In May 2026, Equity Bank — Kenya’s largest lender by customer numbers — issued a statement it had not planned to write. A claim was moving fast across social media: a customer had lost money out of her own account, and no one could explain how.
Investigators traced it to a point of failure that had nothing to do with the bank’s vaults or servers. The woman’s personal email had been compromised, and with it, the credentials her banking app trusted to confirm it was really her. Whoever broke in used them to reach into her mobile money profile and move her savings out from under her. By the time anyone noticed, it was done.
Equity’s statement confirmed her email had been “compromised through fraudulent third-party access,” and that her banking credentials had gone with it. The bank said it had brought in security agencies and begun trying to recover the funds.
It could not say when, or whether, she would get them back. Her name has never been made public. But her account of waking up to a financial life quietly emptied — because one password unlocked everything tied to it — is one of the most ordinary stories in Kenya’s digital economy, repeated in different forms thousands of times a year.
“Fraudsters get people to actually press in the codes that would transfer money to the fraudster without the person realizing. They’re very, very cunning.” — Nicolas Mulila, Group Chief Risk Officer, Safaricom
She is not alone, and the numbers behind her show exactly how not alone she is.
The Numbers Behind Her
| Indicator | Figure | Source |
| Kenya’s total cybercrime losses, 2025 | ~Sh29.9 billion | Serianu Africa Cybersecurity Report 2025 |
| Direct bank fraud losses, 2024 (up from Sh412m in 2023) | Sh1.6 billion | Central Bank of Kenya, Financial Sector Stability Report 2024 |
| Of which, lost through mobile banking specifically | Sh810 million | CBK, 2024 |
| Mobile money moved through the system, Jan–Sep 2024 | Sh6.5 trillion | CBK, 2024 |
| Kenyans targeted by fraud attempts in a single 2024 quarter | 80% (only 8% filed a complaint) | World Bank survey |
| Safaricom SIM-swap investigations, 2025 vs 2024 | Up 327% (11 → 47 cases) | Safaricom |
| Mobile money users unaware of what a SIM-swap scam is | >60% | Mount Kenya University Cybercrime & SIM-Swap Report, 2025 |
Underreporting, researchers note, means the real national bill is almost certainly higher than any official figure captures — banks often quietly reimburse victims to protect their own reputations rather than log every case.
Inside Kamiti: The Con Run From a Cell
Not every fraud in this economy begins with a hacked inbox. Some begin behind bars.
Inside Kamiti Maximum Security Prison, a man serving life for robbery with violence built a second criminal career using a smuggled phone and a stranger’s trust. Patrick Shikure Amere told his victim, a job seeker with a PhD, that he was Eugene Wamalwa, then Kenya’s Cabinet Secretary for Defence.
Over several weeks in 2020, he and an accomplice courted her on Facebook, requested her CV, and promised a State House posting with a monthly salary of 2.2 million shillings and a furnished house with a gym. They forged an appointment letter bearing the signature of the Head of Public Service. She paid roughly 800,000 shillings in instalments, wired by mobile money to Amere inside the prison, who routed it onward through his sister’s M-Pesa account.
Amere pleaded guilty at Milimani Law Courts and was sentenced to three years — but later told the court he wanted to name prison officers he claimed had helped run the scheme. The magistrate ordered detectives to explain how phones kept reaching the country’s highest-security facility.
Four years later, another Kamiti inmate was accused of orchestrating a far larger scheme from the same walls: 7.6 million shillings taken from a businesswoman in a fake land deal, allegedly laundered through his mother’s real-estate purchases outside.
Six Cases, One Pattern
| Case | Amount | Mechanism | Outcome |
| Equity Bank customer, 2026 | Undisclosed | Hacked email → mobile money credentials | Under investigation, funds not confirmed recovered |
| Patrick Shikure Amere, Kamiti Prison | Sh800,000 | Impersonation of a Cabinet Secretary via Facebook | Guilty plea; 3-year sentence |
| Unnamed Kamiti inmate, 2024 | Sh7.6 million | Fake land-sale scheme run from prison | Investigation ongoing |
| Wambugu v. Equity Bank | Sh3m + Sh1,067,802 | Alleged remote hack of email/banking credentials | Court found bank not liable |
| Karangi family estate case | Sh10,464,725 | Fraudulent court decree against a living man’s “estate” | Family still litigating |
| Equity Bank internal fraud, 2024 | Sh1.5 billion+ | Staff used stolen system credentials for payroll/mobile transfers | 1,200+ staff dismissed |
Different mechanisms, same throughline: a single compromised credential, document, or insider was enough to move real money out of real accounts — in sums ranging from one family’s savings to over a billion shillings at once.
The Machinery of a Con

Fraud investigators describe this as performance, not hacking. A name, a phone number, an ID number, or a past transaction is enough to make a stranger sound official. Then comes the script: a caller poses as a bank officer, a telecom rep, or — as with Amere — a senior official, and manufactures urgency until a victim volunteers a code or approves a payment they believe protects them.
Safaricom’s own advisories now catalogue the newer variants: fake “double SIM registration” calls demanding a PIN “for verification,” threats of line suspension unless a link is clicked, and prompts that guide a victim through typing in the very codes that move their own money.
“Your M-Pesa PIN is your final line of defence. Before approving any prompt, take a moment to confirm who you’re paying and why.” — Safaricom, official fraud advisory, July 2026
SIM-swap fraud sharpens the danger further: with a fraudulently obtained replacement SIM, a criminal can silently redirect every OTP meant for the real customer. Investigators have separately alleged that networks obtained personal data belonging to more than 61,000 registered voters — a reminder that stolen identity records now circulate as a commodity, sold in bulk.
What a Phone Behind Bars Can and Cannot Do
Kenya Prisons Service has periodically publicised searches recovering handsets and SIM cards from cells, but specialists caution against fixating on the device. A phone in a locked cell is inert without a network on the outside — someone to receive money, someone to withdraw it, someone to keep the operation running when one link is arrested.
That is what made the Amere case significant: court testimony pointed not to a lone opportunist but to a structure, echoing what criminologists studying organised fraud have long observed — recruiters, callers, account holders and cash-out agents each handling one piece, so no single arrest exposes the whole chain.
Chasing a Crime with No Fixed Address
A call may originate in a prison cell in Kiambu, land on a phone in Kisumu, move funds through an account in Mombasa, and get cashed out in Eldoret — four jurisdictions, each holding only a fragment of the evidence.
The Directorate of Criminal Investigations continues to announce arrests tied to SIM-swap fraud and mule networks nationwide, but each case still depends on matching call records to transaction logs, tracing account ownership, and following money through as many hops as it takes before it disappears into cash.
That patience is precisely what makes these networks hard to dismantle in one sweep. Arresting a caller rarely reaches the account holder who received the funds, and arresting the account holder rarely reaches whoever coordinated the operation from a cell, a rented room, or a laptop in another county entirely.
Each conviction closes one file without necessarily closing the network around it — which is why the same names, the same prisons, and sometimes the same accomplices keep resurfacing in court records years apart.
Victims of this fraud frequently describe shame as sharply as loss — a reluctance to report for fear of being blamed for their own deception. Investigators reject that framing outright: the scripts are rehearsed, the targeting is deliberate, and the manipulation is the point.
A caller who correctly recites a victim’s name, county, or a recent transaction has not demonstrated psychic insight — only that personal data, once leaked, keeps circulating long after the original breach is forgotten.
Closing the Gap
No single institution — prisons, telecoms, banks, police — controls this problem alone, which is why it has persisted through years of individual crackdowns. What comes up repeatedly in expert accounts: faster detection of contraband devices in correctional facilities, identity checks at telecom counters that can’t be rushed past, quicker freezing of funds in the first hours after a report, and public education that keeps pace with tactics that evolve as fast as the technology enabling them.
Kenya built one of the world’s most admired mobile money systems by making transactions almost frictionless. That same quality — speed, trust, minimal friction — is exactly what fraud networks, including ones run from behind prison walls, have learned to weaponise.
Securing it will take every institution that touches a shilling as it moves — the telecom tower, the prison gate, the courtroom — closing its part of the gap at the same time as the others.
Sources: Milimani Law Courts reporting; Equity Bank’s May 2026 public statement; Central Bank of Kenya, Financial Sector Stability Report 2024; Serianu Africa Cybersecurity Report 2025; Safaricom fraud advisories and statements from Group Chief Risk Officer Nicolas Mulila; Mount Kenya University Cybercrime & SIM-Swap Report 2025; Directorate of Criminal Investigations statements; Kenya Prisons Service statements.









