A recent INTERPOL report highlights Kenya as one of Africa's most targeted countries for cybercrime, with mobile money fraud topping the list of threats. The findings reveal a sharp rise in SIM swap attacks and distributed denial-of-service (DDoS) incidents, exposing vulnerabilities in the nation’s digital infrastructure.
Key Findings on Kenya’s Cybersecurity Landscape
- Kenya recorded more than 46,786 DDoS attacks in the first half of 2025, primarily targeting telecommunications operators.
- SIM swap fraud surged by 327% in 2025, with over 123,000 fraudulent SIM cards issued, resulting in estimated losses of $3.8 million (Sh492 million) from mobile money wallets.
- Phishing attacks increased, with Kenya featuring among countries with the highest detection rates.
- Mobile money subscriptions reached 53.4 million by March 2026, expanding the sector’s exposure to cyber threats.
Underlying Challenges and Criminal Tactics
The report attributes the spike in cybercrime to weak know-your-customer (KYC) systems and inadequate real-time biometric verification by telecom providers. Criminals exploit these gaps to create synthetic identities combining real and fabricated data, enabling them to bypass security checks.
Cybercriminal networks have industrialized their operations, leveraging artificial intelligence (AI) to conduct faster, more scalable, and harder-to-detect attacks. AI-enabled scams now account for 55% of cybercrimes reported across Africa.
Sectoral Impact and Regional Context
Financial services, telecommunications, and government institutions remain the most affected sectors. Kenya’s experience mirrors trends in Tanzania and Rwanda, where similar challenges with SIM swap fraud and biometric verification exist.
The report also notes ransomware attacks on critical infrastructure in the region, including a notable incident involving Uganda’s national power grid.
Response and Recommendations
Kenya has made legislative progress with the Computer Misuse and Cybercrimes (Amendment) Bill 2024, targeting SIM swap fraud and scam calls. However, INTERPOL warns that the absence of a unified regional cybercrime response framework allows criminal groups to exploit jurisdictional gaps.
Improved cooperation between banks, telecom companies, and law enforcement is crucial. Currently, financial institutions often lack the authority to promptly block suspicious transactions or freeze compromised accounts without lengthy court procedures.
As cybercrime evolves into a borderless industrial network, the report calls for enhanced real-time verification systems and stronger legal frameworks to safeguard Kenya’s rapidly growing digital economy.