Kenya’s most consequential banking credential may not be issued by a bank. It is the mobile number.

That is why the Communications Authority’s latest complaints data deserves more than a routine warning to “stay vigilant”.

Complaints about fraud and scams escalated to the regulator rose from 47 between January and March 2026 to 86 between April and June, an increase of 83 per cent.

The same quarter produced 110 complaints about digital financial services and mobile money, and 75 about cybercrime or criminal use of ICT infrastructure.

These figures are not a census of Kenyan fraud. They cover complaints escalated to the authority after providers failed to resolve them satisfactorily.

A complaint count measures the door victims found, not the full size of the fire. That limitation strengthens the case for better reporting: policymakers cannot manage a cross-sector risk if they can see only the failures consumers successfully escalate.

Even so, the pattern exposes a structural weakness: Kenya still governs the SIM largely as a telecommunications product although citizens use it as proof of identity across mobile money, banking, eCitizen services and account recovery.

By March 2026, Kenya had 53.4 million active mobile-money subscriptions, according to the authority. When control of a number can unlock a wallet, reset a password or receive a bank’s one-time code, replacing a SIM is no longer routine customer care. It is a security-critical change of identity.

Criminals understand this convergence. Interpol's 2026 Africa Cyberthreat Assessment reported that mobile-money fraud was the most prevalent scam among responding countries.

For Kenya, it reported a 327 per cent rise in SIM-swap fraud during 2025, more than 123,000 fraudulent SIMs and an estimated $3.8 million (Sh490 million) drained from mobile wallets. Those estimates require the same caution as any intelligence-led dataset, but the direction is unmistakable.

Kenya has criminalised unauthorised SIM swapping. Punishment after theft, however, is not a substitute for safe identity-change controls.

Fraud moves across institutions faster than responsibility does. A telco sees the replacement request. A bank sees an unusual transfer. A platform sees a password reset. Each organisation may satisfy its own procedure while the customer loses control of the whole identity chain.

The authentication model is also ageing. The latest NIST digital-identity guidance classifies authentication through the public telephone network as restricted.

It says verifiers should consider a SIM change, device swap or number port before sending a code. SMS one-time codes are not phishing-resistant.

Research presented at the USENIX Symposium on Usable Privacy and Security found exploitable weaknesses in carrier authentication procedures, while later studies show that fallback and account-recovery routes often become the weakest link.

Biometrics alone will not rescue the system. Entrust’s 2026 identity-fraud dataset found deepfakes in one in five biometric fraud attempts it observed.

The appropriate response is layered assurance: strong staff controls, independent verification, liveness checks, device and behavioural risk signals and protected recovery channels. No single selfie, PIN, identity-card image or one-time code should authorise a high-risk identity change.

Kenya now needs an enforceable identity duty of care spanning telecommunications and financial services.

Every SIM replacement or number-port request should trigger verification proportionate to risk, an immediate alert through the old SIM and a previously registered alternative channel, and a simple customer-controlled account lock.

A short, risk-based security window should apply to high-value transfers after a swap, with accessible emergency procedures for legitimate customers who have lost a device.

Banks, mobile-money providers and public digital services should receive a real-time swap or port risk signal before approving sensitive actions.

They should reduce dependence on SMS codes by offering transaction-bound, phishing-resistant authentication such as passkeys, while retaining secure and inclusive alternatives for users without smartphones.

The Communications Authority, Central Bank, Office of the Data Protection Commissioner, Banking Sector Cybersecurity Operations Centre, operators and law-enforcement agencies also need a governed fraud-intelligence mechanism.

It should connect a suspicious SIM change to attempted wallet transfers quickly enough to freeze funds, preserve evidence and warn other institutions, with strict purpose limitation, access logging and independent privacy oversight.

Accountability must follow control. Telcos should not be treated as publishers of every unlawful message crossing their networks.

Yet where a loss follows a proven failure in subscriber verification, staff access control, breach response or a known SIM-swap safeguard, there should be clear investigation, redress and regulatory consequences.

Operators and banks should publish comparable metrics on confirmed fraud, losses, swap-related cases, reimbursement and recovery time, not complaint totals alone.

Other regulators already point towards this model. United States rules require secure authentication before a number is redirected, immediate customer notification and account-lock options.

Australia has imposed cross-sector scam-prevention duties on banks, telcos and digital platforms. Britain is strengthening know-your-customer and traffic-monitoring controls for business messaging.

Kenya pioneered mobile money by treating trust as infrastructure. Its next global contribution should be an identity-safety regime designed for the reality it created.

A SIM that can move money and restore a citizen’s digital life must be regulated like the critical credential it has become.