Why payments attract fraud
Fraudsters go where the money moves quickly. Mobile money is part of everyday life in Kenya. The 2024 FinAccess Household Survey, led by the Central Bank of Kenya, found that 84.8% of adults use formal financial services and that 52.6% use mobile money every day. The Central Bank reported more than 95 million registered mobile money accounts in August 2026 (many people hold more than one account). The same features that make these payments useful (speed, convenience and reach) also make them attractive to criminals:
- Speed: money can move in seconds, and once it has been withdrawn or passed on it is hard to recover.
- Remote access: fraudsters never need to meet their victims.
- The phone as the key: for many people, the phone number and PIN are the whole of their security.
- Scale: a scam that fools one person in a thousand still pays when sent to a million.
Payment fraud falls into two broad kinds:
- Unauthorised fraud: a criminal makes payments from someone's account without their knowledge, for example after stealing their PIN or taking over their phone number.
- Authorised fraud: the victim is tricked into making the payment themselves, believing it to be genuine. Because the victim authorised it, it is often harder to reverse and harder to detect.
Most modern payment fraud begins not with hacking computers but with manipulating people. The rest of this course looks at how.
Scams that trick people into paying
Social engineering is manipulation: persuading someone to act against their own interest by exploiting trust, fear, urgency or greed. Common payment scams include:
- The "wrong send" scam: the victim receives a message that looks like a payment confirmation, then a call or text asking them to "send back" money sent by mistake. Often the message is fake and no money arrived; sometimes real money was sent and the fraudster later asks the provider to reverse it as well. Check your real balance, and ask the sender to request a reversal through the provider rather than sending money back yourself.
- Impersonation: a caller pretends to be from the customer's bank, mobile money provider, a government office or the police, and talks them into sharing a PIN or one-time code, or into moving money to a "safe" account. Caller ID and sender names can be faked; hang up and call the organisation back on the number printed on its official channels.
- Prizes and promotions: a message says the victim has won something and must pay a "fee" or share details to claim it.
- Investment and job scams: promises of high returns or well-paid work, requiring an upfront payment.
- Emergency and family scams: a message claiming a relative is in trouble and needs money now.
- Business payment fraud (often called business email compromise): an organisation receives a convincing request, often by email, to change a supplier's bank details or make an urgent payment for a senior executive.
The warning signs repeat: urgency, secrecy, unexpected contact, and requests for PINs, codes or payments. Genuine banks and payment providers do not ask customers to share their PIN or one-time codes. Institutions protect customers best by saying this often, in plain language and local languages, and by building pauses and warnings into risky payments.
SIM swap and account takeover
Account takeover is when a criminal gains control of someone's account and uses it as their own. On mobile money and mobile banking, a common route is the SIM swap:
- The fraudster gathers details about the victim, often through social engineering or leaked data.
- They persuade, trick or bribe someone to move the victim's phone number to a new SIM card they control.
- The victim's phone suddenly loses signal. Meanwhile the fraudster receives the one-time codes and calls meant for the victim, resets PINs and passwords, and empties the accounts.
Other routes include stolen or guessed PINs, malware on the phone, and one-time codes shared by victims who were tricked.
Useful defences:
- Check for a recent SIM swap before allowing high-risk actions, such as a PIN reset or a large transfer, and add a cooling-off period or extra checks when the SIM has just changed.
- Do not rely on text-message codes alone for high-value actions; combine them with other factors or checks.
- Strict identity checks for SIM replacement by mobile operators, with staff accountability.
- Watch for takeover patterns: a new device, a PIN reset and a new payee followed quickly by large transfers.
- Tell customers what to do if their phone loses signal unexpectedly: contact their operator and bank at once.
In Kenya, the Kenya Information and Communications Act and the Registration of Telecommunications Service Subscribers Regulations, 2025 made under it (which replaced the 2015 SIM card registration regulations) require operators to register SIM users and verify their details. This helps tracing, but a number moved to a criminal's SIM can still be used until the swap is detected.
Agents, insiders and money mules
Not all fraud comes from strangers.
Agent fraud. Mobile money and agent banking depend on networks of agents who handle cash. Risks include agents who deceive customers, for example with fake reversals or by keeping part of a deposit, and criminals who defraud agents, for example with fake confirmation messages or counterfeit notes. Controls include agent vetting and training, monitoring of agent transactions, mystery shopping, clear complaint channels for customers and fast action on agents with repeated complaints. In Kenya, payment service providers are overseen by the Central Bank of Kenya under the National Payment System Act, 2011. Under regulation 14 of the National Payment System Regulations, 2014, a provider is liable to its customers for what its agents do within the scope of the agency agreement, and the agreement cannot remove that liability.
Insider fraud. Employees and contractors with system access can misuse it: moving money, changing customer details, helping with SIM swaps or selling customer data. Controls include least-privilege access, segregation of duties, second-person approval for sensitive changes, logging and review of staff actions, and a culture where staff can report concerns safely.
Money mules. Stolen money has to go somewhere. Mules are people whose accounts are used to receive and pass on criminal funds, sometimes knowingly, often recruited with offers of easy money or fake jobs, and sometimes unaware. Signs include accounts receiving many payments from unrelated people and quickly sending them on or withdrawing them, newly opened accounts with sudden high activity, and several accounts linked by the same device, phone number or address.
Stopping mules matters twice: it cuts off the fraudsters' route for moving money, and it is part of an institution's anti-money laundering duties.
Protecting customers and responding
Good fraud control combines prevention, detection and response.
Prevention - Clear, repeated customer education about common scams and the rule that genuine providers never ask for PINs or codes. - Confirmation of the recipient's name before a payment is completed, so customers can spot a wrong payee. It is not proof that the payee is honest, since fraudsters often use accounts registered in real people's names. - Limits and friction for risky payments: first payments to new recipients, large amounts, or payments soon after a PIN reset or SIM change.
Detection - Monitoring of transactions and account behaviour for fraud patterns, in real time where possible, so payments can be held before money leaves.
Response - Take the first report well. A customer-service officer should record the facts at once: transaction reference, time, amount, receiving number or account, and how the customer was contacted. Escalate to the fraud team immediately, and do not promise that the money will be recovered. - A fast, well-publicised way to report fraud, available at all hours. Victims should contact their bank or mobile money provider immediately, on its official number, to request a hold while funds may still be in the receiving account. - Quick action to freeze receiving accounts and trace funds, working with other providers, because speed is what recovers money. - Fair treatment of victims, with clear decisions and explanations. - Reporting to the authorities. In Kenya, fraud and computer-related offences can be reported to the police and the Directorate of Criminal Investigations. The Computer Misuse and Cybercrimes Act, 2018 makes computer fraud (section 26), identity theft and impersonation (section 29) and phishing (section 30) criminal offences. Under the Proceeds of Crime and Anti-Money Laundering Act, 2009, banks, payment providers and other reporting institutions must report suspicious transactions to the Financial Reporting Centre.
Finally, learn from every case. Each fraud reveals a gap in prevention, detection or response, and fraudsters adapt quickly, so controls must too.
Ten questions
Answer all ten questions, then check your answers. You need 9 out of 10 to pass and receive a certificate. If you score less, you will see which answers were right and wrong, and then go through the course again before you retake the check. Your answers, progress and times are kept only in this browser.
Your answers
Your certificate of completion
Enter your name as you want it to appear, then save the certificate as a PDF. In the print window, choose Save as PDF. A certificate is issued once per completion of the course.
Saolix does not record who takes this course, so it cannot verify these certificates. The certificate confirms completion of a free self-paced course and is not an accredited qualification.
Sources
The official documents this course relies on. Laws and guidance change, so check the current version.
- Mobile payments statistics · Central Bank of Kenya
- Computer Misuse and Cybercrimes Act, 2018 (No. 5 of 2018) · Kenya Law
- National Payment System Act, 2011 (No. 39 of 2011) · Kenya Law
- National Payment System Regulations, 2014 · Central Bank of Kenya
- Kenya Information and Communications (Registration of Telecommunications Service Subscribers) Regulations, 2025 (L.N. 90 of 2025) · Kenya Law
- 2024 FinAccess Household Survey, key insights · FSD Kenya, Central Bank of Kenya and KNBS
- Fraud safety · Central Bank of Kenya
- Proceeds of Crime and Anti-Money Laundering Act, 2009 (No. 9 of 2009) · Kenya Law