AI Illustration
The government has stepped up to tighten monitoring of high-risk mobile money transactions after an analysis found that mobile money was used as either the payment method or destination in 51 of 102 computer fraud cases reported between February and July 2026.
The finding was presented during the 36th meeting of the National Computer and Cybercrimes Coordination Committee (NC4), chaired by Principal Secretary for the State Department for Internal Security and National Administration Raymond Omollo.
According to the analysis, mobile money fraud was the largest single fraud scheme, accounting for 19 cases, or 18.6 per cent of the cases reviewed.
Investment and foreign exchange schemes followed with 16 cases, representing 15.7 per cent, while cryptocurrency-related schemes accounted for 12 cases, or 11.8 per cent.
The analysis also found that 23 cases, equivalent to 22.5 per cent, contained explicit telecommunications or SIM-related indicators.
Reported cases increased from May, with 70 cases, or 68.6 per cent of the six-month total, recorded between May and July. July recorded the highest monthly volume at 27 cases.
The government said the findings would inform efforts to strengthen the response to mobile-enabled fraud, including closer monitoring of high-risk mobile money transactions and faster channels for preserving and escalating evidence involving telecommunications providers.
The response will also focus on intelligence gathering around investment, foreign exchange and cryptocurrency schemes, quicker action against fake websites and impersonation accounts, and more consistent classification of fraud data.
Omollo warned that fraud complaints would be investigated and offenders prosecuted in accordance with the law.
The committee urged the public to exercise caution when using digital financial services and responding to online investment, cryptocurrency, shopping and recruitment offers.
It advised users not to disclose PINs, passwords, one-time passwords or other authentication credentials and to enable multifactor authentication where available.
Members of the public were also urged to report suspicious phone numbers, accounts, websites and transactions to service providers, regulators and law enforcement agencies.
The meeting also reviewed wider cybersecurity threats facing the country.
The Kenya Computer Incident Response Team–Coordination Centre reported 2.3 billion cyber events during the period under review, a 30 per cent decline from the previous quarter.
Ransomware, social engineering, malware, distributed denial-of-service attacks and AI-assisted attacks were among the threats identified.
The centre attributed the decline to continued collaboration and institutional action on cybersecurity advisories.
The Information and Communication Technology Authority also briefed the committee on the defacement of a government website following the exploitation of a critical zero-day vulnerability affecting its content management system.
Digital forensic work is underway to support investigations and possible prosecutions.
The National Cohesion and Integration Commission warned that ethnically charged narratives and organised online mobilisation, amplified by AI-generated and synthetic media, fake accounts and bots, could deepen social divisions and weaken public trust.
The committee said the speed and cross-platform spread of harmful online content was complicating monitoring and response while stressing the need to protect legitimate political discourse.
The meeting brought together senior government and security officials, including Inspector-General of the National Police Service Douglas Kanja, ICT Authority chief executive officer Jessy Kiveu Maruti and NCIC chief executive officer Daniel Mutegi Giti.