The finding was presented at the committee’s 36th meeting, chaired by Internal Security Principal Secretary Raymond Omollo, according to The Eastleigh Voice. The Standard, Citizen Digital, KBC Digital and Techweez separately reported the same headline totals and the government’s proposed response: closer monitoring of high-risk transactions, quicker preservation of digital evidence and faster escalation paths with telecommunications providers.
The important limitation is in the number itself. The committee did not say that half of all fraud in Kenya occurs through mobile money, nor that mobile-money systems were breached in half of the cases. It said mobile money featured in half of a 102-case set of reported computer-fraud cases reviewed by NC4. That is still a serious concentration, but it is a measure of an investigative caseload—not a national prevalence rate, total victim count or financial-loss estimate.
The 51-case figure is broader than “mobile money fraud”
NC4’s breakdown distinguishes between a fraud scheme and the channel used to move or collect money. Mobile money fraud was the largest single named scheme, with 19 cases, or 18.6% of the reviewed total. Investment and foreign-exchange schemes followed with 16 cases, while cryptocurrency schemes accounted for 12.
The 51-case mobile-money figure is larger because it captures a wider role: a wallet could have been used to receive stolen funds, collect a scam payment or move proceeds after another compromise. A recruitment scam, a fake online shop, an account-takeover incident or an investment fraud can therefore appear in the mobile-money total without being classified as a mobile-money fraud scheme.
That distinction is more than statistical housekeeping. If investigators, operators and banks respond only by looking for fraudulent wallet transfers, they may miss the attack that produced the transfer: a cloned login page, stolen one-time password, compromised email account, impersonation call or falsified recruitment offer. The committee’s own advice—do not disclose PINs, passwords or authentication codes—points to social engineering as a likely entry point in at least part of the case set, even though the public reporting does not provide a case-by-case breakdown.
For IT administrators, this is a familiar incident-chain problem. The financial transaction is often the observable outcome, while the compromise may have occurred earlier on a Windows PC, an unmanaged Android handset, a browser session, a corporate email account or a telecom identity record. Preserving evidence only after money has moved gives criminals time to empty intermediary accounts and erase the most useful traces.
Telecom indicators put the phone number inside the fraud chain
The committee identified telecommunications or SIM-related indicators in 23 of the 102 cases, or 22.5%. It did not publicly enumerate those indicators or identify operators, affected services, specific tactics, or how many incidents involved confirmed SIM swaps. Still, the direction is clear: fraud investigators are increasingly treating the mobile number as both an identity token and a potential point of failure.
That matters because phone-based authentication remains common across banking, consumer applications, government portals and workplace accounts. A number that is reassigned, intercepted or socially engineered can expose SMS-delivered one-time passwords and password-reset workflows. Even where a mobile wallet itself has not been technically compromised, the attacker may exploit a phone number to gain access to a linked service and then use the wallet as the cash-out mechanism.
The committee’s call for faster evidence-preservation and escalation channels with telecom providers is therefore one of the most consequential parts of the announcement. Mobile-money and telecom fraud investigations move on a short clock: account balances can be transferred repeatedly, messaging records may be unavailable to a victim, and provider records can be difficult to obtain after the immediate period of relevance has passed.
The government has not said what service-level targets those faster channels will have, whether they will operate around the clock, or whether a report from a victim or enterprise will be enough to trigger an emergency preservation request. It has also not disclosed whether providers will be expected to place temporary holds on suspect wallet activity, how false-positive disputes will be handled, or whether the process will cover cross-provider transfers. Those missing details determine whether the proposal becomes a meaningful response mechanism or remains a coordination goal.
A sharp late-period rise needs better classification, not a simple trend line
Seventy of the 102 cases were reported between May and July, with July alone recording 27. On its face, that means 68.6% of the six-month reviewed caseload landed in the final three months.
The data is too limited to call that a confirmed surge in underlying criminal activity. It could reflect more scams, but it could also reflect reporting changes, delayed case referrals, a focused enforcement operation, revised case classification or a spike in awareness after public warnings. NC4’s own recommendation for consistent fraud-data classification suggests the government recognizes that its current categories are not yet sufficient for reliable trend analysis.
That is the story beneath the headline: Kenya has identified a pattern worth acting on, but it has not published enough underlying information for outsiders to test the pattern’s scale, causes or persistence. There are no public figures in the reporting for money lost, victims affected, recovery rates, time to freeze funds, provider-level exposure, arrest outcomes or the share of cases that began with phishing, SIM abuse, malware or insider assistance.
A national fraud dashboard that separated initial access, impersonated brand, authentication factor abused, cash-out route, provider response time and funds recovered would be considerably more useful than a top-line category count. It would also help enterprises decide whether to prioritize phishing-resistant authentication, help-desk verification controls, mobile-device management or financial-transaction monitoring.
2.3 billion “cyber events” should not be read as 2.3 billion incidents
At the same meeting, Kenya’s Computer Incident Response Team Coordination Centre, KE-CIRT/CC, reported 2.3 billion cyber events for the period under review, down 30% from the preceding quarter. Ransomware, social engineering, malware, distributed denial-of-service activity and AI-assisted attacks were listed among the threats being tracked.
The reported decline should not be treated as proof that risk has fallen. A cyber event commonly includes automated detections such as scans, blocked connection attempts, suspicious requests and telemetry alerts; it is not necessarily a successful intrusion or a separately verified attack. The public account does not explain the event-counting method, monitored population, severity mix, deduplication rules or what portion reached affected organizations.
KE-CIRT/CC attributed the lower total to continued collaboration and action based on advisories. That may be accurate, but without methodology and outcomes—such as reduced confirmed compromises, remediation coverage or time-to-containment—the number is best read as an operational signal rather than a clean national security scorecard.
The committee also discussed a government website defacement after exploitation of a critical zero-day vulnerability in its content-management system. Officials said digital forensics were under way, but they have not named the affected site, software product, vulnerability identifier, attack date, data exposure or whether the flaw was exploited beyond visual defacement. Organizations should resist filling those gaps with assumptions: a defaced page may be limited to web-content integrity, but it can also be the visible symptom of deeper administrative access.
What businesses and users should change now
The immediate practical response is to build a fraud playbook that treats a suspicious payment, a phone-number event and an account-authentication event as potentially connected. Security teams should document who can request urgent log preservation from banks, mobile-money providers, telecom operators and cloud or email providers—and ensure that legal, fraud and IT contacts can act outside ordinary business hours.
Users should enable multifactor authentication where it is available, but enterprises should also recognize its limits when the second factor depends on SMS. High-risk administrators, finance approvers and help-desk staff should use phishing-resistant authentication where their platforms support it, while password resets and SIM-change requests should receive enhanced verification.
Kenya’s 102 reviewed cases do not establish that mobile wallets are inherently unsafe. They show that mobile money has become a prominent junction in the fraud chain, where digital deception becomes an irreversible transfer. The government’s next meaningful update needs to show whether faster telecom escalation and evidence preservation actually reduce the time criminals have to move the money.