The Number Behind the Number

When we profiled Kenya in the 2025 series, the theme was mobile money’s dark shadow — the fraud economy that grew alongside one of the world’s most successful digital payment systems. The 2026 data does not soften that picture. It sharpens it into a single attack type.

INTERPOL’s 2026 assessment reports that Kenyans lost approximately KES 491.6 million — around $3.8 million — to SIM swap fraud in 2025. The loss figure is not the alarming part. The trajectory is: SIM swap fraud surged 327% year on year, with more than 123,000 fraudulently issued SIM cards in circulation.

The first half of 2026 shows no reversal. Authorities recorded 1,240 SIM swap cases, and cybercrime incidents overall rose 67% against the same period in 2025. Mobile money fraud accounted for 58% of those cases, concentrated on M-Pesa and mobile banking applications.

Why the Phone Number Is the Whole Bank

To understand why Kenya is disproportionately exposed to this specific attack, you have to understand what a Kenyan mobile number represents.

In most of the world a phone number is a contact detail and, at worst, a second authentication factor. In Kenya it is closer to a bank account number, an identity document and a password reset mechanism at the same time. M-Pesa balances, till payments, savings and loan products such as Fuliza and M-Shwari, bank app enrolment, and SMS one-time passcodes for card transactions all resolve to that one number.

That produces an unusual property: the attacker does not need your PIN, your card, or your device. They need the network to agree that your number now belongs to their SIM. Everything downstream follows automatically, because every downstream system was designed to trust the line.

How a Kenyan SIM Swap Actually Runs

The technical step is trivial. The work is social and, frequently, internal.

Reconnaissance comes first. The attacker assembles the identifiers a replacement-SIM request requires — full name, national ID number, date of birth, recent transaction details. These come from leaked databases, from loan-app data sharing, from social engineering calls posing as customer care, and from the enormous secondary market in registration data.

The request is the pivot. Either the fraudster impersonates the customer to a legitimate agent using that data, or — the pattern behind the 123,000 figure — a corrupt or careless registration agent issues the replacement directly. Agent-level compromise is the structural weakness across East African mobile money, and it is why the same story recurs in Tanzania’s Halohalo networks.

The window is short and brutal. Once the number ports, the victim’s handset loses service — which most people read as a network outage, not an attack. Inside that window the attacker resets M-Pesa access, drains the wallet, takes out instant digital loans in the victim’s name, and moves the funds through agent cash-outs and betting accounts, which settle fast and are difficult to reverse.

The clean-up follows: proceeds are layered through multiple wallets before withdrawal, so tracing dies at the third or fourth hop.

Recent enforcement shows the scale of individual cases. In June 2026 detectives arrested a suspect tied to a scheme that siphoned more than KES 450,000 from one victim; a July operation produced eight arrests over an alleged KES 1.2 million M-Pesa SIM swap fraud.

The Ruling That Changed the Argument

For years the standard institutional response to SIM swap losses was that the customer must have shared their PIN. That defence has now taken a serious blow.

In June 2026, the High Court ruled that Safaricom and Diamond Trust Bank were jointly responsible for a customer’s KES 4.4 million loss after fraudsters hijacked her phone number.

The reasoning is what matters. Joint liability says the failure was not a customer’s carelessness but a chain in which two regulated institutions each had an opportunity to stop the fraud and each failed — the telco by issuing a replacement SIM on inadequate verification, the bank by treating the resulting SMS as sufficient proof of identity for large transfers.

This is the single most consequential development in Kenyan fraud this year, and its effects will be felt well beyond one judgment. Liability is what forces investment. Institutions that bear the cost of a control failure build better controls; institutions that push the cost onto customers do not.

Kenya in the Regional Picture

Kenya’s numbers sit inside a continental trend. Africa’s cybercrime losses have been estimated at around $484 million, driven by AI-assisted social engineering and mobile fraud, and INTERPOL’s Africa-wide operation this year produced 651 arrests and recovered $4.3 million, including 27 arrests in Kenya.

Kenya is also flagged alongside its East African neighbours in regional mobile-money fraud assessments. The common factor is not weak technology — M-Pesa’s core is robust — but a registration and agent layer that sits outside the security perimeter everyone assumes exists.

Protecting Yourself

Set up a SIM PIN and a network-level port lock. Contact Safaricom, Airtel or Telkom and ask what additional verification they can attach to your line before a replacement SIM is issued. Ask specifically whether in-person ID verification can be required.

Treat sudden loss of network as an emergency, not an inconvenience. If your phone shows no service while others around you have signal, assume a swap. Call your provider from another phone immediately and ask them to suspend the line.

Never share your national ID number, date of birth and full name together with an unverified caller. That combination is the entire input to a fraudulent replacement request. Customer care will never call you and ask for it.

Move authentication off SMS wherever the option exists. Use an authenticator app for banking and email. SMS one-time passcodes are the specific mechanism this attack defeats.

Check your digital loan exposure regularly. Instant-credit products are drained in these attacks precisely because they disburse without human review. Reviewing your borrowing record monthly is how you find a fraudulent loan before the collections calls start.

Report to the DCI and your provider the same day, in writing. Speed determines whether funds are still recoverable at the agent cash-out stage, and a written record matters enormously given the liability picture the High Court has now established.

Push the liability question. The June ruling means “you must have shared your PIN” is no longer the end of the conversation. Victims who were told their loss was their own fault have grounds to ask again.

Kenya built the system the rest of the world studied. The 2026 lesson is that a payments network is only as strong as the counter clerk who can reassign your number — and until that layer is secured, the surge continues.