By The Weekly Vision Reporter
Kenya built its reputation as a pioneer of digital payments. New data from the National Computer and Cybercrimes Coordination Committee (NC4) suggest that the same infrastructure has become the preferred cash-out route for fraudsters.
An analysis presented on 24th August 2026 at the 36th meeting of the NC4, chaired by Dr Raymond Omollo, Principal Secretary for Internal Security and National Administration, reviewed 102 reported computer-fraud cases logged between February and July 2026. Mobile money featured in 51 of those cases, exactly half, either as the method of payment or as the destination for stolen funds.
The finding points to a pattern in street-level cybercrime rather than evidence of a systemic collapse or an insider heist at a licensed bank. The cases sit at the intersection of phones, SIM cards, investment pitches and cash-out schemes, not in corporate boardrooms. The NC4 data separate the problem into a scheme and a channel, and the distinction matters.
As a scheme in its own right, mobile-money fraud was the single largest category, accounting for 19 of the 102 cases, or 18.6 per cent. The Ministry of Interior stated plainly that mobile money fraud was the largest single fraud scheme recorded.

As a channel for moving stolen funds, however, mobile money’s role was far larger. Criminals used it to collect or hold proceeds in 51 cases. Bank transfers followed, linked to 22 cases (21.6 per cent), while cryptocurrency featured in 12 cases (11.8 per cent). A further 23 cases 22.5 per cent) carried explicit telecommunications or SIM-related indicators, including SIM-swap tactics.
In short: even when the initial bait was a fake forex desk, a cloned online shop or a bogus job offer, the stolen money most often left through M-Pesa or a similar mobile wallet.
The remainder of the 102 reviewed cases, as compiled from the NC4 briefing, reflects familiar digital fraud patterns. Investment and forex pitches formed the second-largest scheme category. Cryptocurrency appeared both as a scam type in its own right and as a cash-out route once funds had been stolen. Impersonation of brands and government offices, cloned websites and advance-fee tricks continue to draw in victims. SIM-swap fraud accounted for only three standalone cases in this sample, but sits behind a considerably larger share of cases carrying a telecommunications fingerprint.
Reporting was not evenly distributed across the period. Of the 102 cases, 70, or 68.6 per cent, were recorded between May and July 2026, with July alone producing 27 reports, the highest of any month reviewed. That spike may reflect a genuine rise in fraud, improved reporting, better case classification, or some combination of the three. Notably, NC4 itself listed “consistent classification of fraud data” among the reforms it now wants to pursue, an implicit acknowledgement that earlier data was inconsistently recorded.
NC4’s stated priorities are operational rather than symbolic. They include closer monitoring of high-risk mobile-money transactions, faster preservation of digital evidence, stronger escalation channels with telecommunications providers, better intelligence on investment, forex and crypto-related schemes, quicker action against fake websites and impersonation accounts, and a standardised approach to classifying fraud cases.
The Ministry of Interior reiterated that fraud complaints would be investigated in accordance with the law, while public guidance remained straightforward: do not share PINs, passwords or one-time codes; enable multi-factor authentication where available; treat unsolicited investment, cryptocurrency, shopping and job offers with suspicion; and report suspicious numbers, accounts, websites and transfers to the relevant provider, regulator or police.
Dr Omollo, chairing a meeting that included Inspector-General Douglas Kanja, ICT Authority chief executive Jessy Kiveu Maruti and NCIC chief executive Dr Daniel Muteugi Giti, restated the Government’s broader position: stronger coordination on incident response, investigation and prosecution; legal reform; protection of critical systems; public awareness; and training for law enforcement officers. Those efforts, the ministry said, should be read alongside the Kenya AI Strategy 2025 and the Bottom-Up Economic Transformation Agenda.
The same meeting heard that the National KE-CIRT/CC logged 2.3 billion “cyber events” during the period, a 30 per cent fall on the previous quarter, which officials attributed to better follow-through on security advisories. Ransomware, social engineering, malware, denial-of-service attacks and AI-assisted attacks remain the principal technical threats.
The ICT Authority separately reported the defacement of a government website after attackers exploited a zero-day vulnerability in its content-management system. The NCIC warned that ethnically charged narratives, amplified by synthetic media, fake accounts and bots, risk widening social divisions, though the committee said it aims to address this “without restricting legitimate political discourse.”
Two caveats are worth carrying alongside the headline figures. First, the 102 cases represent a reviewed set of reported computer-fraud cases, not a comprehensive census of all fraud in Kenya; most small-value M-Pesa losses are never formally reported to NC4. Second, the “cyber events” logged by KE-CIRT are network probes and incidents rather than proven crimes, and are not directly comparable to the 102-case fraud file.
Separately, the same NC4 figures have been read against Kenya’s efforts to exit the Financial Action Task Force (FATF) grey list, and are said to align with an Interpol assessment of the country’s exposure to cyber-enabled financial crime, including SIM-swap fraud. Interpol’s 2025 reporting had already ranked Kenya first in East Africa for cybercrime cases.
Kenya’s licensed banks are not the subject of this briefing. No board has been charged, no deposit book has been looted, and no institution has been placed into receivership on the strength of these 102 cases. What NC4 has documented is the exploitation of the country’s most trusted consumer payment rails, mobile wallets, SIM-based identity, and the speed of a send-money prompt, by individual fraudsters and organised criminal networks.
In many respects, this is the cost of success. The same convenience that placed a payment account in almost every Kenyan’s pocket has also given fraudsters a till that never closes. The state’s response, as set out on 24th August, rests on monitoring, evidence preservation, telecommunications cooperation and public vigilance. Whether that proves sufficient will be measured in the next six-month data set, not in any single intervention.

