From August 14, cyber cafés in Kenya must register customers to help authorities trace criminals who exploit public internet facilities to commit cyber offences.
The directive comes as Kenya sees increased SIM-swap fraud, mobile and online banking theft, phishing, and identity theft, fuelled by the rapid adoption of digital financial services.
Why is the government collecting cyber café users data?
Kenya is grappling with high cases of identity theft and impersonation, mobile and online banking fraud, SIM-swap scams, and phishing attacks. SIM swap fraud has seen fraudsters hijack victims’ phone numbers, gaining unauthorised access to sensitive accounts such as banking, mobile phone wallets and cryptocurrency platforms.
The criminals convince a mobile carrier to transfer a victim’s phone number to a SIM card they control.
Through phishing, cybercriminals impersonate trusted organisations or individuals to trick people into revealing sensitive information like passwords, bank card numbers or login credentials.
What is behind the rise of cybercrime in Kenya?
Cyber risks are rising in the wake of the widespread internet penetration and the adoption of digital banking.
More people with smartphones, computers and online money wallets, a few of whom practice safe cyber practices, means a larger playing ground for criminals.
Advances in AI have further allowed hackers and fraudsters to automate cyber attacks, making it more difficult for victims to detect phishing campaigns, malicious requests for information or money and malware deployment.
What are the financial implications of cyber attacks?
Kenyans lost Sh491.6 million ($3.8 million) and cryptocurrency after cybercriminals hijacked victims’ mobile phone numbers in SIM-swap fraud last year, according to the International Criminal Police Organisation (Interpol).
Central Bank of Kenya data estimates that mobile banking was the hardest hit by cyber fraud in 2024, with criminals siphoning off Sh810.68 million, a 344 percent rise from Sh182.41 million in the prior year.
Why are cyber cafés a cybersecurity weak point?
When café owners operate unsecured computers, the machines are targeted with malware capable of capturing usernames, passwords, full names, ID numbers, KRA pins and other sensitive information entered by customers.
Criminals also exploit poorly secured networks to monitor activity or compromise machines, which becomes risky when users access services such as email, mobile banking or cryptocurrency accounts from shared computers.
Because the majority of these cafés do not record identity details of customers, the criminals operate anonymously as police cannot trace them through the shops’ IP addresses.
What do the new rules mean for internet users?
Customers using internet cafés will have to provide identifying information before using the service. Cafés will be required to register customers and maintain basic session logs showing the computer or terminal used and the start and end time of a session.
The rules do not require cafés to keep customers’ personal browsing history. However, they must retain the required customer and session records for at least three years and make them available to authorised Communications Authority of Kenya officers for inspection, audit or investigation.
Customers should expect cyber cafés to ask for information such as their name and identification number and get a receipt for the service.
How will cyber cafés track computers users?
Computers’ terminal ID and session times can create an audit trail. For example, if investigators establish that a particular cyber café computer was used to access an account or conduct activity linked to a cybercrime at 8 pm, the session records could help establish who had registered to use that terminal at the time.
The terminal ID essentially connects the activity to a specific machine, while the start and end times establish when the machine was being used. Combined with customer registration information, these records can potentially give investigators a clearer starting point for tracing a suspect.
This could provide useful leads in cases involving mobile-money theft, SIM-swap fraud, identity theft and other cybercrimes.
What are the penalties for violating the new rules?
Those in breach of the regulations face fines equivalent to 0.2 percent of their businesses’ annual turnover, with the minimum penalty set at Sh500,000. They also face closure of the cafés.
How can one stay safe when browsing at public internet cafés?
Customers are generally advised against accessing sensitive accounts such as mobile money, banking and investment platforms where possible, saving passwords or allowing the browser to remember their login details, and always logging out completely when finished.
Users are encouraged to use two-factor authentication such as SMS codes or authentication apps on their sensitive online accounts, avoid downloading files or installing software or browser extensions, and check website addresses carefully before entering personal information.
Experts warn against connecting unknown USB devices, and if the computer appears suspicious or compromised, stop using it and change any passwords entered from a trusted device.
How does Kenya’s new rules compare to other markets globally?
India and China require users to present an official identity document before accessing cyber cafés to help the governments trace cases of financial fraud, online harassment, hacking and the distribution of prohibited content. It also prevents terror groups from using public internet spaces to coordinate attacks without leaving a personal trace.
Click Here For The Original Source.
