Cyber fraud in Kenya’s banking sector more than doubled in one year. Reported cases rose from 153 in 2023 to 353 in 2024, while actual losses increased from KES 412 million to approximately KES 1.59 billion, according to the Central Bank of Kenya (CBK).
At the same time, Kenya’s rapid shift toward mobile and digital banking is expanding the attack surface for fraudsters, ransomware groups, insiders and compromised third parties.
For Kenyan banks, cybersecurity is no longer simply an IT concern. It is a financial, operational, regulatory and reputational risk that increasingly belongs on the boardroom agenda.
Kenya’s Banking Cybersecurity Landscape at a Glance
| KEY METRIC | LATEST AVAILABLE FIGURE |
|---|---|
| Mtric | Figure |
| Banking cyber-fraud cases, 2024 | 353 |
| Banking cyber-fraud cases, 2023 | 153 |
| Actual fraud losses, 2024 | KES 1.59 billion |
| Amount exposed to fraud, 2024 | KES 1.96 billion |
| Customers preferring mobile banking, 2021 survey | 58.5% |
| Commercial banks ranking cyber risk among top 3 innovation risks | 92% |
| Microfinance banks doing the same | 86% |
| KE-CIRT/CC cyber-threat events, Apr–Jun 2025 | 4.59 billion |
CBK recorded 353 reported banking fraud cases in 2025, with KES 1.963 billion exposed and KES 1.594 billion actually lost. Meanwhile, the Communications Authority of Kenya (CA) reported more than 4.59 billion cyber-threat events between April and June 2025.
The takeaway: Kenya’s financial sector is becoming increasingly digital at precisely the moment the threat environment is becoming more complex.
What Are the Biggest Cyber Threats Facing Banks in Kenya?
The biggest cyber threats facing banks in Kenya are not limited to traditional hacking. Financial institutions are dealing with a combination of mobile banking fraud, SIM-swap attacks, insider threats, ransomware, third-party compromise and large-scale system attacks.
Kenya’s Cyber Threats: Risk Comparison
| THREAT | PRIMARY TARGET | POTENTIAL IMPACT |
|---|---|---|
| SIM-swap & smishing | Customers | Account takeover and financial loss |
| Insider threats | Accounts and internal systems | Fraud and data theft |
| Ransomware | Core systems and endpoints | Operational disruption |
| Third-party compromise | Vendors and connected systems | Data exposure and lateral access |
| System-level attacks | Networks, devices and databases | Infrastructure compromise |
These threats can also overlap. A compromised employee or contractor account, for example, could provide an attacker with legitimate access that can then be used to steal data or facilitate fraudulent transactions.
1. Mobile Banking: Kenya’s Biggest Cybersecurity Pressure Point?
Kenya’s mobile-first financial ecosystem has transformed access to banking. But the same convenience has created an attractive target for cybercriminals.
According to the Kenya Bankers Association’s Customer Satisfaction Survey, 58.5% of bank customers preferred mobile banking, compared with 52% in 2020.
The wider mobile-money ecosystem is also enormous. The Communications Authority reported 48.6 million mobile-money subscriptions by September 2025, representing 92.8% penetration.
For attackers, mobile banking offers speed.
A typical SIM-swap attack can follow this pattern:
Social engineering → SIM replacement → OTP interception → Account access → Fraudulent transaction
Smishing adds another layer, with criminals sending messages impersonating banks or trusted organizations to trick customers into revealing credentials or visiting fraudulent websites.
How Banks Can Reduce Mobile Banking Risk
Banks should move beyond relying solely on SMS-based authentication and combine multiple signals before approving high-risk transactions.
Key controls include:
- Stronger, app-based authentication
- Device fingerprinting
- Behavioural analytics
- Transaction risk scoring
- SIM-swap detection
- Cooling-off periods after SIM changes
- Step-up authentication for unusual transactions
- Real-time customer alerts
- Continuous anti-smishing awareness
The Communications Authority also recommends measures such as multi-factor authentication, strong passwords, regular patching and strengthened security controls as part of cyber-risk management.
The objective is straightforward: a valid credential should not automatically mean a valid transaction.
2. Insider Threats: When the Attacker Already Has Access
External hackers are only part of Kenya’s banking security challenge.
Employees, agents, contractors and other trusted users can have legitimate access to customer information, applications or transaction systems. That makes insider risk particularly difficult to detect.
CBK’s banking-sector innovation research found that 92% of banks and 86% of microfinance banks identified cyber risk among their top three innovation-related risks. The same research also highlighted third-party and vendor-management risks.
Insider risk does not necessarily mean a malicious employee. It can involve:
- Compromised credentials
- Excessive privileges
- Poor access controls
- Inadequate monitoring
- Third-party accounts
- Deliberate employee or agent collusion
Four Controls Banks Should Prioritize
Least privilege: Employees should only have access to the information and systems required for their roles.
Segregation of duties: High-risk activities should not be concentrated with one individual.
Behavioural monitoring: Banks should monitor unusual access and transaction patterns rather than relying solely on login failures.
Continuous access reviews: Privileges should be reviewed when employees change roles and immediately when contractors or employees leave.
The key principle is to treat trusted access as a risk that requires continuous verification, rather than assuming legitimate credentials are inherently safe.
3. Ransomware: From Cyber Incident to Banking Outage
Ransomware is especially dangerous for financial institutions because its impact can extend beyond stolen information.
An attack could potentially result in:
ATM disruption → Mobile banking downtime → Failed transactions → Branch disruption → Customer trust impact
That makes ransomware a business-continuity issue as much as a cybersecurity issue.
Kenya’s wider cyber environment demonstrates the scale of the challenge. During April–June 2025, KE-CIRT/CC recorded approximately 4.59 billion cyber-threat events, including malware and distributed denial-of-service activity.
Common ransomware entry points include:
- Phishing
- Compromised credentials
- Unpatched systems
- Vulnerable remote-access services
- Malicious files
- Compromised third parties
4. Third-Party Risk: The Extended Banking Attack Surface
Modern banks rely on an extensive network of technology and service providers.
Cloud platforms, payment processors, IT contractors, software vendors and telecommunications providers can all connect to systems or data that banks need to operate.
That creates an extended attack surface.
Kenya’s Cyber Threat Volume Shows the Scale of the Problem
Banks operate within Kenya’s broader digital ecosystem, so national cyber-threat trends matter.
KE-CIRT/CC recorded 4,586,682,277 cyber-threat events between April and June 2025, representing an 80.70% increase from the previous quarter. More than 4.49 billion of those events were classified as system attacks.
These numbers should be interpreted carefully. A cyber-threat event is not necessarily a successful breach or financial attack. It represents activity detected by the national monitoring infrastructure.
The important point for banks is the scale and volatility of the threat environment.
Threat volumes can rise or fall dramatically from one reporting period to another. That makes continuous monitoring and threat intelligence more valuable than relying exclusively on periodic security reviews.
How Is the Central Bank of Kenya Responding?
CBK has taken steps to strengthen cybersecurity coordination across Kenya’s banking sector.
One of the most significant developments is the Banking Sector Cybersecurity Operations Centre (BS-SOC), established by CBK in September 2025.
Operating under CBK’s Cyber Fusion Unit, the centre is designed to strengthen capabilities around:
- Cyber threat intelligence
- Incident response
- Digital forensics
- Cyber investigations
- Sector-wide information sharing
CBK has also stated that regulated institutions are required to report cybersecurity incidents to the BS-SOC within stipulated timelines under the applicable cybercrime regulations.
This represents a shift from isolated institutional responses toward greater sector-wide cyber resilience.
For banks, the practical implication is clear: cybersecurity programs need to align not only with internal risk frameworks but also with the broader regulatory and intelligence-sharing ecosystem.
The 2026 Cybersecurity Priorities for Kenyan Banks
There is no single technology that can eliminate banking cyber risk.
Instead, banks need a layered approach covering customers, employees, infrastructure, third parties and regulatory requirements.
Six priorities stand out:
1. Modernize authentication
Reduce dependence on SMS-only authentication and introduce stronger risk-based controls.
2. Strengthen insider-risk monitoring
Use behavioural analytics and transaction monitoring to identify suspicious activity.
3. Tighten third-party access
Apply rigorous access, monitoring and offboarding standards to vendors and contractors.
4. Build ransomware resilience
Segment critical systems, maintain isolated backups and test recovery procedures.
5. Strengthen threat intelligence
Use sector-wide intelligence and information-sharing mechanisms to identify emerging threats faster.
6. Integrate cyber risk into enterprise risk
Bring technology, fraud, compliance, legal and communications teams into cyber-incident planning.
Conclusion
Kenya’s banking sector is entering a period where digital growth and cyber risk are advancing together. Reported banking cyber-fraud cases increased from 153 to 353 between 2023 and 2024, while actual losses reached approximately KES 1.59 billion, against a backdrop of billions of cyber-threat events detected across Kenya’s digital infrastructure. Mobile banking, insider access, ransomware and third-party exposure must therefore be treated as interconnected business risks rather than isolated IT issues. With CBK strengthening sector-wide capabilities through the Banking Sector Cybersecurity Operations Centre and national monitoring continuing through KE-CIRT/CC, Kenyan banks have an increasingly clear framework for moving from reactive defense to proactive resilience. The priority for 2026 is not simply to prevent the next attack, but to detect it faster, contain it sooner, recover quicker and protect customer trust throughout the process.