Payment providers such as M-Pesa and Airtel Money will immediately have to disclose cyber incidents such as mobile money fraud and hacking to the sector regulator under proposed rules seeking stronger safeguards for customers’ cash.
The Treasury and the Central Bank of Kenya (CBK) regulatory proposals require payment service providers (PSPs) and payment system operators to notify the regulator of any cyber breach that affects their operations.
This gives authorities early warning of attacks that could disrupt financial services and threaten the security of Kenyans’ cash, as the country grapples with rising cyber threats with the adoption of mobile banking.
Payment providers, which fail to report material incidents could face fines of up to Sh1 million or risk having their permits revoked. “A payment service provider or a payment system operator that fails or refuses to comply, or gives false information relating to the material event, shall be liable to administrative enforcement action by the Central Bank,” the proposals state.
Official data show that half of the Sh1.59 billion that was stolen from banks by hackers in 2024 was through mobile banking.
“A payment service provider or payment system operator shall notify the Central Bank about any material event that significantly affects its business and operations immediately after the material event occurs,” says National Payment System Bill, 2026.
Payment service providers are firms that handle customer-facing transactions, such as M-Pesa and Airtel Money. Payment system operators own the underlying infrastructure for settling funds between financial institutions and include firms such as Pesalink.
The proposed rule defines a material event as a significant data breach or cybersecurity incident, a prolonged or systemic service outage affecting payment processing or settlement, and the loss, unauthorised access to or misappropriation of customer funds.
Kenya has seen rising cyber threats such as hacks, mobile and SIM-swap fraud, and high-volume strikes targeting telecommunication operators and public portals.
“The rapid growth and digitalisation of Kenya’s payment ecosystem have heightened exposure to cyber threats, financial crime, operational disruptions, and systemic risks, which affect consumer confidence and financial stability,” the CBK and Treasury say.
Kenyans lost $3.8 million (Sh492.3 million) in cash and cryptocurrency after cybercriminals hijacked victims’ mobile phone numbers through SIM-swap fraud in 2025, according to the International Criminal Police Organisation (Interpol).
Interpol said incidents in which scammers trick mobile network operators into transferring phone numbers to new SIM cards they control rose 327 percent in Kenya during the year.
More than 123,000 fraudulent SIM cards were issued, enabling criminals to hijack victims’ phone numbers and steal money from mobile wallets.
Kenya pioneered financial inclusion in the region through its early adoption of a mobile money system that enables people to transfer cash and make payments on mobile phones with or without a bank account.
But this has become a hackers’ paradise. Central Bank data shows that mobile banking was the hardest-hit channel by cyber fraud in 2024, with criminals siphoning Sh810.68 million, up from Sh182.41 million in 2023.
The thefts often happen on Friday and Saturday nights, with millennials — individuals born between 1981 and 1996 — being the most affected.
The wider digital economy is also facing a sharp increase in cyberattacks. The Communications Authority of Kenya (CA) recorded 11.1 billion cyber-threats in the year to June 2026, a 29 percent increase from 8.6 billion a year earlier.
The current National Payment System Act was enacted in 2011 and is silent on cybersecurity. It does not require payment providers to immediately report such breaches. The Treasury and CBK reckon that the law is no longer fully aligned with the pace of technological change in recent years.
“This creates regulatory gaps that hinder innovation while exposing the financial system to risks such as fraud, cybercrime, money laundering, and operational inefficiencies,” the apex bank and the regulator say.
The proposed law seeks to strengthen cybersecurity and technology risk management through enhanced incident reporting, threat intelligence, security testing, third-party risk management and stronger supervisory arrangements.
Authorities also point to growing interconnection between banks, payment service providers, fintechs, payment systems and third-party technology providers as a source of new risks.
“Rapid digitisation, increasing reliance on technology and growing interconnection between banks, PSPs, fintechs, payment systems and third-party technology providers, expose the payment ecosystem to cyber threats, fraud, operational disruption, data compromise and risks associated with emerging technologies and new business models,” the proposals say.
Other markets which have adopted similar measures globally include the European Union, where payment service providers are required to report major operational or security incidents within four hours of classification, or within a maximum of 24 hours after becoming aware of an incident.
Thailand also requires payment providers to disclose cybersecurity incidents and data breaches under a framework overseen by the Bank of Thailand, the Personal Data Protection Committee and national cybersecurity authorities.