Kenya's cybercrime bill is now a banking-sector problem
Central Bank of Kenya data shows mobile-banking fraud drove the sharpest year-on-year jump in cybercrime losses in 2024, and the country's regulator is now extending banking-style supervision to a sector that did not exist as a category a decade ago.

On 13 July 2026, the Kenyan daily The Star reported figures the country's banking supervisors have been quietly preparing for two years: Kenyans lost significantly more money to cybercrime in 2024 than in the year before, and mobile banking fraud recorded the sharpest increase of any category the central bank tracks.
That single sentence is the most consequential data point in East African retail finance this year. It moves the conversation about Kenyan digital crime out of the cybersecurity trade press and into the meeting rooms of the Central Bank of Kenya, the four largest commercial banks, and the mobile-network operators whose SIM cards sit at the front of every transaction.
What the regulator actually said
The data comes from the Central Bank of Kenya's annual cybersecurity returns, which commercial banks, microfinance institutions, and a small group of payment-service providers are required to file. The bank does not publish a headline loss figure; the press release that triggered the Star's write-up is a one-paragraph item summarising the year-on-year direction of fraud by channel. Mobile banking, defined by the regulator to include USSD, app-based, and SIM-toolkit transactions that move money directly from a customer's bank or saccos account, was the line that moved fastest upward. Card-not-present and ATM skimming categories also grew, but at a slower rate.
That detail matters because Kenya's financial system is unusually concentrated at the consumer edge. More than two-thirds of all retail transactions in the country now pass through a mobile-money or mobile-banking rail, and a single platform, M-Pesa, handles the bulk of person-to-person transfers. When fraud migrates onto the mobile rail, it does not arrive as a marginal uptick. It arrives at the scale of the rail itself.
A category that did not exist a decade ago
Kenya did not have a "mobile banking fraud" line in its supervisory returns in any meaningful sense until 2018. The relevant rulebook at the time, the CBK's Risk Management Guidelines, was written for branch-based retail banking with a thin online-banking appendix. The category expanded as banks began to push customers toward apps and as the country's saccos, the cooperative savings societies that dominate rural Kenya, contracted with mobile-platform vendors to offer deposits and withdrawals through USSD codes.
The supervisory response has been incremental rather than disruptive. The CBK has issued a series of circulars tightening customer-authentication requirements, requiring second-factor confirmation for transactions above a threshold, and forcing banks to refund customers who lose money to demonstrably unauthorised transactions within defined windows. The 2024 figures will be read, in Nairobi's banking circles, as a verdict on whether those measures have arrived fast enough to keep up with the fraudsters. By the directional read in the Star report, they have not.
The structural read
Kenya is the most-cited case study in the world for mobile-money-led financial inclusion, and rightly so. The same architectural choice that pulled tens of millions of first-time account holders into the formal financial system, light onboarding, a SIM as identity, a phone number as an address, also widened the surface area for theft. Fraud follows the path of least friction. In Kenya that path now runs through a SIM.
That is not a uniquely Kenyan problem. Ghana, Tanzania, Uganda, Nigeria, and Côte d'Ivoire all run similar mobile-money rails at scale, and their central banks are publishing similar directional data, though with less public granularity. What is distinctive about Kenya is the depth of integration: a Kenyan smallholder farmer is more likely to receive payment for a coffee harvest through M-Pesa than through a bank account, and a Nairobi matatu conductor is more likely to settle the day's takings through an app than through a till. When fraud scales on the rail, it scales against the productive economy.
A second structural point sits underneath the first. The CBK supervises banks; the Communications Authority of Kenya supervises telcos. Mobile banking lives in the gap, regulated at the application layer by the bank that holds the deposit and at the transport layer by a telco that may not have a banking licence. The supervisory boundary is drawn around the institution, not the transaction, and the transaction is where the crime happens. The 2024 numbers will accelerate a long-running discussion about whether the CBK needs a dedicated digital-retail-supervision unit with authority that crosses the bank-telco seam.
What to watch next
Three concrete dates will frame the rest of the year. First, the CBK's next annual cybersecurity report is expected to be released later in 2026 and will, for the first time, sit alongside the data already disclosed in the press summary, giving analysts a single document to read. Second, the bank's draft Risk Management Guidelines revision, which has been in consultation since late 2025, is expected to land in the second half of the year; it is widely expected to harden the authentication rules that currently apply only above a transaction threshold. Third, the Office of the Data Protection Commissioner has indicated that guidance on consent for SIM-swap verification will follow in the same window, which will affect the fraud vector that is most often upstream of a mobile-banking loss.
There is also a counter-narrative worth naming plainly. Some Kenyan fintech executives argue in private that the headline loss figures overstate the problem, because banks have grown more aggressive about writing off small consumer losses as fraud in order to comply with the CBK's refund rules, even where the customer may have authorised the transaction. If that read is even partly correct, the 2024 jump reflects a reclassification as much as a crime wave. The direction of travel, however, is the same in either telling: more reported fraud, more supervisory pressure, more demand on banks and telcos to spend on controls they did not have to build five years ago.
The structural bet Kenya made in the late 2000s was that financial inclusion and consumer protection could be sequenced, with inclusion first and protection layered on as the rail matured. The 2024 numbers are the first hard evidence that the protection layer has not kept up. Whether the next supervisory cycle closes the gap, or whether the rail keeps outrunning the regulator, will be the most important question in East African finance for the rest of 2026.
Desk note: This piece follows the central-bank disclosure rather than the wire cycle, because no major wire has yet filed on the 2024 figures; The Star's 13 July summary is the originating public reference, and the regulatory documents it cites will become the primary sources once published in full.
Wire provenance
This editorial synthesis draws on the following public wire/social posts:
- https://t.me/TheStarKenya