VUNVAULT
KENYA CYBER WATCH · East Africa · August 11, 2026
VUNVAULT  /  Africa Cyber Watch  /  Kenya
Country Deep Dive · ~5 min read

Kenya's Cybersecurity Crisis: SIM Swap Fraud, a 67% Attack Surge, and a Ransomware Hit on the Presidency

East Africa's most digitalized economy is under siege. From Ksh 500 million lost to SIM swap fraud to a ransomware defacement of the presidential website, here is the full picture and what you can do to protect yourself.
By VUNVAULT News Desk  |  August 11, 2026
A person using a smartphone for mobile money in Kenya
Image via People Daily

Kenya has long been celebrated as Africa's mobile money pioneer. But that digital leadership now carries a heavy cost. New reporting from INTERPOL, Kenya's Communications Authority, and regional outlets paints a sobering picture: cybercrime against Kenyans is surging, the methods are getting more sophisticated and even the presidency has not been spared.

The Headline Numbers

Three statistics capture the scale of the problem:

The SIM Swap Explosion

Using a smartphone as part of SIM swap fraud awareness
Cybersecurity concept image (illustrative)

INTERPOL's 2026 report identifies SIM swap fraud as one of the leading methods targeting Kenyan mobile money users. The crime recorded a staggering 327% increase in 2025, resulting in the issuance of more than 123,000 fraudulent SIM cards used to gain unauthorized access to victims' accounts.

The attackers rarely hack banks directly. Instead, they exploit human processes. Criminals gather personal details about a victim, then use social engineering to convince telecom customer service representatives that they are the legitimate account holder requesting a SIM replacement. Once the swap succeeds, the fraudster intercepts one time passwords, transaction alerts, and verification messages.

This approach exposes a critical weakness in telecom based authentication the very SMS based one time codes that secure millions of mobile wallets and bank accounts across the country. The 327% surge reflects not just more criminals, but weak and inconsistently implemented customer identification procedures.

Beyond Mobile Money: The Presidential Website Attack

On the morning of Saturday, 18 July 2026, visitors to president.go.ke found the official portal of Kenya's head of state replaced with insulting messages, a cryptocurrency wallet address, and a countdown timer. The attackers described President Ruto as "head of scandal and corrupt" and warned "this is the third time for you before we leak everything about you."

The ransom demand was set at 5 Bitcoin approximately Ksh 41.3 million, or about US$320,000 with a 6:00 p.m. deadline on the day of the breach. Within hours, the government restricted access to the site entirely while forensic teams began work.

ICT Cabinet Secretary William Kabogo Gitau confirmed the cyberattack and temporary shutdown. He stated that there was no evidence of unauthorized access to sensitive government data, exfiltration, or information loss, adding that core government systems and digital services remained operational. As of publication, no group had claimed responsibility, and the government had not attributed the attack to any specific organization or country leaving open whether it was purely financial extortion or politically motivated.

Why SIM Swap Fraud Is So Hard to Stop

SIM swap fraud is difficult to defeat because it does not exploit a technical flaw in the payment system itself it exploits a trust gap in the human process of identity verification. Telecom agents are trained to help legitimate customers who have lost their phones, and criminals simply learn to convincingly impersonate those customers. Every safeguard that adds friction for fraudsters also adds friction for genuine users, creating a delicate balancing act for service providers.

The result is a race between verification and social engineering. As banks and telcos strengthen their identification procedures, fraudsters adapt with more elaborate scripts, better research on victims, and increasingly AI tools that can clone a voice or generate convincing documentation. Kenya's experience shows that technological fixes alone are insufficient; the human element of identity verification must be hardened at the same time.

The Broader Cyberattack on National Services

July's outages were not limited to the presidency. A separate cyberattack disrupted access to Kenya's e Citizen platform, M Pesa, digital banking, Kenya Power token purchases, and railway ticketing. Kenya Power reported a system failure at its payment service provider, leaving thousands of prepaid customers unable to buy tokens. Standard Chartered Kenya confirmed its online and mobile banking were affected. Kenya Railways and the NTSA also reported interruptions.

Officials described the attack on e Citizen as an attempt to overload the system with extraordinary requests a distributed denial of service (DDoS) style attack. A group calling itself "Anonymous Sudan" claimed responsibility on Telegram, though the claim could not be independently confirmed. The National Computer and Cybercrimes Coordination Committee (NC4) warned of a rise in global traffic targeting Kenya's critical information infrastructure, particularly in telecommunications, banking, and education.

"SIM swap fraud exposes a fundamental flaw: our most important financial services still rely on authentication methods that criminals can social engineer." VUNVAULT analysis

The Human and Financial Toll

The losses extend beyond traditional mobile money. Kenyan crypto investors lost an estimated Ksh 491 million (~$3.8 million) to SIM hijack scams in the past year. Because attackers can intercept OTPs after a SIM swap, they can reset passwords and drain crypto exchange accounts within minutes without ever breaking into the blockchain.

Kenyan courts are beginning to hold institutions accountable. In June 2026, the High Court ruled that Safaricom and Diamond Trust Bank (DTB) were jointly responsible for a customer's Ksh 4.4 million loss after fraudsters hijacked her phone number. Law enforcement has also responded with arrests throughout 2026, including an operation that netted eight suspects over an alleged Ksh 1.2 million M Pesa SIM swap fraud.

Key Facts at a Glance

How Kenyans Can Protect Themselves

For individuals

For organizations

Editor's note: Compiled from publicly reported news. The "Anonymous Sudan" claim and the exact extent of several incidents remain subject to official confirmation. Figures are as reported by the cited outlets.
← Back to Africa Cyber Watch

Sources & Further Reading