more money, personal information and essential services move online. Cybersecurity officials warned that human behaviour, interconnected systems and false confidence in security are creating new vulnerabilities. This was highlighted on Thursday at the launch of the 2026 National Cyber Security and Data Protection Awareness Campaign in Kigali, held under the theme Tekana Online: Be Cyber Smart. Minister of ICT and Innovation Paula Ingabire said the expanding digital economy was increasing exposure to online fraud, phishing, identity theft and increasingly sophisticated scams. As our digital economy grows, so does our exposure to cyber threats, she said. ALSO READ: Rwanda takes cybersecurity to TVET schools as first 24 teachers complete training Ingabire urged Rwandans to make cybersecurity an ongoing practice. Let's make cybersecurity awareness a habit, not an annual event or a monthly activity that we are launching today, she said. Ghislaine Kayigi, chief cybersecurity standards officer at the National Cyber Security Authority (NCSA), said even strong defences can be undone if users are not cautious. You can put up the strongest security measures, but if the citizen can give away their PINs or passwords, the technical measures will no longer be of use, Kayigi said. That is how phishing works: fraudsters pose as a trusted bank, mobile-money provider or official, usually through a message, call or fake link, to trick people into revealing PINs or passwords. Kayigi said attackers can target social media accounts and mobile wallets. ALSO READ: When the money crosses borders: Rwanda’s cybercrime challenge Patrick Ndjientcheu, chief product and technology officer at Irembo, noted that terms such as phishing and multi-factor authentication confirming identity in more than one step, such as a password plus a phone code, can mean little to ordinary users. Artificial intelligence (AI) adds another layer. Kayigi said it gives criminals new ways to manipulate people and systems. Innocent Mudenge, chief operations and strategy officer at the Rwanda Information Society Authority (RISA), said AI can learn and mimick people's behaviours and vulnerabilities. ALSO READ: AI linked to half of cybercrime in Africa – Interpol report The illusion of security David Kanamugire, the chief executive at the NCSA, warned organisations against assuming that keeping data or systems within Rwanda, automatically means stronger security. Organisations need to know where their services and assets are and who has access to them, he said. There is what we call the illusion of security. We prefer to be paranoid than to assume we are secure, Kanamugire said. Lionel Ngendakuriyo, chief technology and innovation officer at the Rwanda Social Security Board (RSSB), warned against buying security products mainly to feel protected. He said security needs multiple layers and preparation for failure, including backups kept online, offline and offsite, and tested to confirm they can be restored. Ngendakuriyo warned that organisations sharing systems and integrations effectively share security responsibilities. Discussing attackers' use of AI, he described an email purporting to come from a chief finance officer asking a chief executive to process a payment, a scam known as business email compromise. The scale of the shift The urgency of these warnings is underscored by the rapid growth of the country's financial technology ecosystem. The National Bank of Rwanda's 2024–2025 Annual Report shows about 7.46 million active mobile payment subscribers by June 2025. Mobile payments rose 40 per cent to 588 million transactions worth more than Rwf3 trillion at the end of June 2025. Internet banking subscriptions increased by approximately 78 per cent, during the same period. Current mitigation efforts Capacity building has to be done at all tiers, Mudenge said, calling for practical, hands-on skills rather than training that ends with certificates. He said Rwanda has about 2,000 digital ambassadors who can extend awareness to communities, and that older people may first need to learn to keep a four-digit mobile money PIN private. Data gaps remain NCSA did not provide figures on cyber incidents or financial losses, so the scale of the problem remains difficult to quantify locally. Rwanda Computer Security Incident Response Team (Rw-CSIRT) says incidents can be reported through its online form.