Mobile-money fraud is reshaping Kenya's cybercrime ledger
Central Bank of Kenya data shows Kenyans lost significantly more to cybercrime in 2024, with mobile banking fraud recording the sharpest year-on-year jump. The shift reshapes who picks up the bill.

Kenyans lost significantly more money to cybercrime in 2024 than in the year before, and the fastest-growing slice of those losses came not from card skimming, business email compromise, or the WhatsApp inheritance scam, but from the rails that move wages and rent across the country every afternoon. Central Bank of Kenya data published on 13 July 2026 show that mobile banking fraud recorded the sharpest increase of any cybercrime category tracked by the regulator, a structural shift in a market where more than 80 per cent of the adult population transacts through a mobile wallet rather than a bank account.
What is changing is not the existence of fraud, which has shadowed Kenya's mobile-money revolution since the early days of M-Pesa, but its centre of gravity. Thefts are moving from the perimeter of the financial system into the everyday transactions of households and small traders. The implications extend well beyond Nairobi.
The numbers, and what the regulator will say
The headline figure, drawn from Central Bank of Kenya reporting and circulated by The Star Kenya on 13 July 2026, is that cybercrime losses climbed year-on-year in 2024, with the mobile banking sub-category outpacing every other segment of the regulator's taxonomy. The bank has not, in the public version of the release seen by Monexus, broken out a single shilling figure for total losses or for the mobile share. The framing is comparative: mobile fraud grew fastest, and it grew from a base that was already the largest in absolute terms.
That distinction matters. A small base can produce eye-catching percentage jumps without changing the practical exposure of households. A jump from the largest base implies that the dominant channel through which ordinary Kenyans store and move money is the one becoming less safe, in relative terms, every quarter. The regulator's choice to flag mobile banking rather than, say, card-not-present fraud signals where it believes the next round of enforcement and disclosure rules will land.
Counter-narrative: the platform story
The standard industry explanation is that fraud follows convenience, and that mobile money is convenient. Safaricom, which operates M-Pesa through its fintech subsidiary, has spent more than a decade layering SIM-swap protections, biometric onboarding, transaction limits and a 24-hour cooling-off window on SIM replacements onto the network. Similar controls exist at Airtel Money and Telkom's T-Kash. On paper, the platforms are the most heavily defended retail payments rails in East Africa.
The fraud data complicate that defence. Thefts that the regulator now classifies as mobile banking fraud often begin outside the platform: a phone call, a forged national ID, a corrupted agent. The wallet is where the loss is realised, not where the crime begins. That is the structural reason a control architecture built inside the platform does not, by itself, contain losses that originate in the social layer around it. The bank cannot SIM-swap-proof a grandmother in Kisumu; the operator cannot biometrically authenticate a nephew who has been coached by a stranger on Telegram.
The architecture of the loss
What is unfolding in Kenya is a small case study in a wider African pattern. Domestic payments have been digitised faster than the consumer-protection apparatus around them, and the slack has been filled by social engineering. The dominant fraud typologies are no longer technical exploits of the network; they are confidence tricks executed over voice calls and SMS, ending in a transfer instruction the victim authorises themselves. When the customer pushes the button, the platform has little room to refuse.
This is where the political economy begins to bite. Kenya's mobile-money stack is a private infrastructure that performs a public function. The central bank sets the rules, the Communications Authority of Kenya polices the airwaves, and Safaricom, Airtel and Telkom run the rails. When fraud volumes rise, the cost is split: the customer eats the loss in practice, the platform absorbs the chargeback and the reputational damage, and the regulator writes the next circular. Nobody has yet proposed that the platforms bear a defined statutory share of consumer losses in cases of platform-side control failure, the model that consumer-credit regulators in Europe and parts of Asia now apply. Kenya is not there yet.
What to watch next
Two deadlines will sharpen the picture. The central bank's annual cybercrime report is expected later in the year and may for the first time disaggregate mobile fraud between agent-assisted cash-out, SIM-swap-enabled account takeover, and social-engineering transfers originated by the customer. The Kenya Information and Communications (Amendment) regulations under discussion at the Ministry of ICT would, if enacted, impose new liability rules on telcos for SIM swaps performed without enhanced identity verification. Both moves would shift some of the cost of fraud back onto the operators and the agents, away from the customer.
The open question, and the one the available sources do not resolve, is whether the 2024 figures reflect a one-off year or the new baseline. The central bank's framing of mobile banking as the fastest-growing category suggests the latter. If so, the next phase of Kenya's celebrated mobile-money story will be written not in Nairobi's product launches but in a quieter argument about who pays when the button is pushed.
Desk note: where the international wire has tended to treat African mobile-money fraud as a feature of the technology, Monexus treats it as a feature of the regulatory perimeter around the technology, which is where the next round of policy will actually land.
Wire provenance
This editorial synthesis draws on the following public wire/social posts:
- https://t.me/TheStarKenya