Lead image for SIM Swap Fraud Cost Kenyans KSh491.6mn As Cyberthreats Soar - INTERPOL.
An estimated US$3.8 million (~ KSh491.6 million) was siphoned from Kenyan mobile wallets last year as SIM swap fraud surged 327%, with more than 123,000 fraudulent SIM cards issued, according to INTERPOL.
- The figures place Kenya at the sharp end of one of East Africa's fastest-growing cybercrime trends, where criminals increasingly target identities rather than computer systems.
- Instead of deploying sophisticated malware, attackers seek control of victims' phone numbers, allowing them to intercept one-time passwords and gain access to bank accounts, mobile wallets, and other digital services.
- In the ‘African Cyberthreat Assessment Report 2026’, the global policing body stated that such attacks typically rely on social engineering and weaknesses in customer verification processes at telecom providers.
“The region’s rapid digital adoption has outpaced its ability to secure it. The absence of a unified regional cybercrime response mechanism has allowed criminal networks to exploit jurisdictional boundaries between nations,” INTERPOL said in the report.
INTERPOL also noted that Tanzania and Rwanda have reported similar SIM swap activity, attributing part of the challenge to telecom operators struggling to implement real-time biometric identity verification. However, Tanzania recorded a 19% decline in mobile fraud attempts after tightening SIM registration enforcement, suggesting stricter identity controls can curb abuse.
The broader survey found mobile money fraud to be the most prevalent cyber-enabled scam across the continent, reported by 97% of responding countries. INTERPOL also points to inconsistent Know Your Customer (KYC) procedures and the absence of real-time identity verification in some markets as structural weaknesses that continue to leave telecom networks vulnerable to identity-based fraud.
The Cyber Threats
Kenya is also ranked second in Africa for detected cyber vulnerabilities, accounting for 11.9 per cent of all continental detections, behind South Africa's 43.6 per cent and ahead of Nigeria's 9.1 per cent, according to the Shadowserver Foundation.
Cybersecurity firm, NETSCOUT, recorded more than 46,786 distributed denial-of-service (DDoS) attacks targeting Kenyan telecommunications infrastructure during the first half of 2025. Separately, the Communications Authority (CA) reported hundreds of millions of intrusion attempts against government and ICT infrastructure between July and September 2025, largely through brute-force attacks and system exploitation.