Kenya is facing cybercrime threats linked to SIM swaps that resulted in the loss of Ksh500 million from digital wallets.
According to the INTERPOL African Cyberthreat Assessment Report 2026, fraudsters in 2025 targeted digital financial platforms, using advanced techniques to bypass security systems.
“In 2025, SIM swap fraud surged by 327 per cent in Kenya, with more than 123,000 fraudulent SIMs issued and an estimated USD 3.8 million drained from mobile wallets,” read the report in part.
The report identifies mobile money fraud, online scams, digital extortion and identity-based attacks as some of the fastest-growing cyber threats affecting African countries.
SIM Swap Fraud Surge Drives Millions in Mobile Money Losses
SIM swap fraud became one of the leading methods used by cybercriminals to target Kenyan mobile money users in 2025.
The crime recorded a 327% increase, resulting in the issuance of more than 123,000 fraudulent SIM cards that were allegedly used to gain unauthorized access to victims’ accounts.
A SIM swap attack involves replacing a genuine customer’s SIM card with another SIM card controlled by a fraudster.
Once the swap is completed, the criminal’s device becomes linked to the victim’s phone number, giving them access to all services.
Since many digital financial platforms use mobile numbers for account verification, gaining control of a SIM card can provide criminals with access into a victim’s financial ecosystem.
This may include mobile money wallets, banking applications, and other online services connected to the phone number.
In many cases, victims become aware of the attack only after losing access to their mobile network services or noticing unexplained withdrawals and transactions from their accounts.
How Criminals Manipulated Telecom Customer Systems in Kenya
According to the report, the rise in SIM swap cases was driven by social engineering, where criminals manipulated telecommunications customer service processes to obtain control of targeted phone numbers.
Rather than attacking financial systems directly, fraudsters focused on exploiting human processes.
They gathered personal details about victims and used the information to convince customer care representatives that they were legitimate account holders requesting SIM replacements.
After successfully completing the fraudulent replacement, criminals could intercept one-time passwords, transaction alerts and verification messages sent to the victim’s phone.
The attacks exposed vulnerabilities in telecom-based authentication systems, especially where customer identification procedures are weak or inconsistently implemented.
In Kenya, millions of citizens rely on telco platforms such as M-Pesa and Airtel Money for daily transactions.
However, the same dependence on mobile connectivity has created new opportunities for cybercriminals.
Mobile Money Platforms Become Channels for Advanced Digital Scams
One emerging threat is digital sextortion, where criminals threaten victims with the release of private images, videos or artificially generated deepfake content unless payments are made.
Mobile wallets are often preferred by criminals because they allow quick transfers and can be accessed remotely.
The growing use of artificial intelligence has also made cyber scams more sophisticated, enabling criminals to create convincing fake identities, manipulated images and deceptive online investment platforms.
To curb the increase in digital crimes, including SIM swaps, Kenya has moved to strengthen its cybercrime laws, including measures under the Computer Misuse and Cybercrimes (Amendment) Bill, 2024.
Follow our and X Account for real-time news updates.







Comments
No comments yet. Be the first to share your thoughts.