Kenya is tightening its grip on cyber-enabled fraud after new government data revealed that mobile money was linked to exactly half of all computer fraud cases reported in the first six months of 2026.
An analysis by the National Computer and Cybercrimes Coordination Committee (NC4) found that mobile money was used either as a payment method or as the destination for stolen funds in 51 of 102 reported computer fraud cases reviewed between February and July. The findings were presented during the committee’s 36th meeting, chaired by Interior Principal Secretary Raymond Omollo.
On its own, mobile money fraud was the single largest fraud scheme recorded, accounting for 19 cases, or 18.6 per cent of the total. Investment and foreign exchange schemes followed with 16 cases (15.7 per cent), while cryptocurrency-related scams accounted for 12 cases (11.8 per cent). Account takeover and impersonation made up 10 cases, online shopping fraud nine, and fake websites and phishing eight. A further 23 cases, or 22.5 per cent, carried a clear telecommunications or SIM-related element.
The committee noted that reported cases rose sharply from May onward, with 70 of the 102 cases, or 68.6 per cent of the six-month total, recorded between May and July. July alone registered the highest monthly volume at 27 cases.
In response, the government said it would tighten monitoring of high-risk mobile money transactions, set up faster channels for preserving and escalating digital evidence with telecommunications providers, and sharpen intelligence gathering around investment, forex and cryptocurrency schemes. Authorities also pledged quicker action against fake websites and impersonation accounts, alongside more consistent classification of fraud data.
Omollo warned that fraud complaints would be investigated and offenders prosecuted in accordance with the law. The committee urged Kenyans to exercise caution when using digital financial services and to think twice before responding to online investment, cryptocurrency, shopping or recruitment offers. The public was advised never to disclose PINs, passwords or one-time passwords, to enable multifactor authentication where available, and to report suspicious numbers, accounts, websites and transactions to service providers, regulators and law enforcement.
The same meeting reviewed wider cybersecurity threats. The Kenya Computer Incident Response Team–Coordination Centre reported 2.3 billion cyber events during the period, a 30 per cent decline from the previous quarter, attributed to improved collaboration on security advisories. Ransomware, social engineering, malware, denial-of-service attacks and AI-assisted attacks remained the dominant threats, while the ICT Authority disclosed that a government website had been defaced after attackers exploited a zero-day vulnerability, with forensic investigations ongoing.
The findings come as Kenya ranks first in East Africa for cybercrime cases and among the top five on the continent, according to Interpol’s 2025 cybercrime report.




























































