Kenya in focus as East Africa flagged over mobile cash fraud

Kenya, Uganda, Tanzania, Ethiopia and Rwanda are among Africa’s fastest-growing cybercrime hotspots, driven by mobile money fraud and advances in artificial intelligence (AI).

A new report by Interpol notes incidents of scammers tricking mobile network providers into moving phone numbers to new SIM cards they control, technically called SIM swap fraud, rose by 327 percent in Kenya in 2025.

The international police agency says more than 123,000 fraudulent SIM cards were issued, enabling criminals to hijack victims’ phone numbers and steal cash from mobile money wallets.

The report says the region’s fast adoption of mobile money has made it a prime target for fraudsters, while AI is enabling criminals to launch faster and more complex attacks.

“The region’s rapid digital adoption has outpaced its ability to secure it,” the report says, noting that while Kenya and Tanzania have made progress in strengthening cybercrime laws, criminal networks continue to exploit weak regional coordination and jurisdictional boundaries.

Kenya recorded more than 46,786 distributed denial-of-service (DDoS) attacks targeting telecommunication operators in the first half of 2025.

DDoS attacks involve flooding websites, servers or networks with an overwhelming amount of internet traffic from multiple compromised devices to make the service slow or unavailable to real users.

Interpol also flags Kenya’s high cases of cybercriminals impersonating trusted organisations or individuals to trick people into revealing sensitive information like passwords, bank card numbers or login credentials, which is known as phishing.

“Kenya was included in SOCRadar’s top phishing detections in September 2025,” the report says, referencing the US-based cyber threat monitoring platform.

Advances in AI have allowed criminals to automate cyber-attacks. The technology has made it more difficult for victims to detect phishing campaigns, malicious requests for information or money and malware deployment.

In Africa alone, AI is enabling 55 percent of reported cybercrime.

At the same time, Kenya’s mobile money market is expanding rapidly, giving criminals a larger playing field. Data from the Communications Authority (CA) shows mobile money subscriptions reached 53.4 million by March this year, representing a penetration rate of 100.1 percent.

Safaricom’s M-Pesa, which controls 89.1 percent of the market, processed Sh41.68 trillion in transactions in the year ended March 2026, according to the telco’s financials. This is equivalent to about 2.4 times Kenya’s gross domestic product.

Interpol says 97 percent of African countries surveyed identified mobile money fraud as their most common cyber scam. The report attributes the trend to inconsistent know-your-customer (KYC) procedures, particularly where telecom operators lack the technical capacity to verify customer identities in real time.

The agency also warns that the rise of “money mulling” is making cybercrime harder to combat. Criminals recruit individuals through fake online job advertisements posing as opportunities for “financial agents” or “remote transaction officers” to receive and transfer illicit funds, often without understanding they are laundering proceeds from business email compromise, ransomware or cryptocurrency scams.

Interpol further said fragmented cooperation between banks, telecommunications companies and law enforcement agencies has created major blind spots.

“While financial institutions could detect suspicious transactions, they lacked the legal authority or technical channels to block SIM swaps or freeze accounts without court orders, a process that often took weeks to months,” the report says.

The police body also warns that Africa’s lack of an interoperable digital identity framework is allowing criminals to steal identities in one country, open financial accounts in another and move illicit funds through a third.

The assessment is based on a survey of 49 African member countries, drawing on information from law enforcement agencies, national cybersecurity units and judicial authorities, alongside cybersecurity telemetry from private-sector partners.

Leave a Reply

Your email address will not be published. Required fields are marked *