Alarm as more Kenyans fall victim to online scam, mobile money fraud
Financial Standard
By
Kamau Muthoni
| Aug 18, 2026
Sometime on August 19, 2023, Moi Teaching and Referral Hospital (MTRH) had on its website a communication that it had a vacancy for orthopaedics and trauma medicine.
Attracted by the opportunity, Joseph Kinyanjui Kuburi wired Sh5,600 in the hope that he would get a chance to pursue a diploma in the advertised opportunity.
Little did Kinyanjui know that he had fallen into a trap, as someone had managed to infiltrate the hospital’s website and was making a killing out of unsuspecting persons.
Meshack Kimtai, a Kabianga University student, was nabbed and charged with the crime of unauthorised access to a computer system. He was also charged with obtaining by false pretence and having government property, a digi-school laptop.
When he was presented before the court on September 19, 2023, he admitted to the charges and was slapped with Sh1.8 million for the cybercrime offence, and in default, two years behind bars; then Sh50,000 for the second count, with a rider that he serves six months if he fails to pay the fine and an equal amount of fine and jail term for the third count. Each of the sentences the court ordered ought to run consecutively, meaning he was to pay Sh1.9 million and, in default, serve three years.
READ MORE
How Kenya's election misinformation spreads faster than facts
IEBC proposes Bill to guide recall of MPs, remove need to livestream
Ruto to certify 40,000 skilled youth without formal qualifications
Kenya's new health policies are abandoning infertile Wanjiku
'Broad-based government' that chokes citizens' voice bad for democracy
Scrap metal dealers report sharp decline in vandalism cases
Kenya bets Sh152 billion on AI to become Africa's technology hub
Meru dairy farmers upbeat as processor gets ISO certification
Why court has blocked sole claim to Justice Majanja's Sh22M insurance funds
Aggrieved, Kimtai appealed before High Court Judge Robert Wananda. He claimed that he would lose his studies and sponsorship if the custodial sentence stayed. He also alleged that he is a God-fearing man and an orphan, having been raised by a single mother with seven other siblings.
The prosecution opposed his release. The Director of Public Prosecutions (DPP) argued that Kimtai had been punished out of his admission.
Justice Wananda agreed with the DPP. He ruled early last year that Kimtai was simply seeking sympathy without showing that the lower court was either incorrect or the punishment was marred by irregularities or illegalities.
He observed that the student had used his knowledge to spoof unsuspecting persons instead of schooling.
“This is a case of a brilliant, academically gifted young man who, instead of using his skills for the betterment of society and for his own education endeavours, chose to instead use them to rob innocent Kenyans of their hard-earned sweat. In my view, the sentences imposed were appropriate and proportionate to the offences committed,” said Justice Wananda.
Fast forward to July this year, Kamau Kimani intended to use the services of a courier to ferry his items to Nanyuki. The courier, which we have redacted since the issue is under investigation, had its website cloned. Kamau was directed to pay for the items, but the caller on the other end was interested in his M-Pesa message. After sensing that something was not right, he deleted the balance and sent the same, but the caller insisted that he must get the full text as it had allegedly not reflected on the other end. The caller then changed tune, this time directing Kamau to instead key in a certain number on his keypad, enter the same amount of money he had sent and then the password. This, Kamau explained, was trickery as the number he had been given was the last digits of the mobile number of the caller and had been listed as a till number. He was lucky that he verified before sending.
Kinyanjui and Kamau are poster boys of a growing trend of cyber-attacks in the country. An Interpol 2026 report indicated that Kenya is among the fastest cybercrime flashpoints in Africa, with the biggest threat being mobile money owing to increased access to cell phones and use of Artificial Intelligence by criminals.
According to the report, 46,786 distributed denial-of-service (DDoS) attacks while online scams contributed to 17 per cent of the reported cases.
Identity theft and financial fraud accounted for 14 per cent; ransomware and banking trojan stealers, seven per cent; crypto jacking, four per cent; and data breaches, 11 per cent.
It is only sextortion or revenge porn and cyberbullying online human trafficking which were not related to financial services. They contributed to 14 per cent and five per cent of the reported cases.
Interpol indicated that mobile connections in Africa had more than 1.1 billion subscriptions, while money wired through mobile phones was more than Sh129 trillion. Further, the report reads that there are more than 570 million internet users, with governments also shifting services online.
On the flip side, the number of losses related to cybercrime has shot from $192 million to $484 million in the last year, with the number of identified victims increasing from 35,000 to 87,000.
“While comprehensive national data on financial losses remain inconsistent due to underreporting and divergent reporting methodologies, aggregated estimates suggest that cybercrime inflicted at least $5 billion (Sh650 billion) in direct economic damage across Africa in 2025, as compared to the region’s total cybersecurity expenditure of $15.3 billion (Sh1.98 trillion),” the report reads in part.
Closer to home, the Communications Authority of Kenya (CA) said that it had detected a total of 3.4 billion cyber threats between January 1 and March 31 this year, although this was a decline of 26.1 per cent from 4.6 billion events recorded in the previous quarter.
From the report, Malware and brute force attacks contribute to the largest share of cyber threats in the country, with 68.7 million and 46.3 million reported cases, while web application attacks come in third with 12.1 million, while mobile application attacks were 219, 549 cases.
Interpol indicated that mobile money fraud is the most prevalent scam at 97 per cent. Kenya alone, according to the global policing agency, detected 123,000 fraudulent SIM cards in 2025, a 327 per cent increase, which enabled fraudsters to carry out SIM swap attacks and drain mobile wallets.
Central Bank of Kenya data estimated that more than Sh810.69 million was lost through mobile banking in 2024 alone, a sharp rise from 182.4 million.
The other threat identified was business email compromise, which indicated that 70 percent of BEC originated from South Africa.
What is call/SMS spoofing?
Call or SMS spoofing is a technique where a caller or sender falsifies the phone number or sender ID that appears on your phone. The goal is to make the communication appear to come from someone else, such as a bank, government agency, a company, or even someone you know.
Why criminals use spoofing:
Criminals use spoofing to steal banking credentials or OTPs, conduct phishing attacks, convincing victims to transfer money, collect personal information (identity theft) and bypass trust by impersonating legitimate organisations.
How criminals use spoofing
Several victims have reported receiving calls from “legitimate” numbers associated with banks, Safaricom and the Directorate of Criminal Investigations (DCI). They narrate that the calls inform them that there have been attempts to breach their accounts and that immediate action is needed to secure their accounts. They are then asked to give personal details and they later end up losing their savings.
How to protect yourself
Don't trust caller ID or SMS sender names alone, as they can be spoofed.
Never share OTPs, PINs, passwords, or card details over the phone or by text.
If someone claims to be from your bank or another organisation, hang up and call back using the official number from their website
Avoid clicking links in unexpected SMS messages.
Enable multi-factor authentication where possible.
Report suspicious calls or messages to your mobile operator and the organisation being impersonated.