INTERPOL's 2026 report names Kenya East Africa's top cybercrime target, citing a 327% surge in SIM swap fraud and mobile money attacks.

Kenya Named East Africa’s Top Cybercrime Hotspot by INTERPOL

The420 Web Correspondent
5 Min Read

Kenya has emerged as East Africa’s most cyber-vulnerable nation, according to INTERPOL’s African Cyberthreat Assessment Report 2026, which warns that the country’s rapid digital expansion has significantly outpaced its ability to defend the infrastructure underpinning it. The report singles out attacks on mobile money platforms, telecommunications networks and government digital systems as the primary threats facing Kenya, painting a picture of a digital economy whose growth has become its own greatest vulnerability.

A Digital Economy Growing Faster Than Its Defences

Kenya’s exposure stems directly from the scale of its digital adoption. Widespread reliance on mobile money services, combined with rapidly expanding digital payment systems and growing everyday dependence on connectivity, has created exactly the conditions cybercriminal networks look to exploit, according to the assessment.

Telecommunications infrastructure bore the brunt of this pressure through sheer volume of attack. Kenyan telecom operators recorded more than 46,786 Distributed Denial-of-Service attacks in just the first half of 2025 alone, floods of malicious traffic aimed at disrupting services that millions of citizens depend on daily. Kenya also ranked among the countries with the highest phishing detections globally as of September 2025, according to the report.

Government systems fared no better. Data from the Communications Authority of Kenya cited in the assessment recorded hundreds of millions of attempted intrusions against government institutions and ICT infrastructure between July and September 2025 alone, the bulk of them relying on brute-force techniques aimed at forcing unauthorised access into digital networks. The report’s most striking illustration of this vulnerability came in July 2025, when attackers briefly compromised the Kenyan Presidency’s official website, defacing its homepage with a ransom demand in Bitcoin worth approximately KSh 41 million.

SIM Swap Fraud Surges by 327 Percent

Nowhere is the cost of Kenya’s digital exposure more concrete than in its mobile money fraud figures. INTERPOL’s data shows SIM swap fraud surged 327 percent during 2025, with more than 123,000 fraudulent SIM cards issued over the year. Criminals used these hijacked numbers to seize control of victims’ mobile identities, gaining unauthorised access to banking and payment accounts before draining an estimated US$3.8 million from mobile wallets.

The mechanics of SIM swap fraud make it particularly difficult to defend against in markets built around mobile-first financial inclusion. Once a fraudulent SIM replacement succeeds, criminals inherit the very channel most banks and payment platforms use to verify a user’s identity, effectively turning the security mechanism itself into the point of failure.

Kenya’s troubles are not occurring in isolation. The wider INTERPOL assessment found artificial intelligence now plays a role in roughly 55 percent of reported cybercrime across the African continent, making attacks faster to execute and considerably harder for both victims and platforms to detect. Uganda faced a suspected ransomware attack on its national electricity transmission company, while Tanzania and Rwanda both recorded rising SIM swap fraud as telecom providers struggle to roll out real-time biometric verification. Elsewhere on the continent, South Africa remains its leading ransomware target, accounting for roughly 92 percent of all detections, while Nigeria and Cabo Verde continue to anchor West Africa’s Business Email Compromise fraud economy.

Legislation Alone Will Not Be Enough, INTERPOL Warns

Kenya has responded by advancing its legal framework through the proposed Computer Misuse and Cybercrimes Amendment Bill 2024, aimed specifically at SIM swap fraud and scam calls. INTERPOL, however, was direct in cautioning that legal reform alone cannot resolve a threat landscape defined by cross-border coordination and rapidly evolving criminal tactics. The agency stressed that stronger cybersecurity systems, better protection of critical digital infrastructure and deeper regional cooperation will all be necessary to meaningfully counter the trend.

Cybercrime expert and former IPS officer Prof. Triveni Singh said cybersecurity frameworks must evolve at the same pace as digital payments and mobile services themselves, rather than trailing behind them. He said countering SIM swap fraud, phishing and social engineering attacks effectively requires real-time intelligence sharing and stronger multi-factor authentication working in tandem across telecommunications companies, financial institutions and law enforcement.

For India, whose own mobile-first digital payments ecosystem has scaled at a comparable pace over the past decade, Kenya’s experience offers a cautionary parallel. Both economies have built financial inclusion substantially around mobile identity and instant payments, a design that delivers enormous convenience but concentrates risk precisely where SIM swap fraud and telecom-targeted attacks strike hardest.

Stay Connected