Skip to content
News

Kenyans lost KES 491.6 million to SIM swap fraud in 2025, INTERPOL report says

INTERPOL's African Cyberthreat Assessment 2026 counts 123,000 fraudulent SIM cards in Kenya and a 327% jump in cases. Here is what the report actually says, and where its Kenya numbers come from.

Fraudsters drained an estimated USD 3.8 million, about KES 491.6 million at current exchange rates, from Kenyan mobile wallets in 2025 through SIM swap fraud, according to INTERPOL’s African Cyberthreat Assessment Report 2026. The report says SIM swap fraud in Kenya surged by 327% during the year, with more than 123,000 fraudulent SIM cards issued.

A SIM swap moves your phone number onto a new SIM card. The feature exists for a good reason: lose your phone and you need your number back. The problem is that whoever holds your number also receives every one-time password and transaction alert sent to it, and SMS codes are what most Kenyan banks and mobile money services use to confirm you are you. A fraudster who takes over your number can reset your accounts and move your money without ever touching your handset.

INTERPOL says the attacks rarely involve any actual hacking. Fraudsters gather personal details about a victim, often through phishing or from leaked data, then impersonate the victim to telecom customer service staff and request a SIM replacement. The report points at weak and inconsistent Know Your Customer procedures, and at telecom providers that cannot verify identity in real time. Tanzania and Rwanda reported similar patterns, with providers in both countries struggling to roll out real-time biometric verification.

Where the numbers come from

The report draws on survey responses from 36 of INTERPOL’s 49 African member countries, plus telemetry from Fortinet, Mastercard, the Shadowserver Foundation, S2W and TrendAI.

One detail worth knowing: INTERPOL’s footnote for the Kenya figures cites an October 2025 Capital FM story about Safaricom’s own disclosure that its SIM swap fraud investigations rose 327%. The 123,000 SIMs and the 327% jump are Kenyan-origin data, first reported here, now repeated back to us by a global policing body. Safaricom made that disclosure in the same 2024 sustainability report in which it revealed it had fired 113 employees over fraud, a story we covered at the time, with SIM swap collusion among the offences.

Kenya’s other appearances in the report

The SIM swap figures are not Kenya’s only mention. The Shadowserver Foundation ranked Kenya second in Africa for detected exploitable vulnerabilities in 2025, at 11.9% of all continental detections. South Africa led with 43.6% and Nigeria was third at 9.1%. The most targeted systems were unpatched routers, vulnerable VPNs and misconfigured document management platforms, weaknesses the report describes as well documented and easily fixed.

Cybersecurity firm NETSCOUT recorded more than 46,786 DDoS attacks on Kenyan telecoms infrastructure in the first half of 2025, and SOCRadar placed Kenya among its top phishing detections in September 2025. TrendAI data puts 13% of Africa’s 600,000 sextortion detections as originating from Kenya, second only to South Africa.

Across the continent, the picture is worse. Reported cybercrime losses more than doubled between 2024 and 2025, from USD 192 million to USD 484 million, with identified victims rising from 35,000 to 87,000. Mobile money fraud was the most prevalent scam of all, reported by 97% of the countries surveyed. INTERPOL’s member survey found AI involved in 55% of cybercrime cases in 2025.

What is being done, and what you can do

The report credits Kenya on two fronts: the Computer Misuse and Cybercrimes (Amendment) Bill 2024, which specifically targets SIM swaps and scam calls, and the “Kaa Chonjo!” awareness campaign, which tells Kenyans never to share one-time passwords or PINs over a call or text.

The courts have moved too. In June 2026, the High Court upheld a ruling that Safaricom and Diamond Trust Bank must jointly pay a customer KES 4.4 million stolen after her line was fraudulently swapped, with Safaricom carrying 60% of the loss. The judgement makes permitting the swap itself a direct cause of the theft, which raises the cost of weak verification for both telcos and banks.

On your end, the single highest-value protection takes one dial. Enter *100*100# on your Safaricom line and confirm the prompt. After that, your SIM can only be replaced at a Safaricom Shop or Care Desk with your ID, or by calling Safaricom yourself, which closes the remote route SIM swappers depend on. We covered this and the other tricks fraudsters currently use earlier this month.

The report’s Kenya numbers describe 2025. The Amendment Bill, biometric SIM verification at the telcos, and how courts apply the Safaricom-DTB precedent will determine whether the 2027 edition reads any better. The full report is on INTERPOL’s website.

Dickson Otieno

I love reading emails when bored. I am joking. But do send them to editor@tech-ish.com.

Join the discussion

0 comments
posting as Pofu Hodari

Anonymous by default — no sign-up or email needed. Prefer to be recognised? Add a name or email above, your call. We don't email you about replies, so do check back.

protected, no CAPTCHAs
Back to top button