Your Phone Is Now the Frontline: How AI Is Fueling Cybercrime in Kenya | #cybercrime | #infosec


Kenya’s hard-earned reputation as a global mobile money pioneer is facing a sobering reality check following recent reports. Interpol’s African Cyberthreat Assessment Report 2026 ranks Kenya as the second most vulnerable country to cyberattacks in Africa and identifies the East African Community as a hotspot for mobile money fraud. Another worrying finding adds to this: artificial intelligence is now involved in 55 per cent of reported cybercrimes across the continent. Viewed separately, these are three major stories. Viewed together, they reveal a growing crisis in a region where digital growth has outpaced digital security, allowing criminals to exploit the same mobile systems that helped bring financial services to millions. 

How We Got Here 

Kenya’s vulnerability is, in many ways, the cost of its success. The country led the way in large-scale mobile money through M-Pesa, developed one of Africa’s most advanced telecommunications sectors, and moved government services online faster than many neighboring countries. However, Interpol’s report says that Kenya’s high level of exposure, 11.9% of all exploitable digital weaknesses found across Africa in 2025, behind only South Africa’s 43.6% and ahead of Nigeria’s 9.1%, is mainly due to poor cybersecurity practices, limited investment in cyber protection, and delays in updating systems across both public and private institutions. Simply put, digital infrastructure expanded faster than the systems designed to protect it.  

The figures show how serious the situation has become. Kenya experienced more than 46,786 distributed denial-of-service attacks on telecom networks in the first half of 2025 alone. The Communications Authority of Kenya also recorded 2.35 billion cyber threat events in the three months ending June 2026, mainly because systems were not updated on time, many people remained unaware of phishing scams, and attackers increasingly used AI. Government and ICT systems faced hundreds of millions of attempted attacks between July and September 2025, most of which used brute-force techniques. Several major incidents highlighted the problem: hackers took over President William Ruto’s official website. They demanded five Bitcoin as ransom, while the High Court ruled that Safaricom was responsible for a data breach that exposed customers’ financial, location and browsing information between 2018 and 2019.  

Weakness in Mobile Money  

While DDoS and other network attacks target digital infrastructure, SIM-swap fraud directly targets people’s money, and this is where East Africa’s mobile money success has become its biggest weakness. Interpol found that investigations into SIM-swap fraud in Kenya increased by 327 per cent in 2025, with more than 123,000 fraudulent SIM cards identified. Criminals used these compromised SIM cards to take control of mobile money accounts, stealing about KSh491.6 million from victims. Since mobile phones also serve as banking credentials within East Africa’s financial system, stealing a SIM card is almost the same as stealing a bank account. This is a weakness unique to mobile-first economies, one that traditional cybersecurity systems, built mainly for desktop banking, were never designed to address.  

AI & Cybercrime 

The link between Kenya’s infrastructure weaknesses and the region’s fraud problem is the growing use of artificial intelligence (AI). Interpol’s report says AI is now involved in 55 per cent of reported cybercrimes across Africa, making attacks quicker to carry out and harder to detect. Deepfake incidents increased sevenfold across the continent between the second and fourth quarters of 2024. The report also highlights the growing use of AI-generated fake identities to bypass Know-Your-Customer checks, the same security process banks and mobile money providers rely on to prevent fraud during customer registration. AI is not creating entirely new crimes; instead, it is making existing crimes much easier to carry out, allowing a single criminal network to conduct phishing, SIM-swapping, and identity fraud on a scale and at a speed that human investigators cannot easily keep up with.  

 What Next? 

Moving forward means treating cybersecurity as essential national infrastructure rather than an afterthought. Kenya is already one of only four African countries, along with Nigeria, South Africa and Mauritius, that require cyber incidents to be reported within 72 hours, giving it a strong starting point. Key priorities include ensuring government and telecom systems receive regular, properly funded security updates; introducing stronger real-time identity verification to reduce SIM-swap fraud; investing in AI skills and technology for law enforcement and telecom fraud teams to close the technical gap highlighted by Interpol; and aligning cybercrime laws across the East African Community so criminals cannot simply move their operations across borders to avoid prosecution. Public education on phishing and SIM-swap scams, together with quicker coordination between telecom companies and banks when SIM swaps are reported, would also reduce fraud even before more advanced technical solutions are fully developed.  

Conclusion  

Kenya’s current situation is not the result of failed digital ambition; it reflects the unfinished work that accompanies rapid digital growth. The same mobile money system that made Kenya a leader in Africa has also become its most vulnerable point, targeted by criminals who increasingly use AI. Interpol’s report is not simply a judgement but a warning that the region that led Africa in mobile-first finance now has the opportunity to lead in mobile-first cybersecurity, but only if system updates, identity verification, regional cooperation and AI capability receive the same level of commitment that once made M-Pesa a success. 



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW