Evidence-Led Cyber Risk Analysis

Kenya Cyber Risk Case Studies

Real incidents. Real losses. Actionable security lessons.

Cyber incidents leave evidence. We examine documented cybercrime, financial fraud, system compromise, service disruption and regulatory failures affecting organisations in Kenya to understand what happened, what security questions they raise, and what should be tested before similar exposure becomes loss.

✓ Verified IncidentsGrounded in credible public sources
🔎 Technical AnalysisFacts separated from inference
◎ Actionable LessonsTurning incidents into security improvements

The Financial Impact Is Real

Official Central Bank of Kenya data shows that banking-sector cyber and digital fraud is a measurable financial risk — not simply a theoretical IT concern.

Source: Central Bank of Kenya, Financial Sector Stability Report 2024.

353
Fraud cases

recorded in the banking sector in 2024

KSh 1.963B
Exposed

to cyber and digital fraud in 2024

KSh 1.594B
Actual losses

recorded across the banking sector

KSh 810.7M
Mobile banking

actual losses recorded in 2024

Why Case Studies Matter

Cyber incidents are different. The lessons are transferable.

A useful case study goes beyond the headline. We separate verified facts from technical analysis, identify the control questions raised by the incident and translate those lessons into areas organisations can assess, test and improve.

🛡️

Based on real events

Regulators, government records, law-enforcement reporting, forensic case studies and credible public reporting form the evidence base.

🔎

Facts before assumptions

Where the public record does not establish a technical cause, we do not invent one. We identify what an organisation should test.

🧭

From incident to action

Every case is translated into practical areas for assessment, hardening, monitoring, governance and response.

🧪

Test the real exposure

The deeper question is whether weaknesses can be combined into an attack path that reaches critical systems, money or data.

Verified Case Register

Documented incidents. Important lessons.

The cases below span SACCO fraud, insider-enabled financial fraud, mobile-banking compromise, banking-sector losses, public-service disruption, regulatory enforcement and critical web-application attack activity.

01 ⌨
June 2026 • SACCO • Financial Systems

KSh 22.4M SACCO System Fraud Investigation

Public reporting on a 2026 investigation described an alleged scheme in which more than KSh 22.4 million was siphoned from a SACCO through its computerized financial systems. An ICT assistant was among the suspects arrested, and investigators described internal access combined with external collaborators.

What is established: this is an alleged fraud under investigation. The public record supports questions around internal access and system manipulation, but does not establish every technical control weakness.
Security lesson: legitimate access can still become a fraud path if privileges, transactions and administrator activity are insufficiently controlled or monitored.
What should an organisation test?
  • Privileged and administrative access pathways.
  • Role-based access and segregation of duties.
  • Transaction approval and exception controls.
  • Ability to create, alter or misuse accounts and beneficiaries.
  • Log integrity, alerting and anomalous user behaviour.
02 📱
2026 • Financial Institution • Mobile Banking

Mobile Banking Compromise — Project Tikonze

A PwC Kenya forensic case study describes a financial institution that began receiving reports of unauthorised customer transactions less than three weeks after launching a mobile-banking platform. Unknown accounts were discovered on mobile-banking servers and databases.

Forensic findings reported by PwC: the attack was traced to infrastructure associated with the institution's third-party SOC provider, with extensive abuse of credentials assigned to a specific SOC staff member, lateral movement, privilege escalation and more than four weeks of undetected access.
Security lesson: critical digital platforms should be tested against real attack paths before customer complaints become the first detection mechanism.
What should an organisation test?
  • Third-party credentials and remote-access pathways.
  • Privilege escalation and lateral movement.
  • Application, server and database access controls.
  • Detection of unknown or unauthorised accounts.
  • Pre-go-live penetration testing and post-remediation retesting.
03 🏦
2024 • Banking Sector • Digital Fraud

KSh 1.594B in Banking-Sector Cyber & Digital Fraud Losses

Central Bank of Kenya reporting records 353 banking-sector fraud cases across cyber and digital channels in 2024, with approximately KSh 1.963 billion exposed and KSh 1.594 billion in actual losses.

Mobile-banking fraud alone accounted for about KSh 810.7 million in actual losses, alongside losses linked to computer fraud, online banking, card fraud and identity theft.
Security lesson: cyber fraud is a measurable financial and operational risk that requires prevention, detection, response and recovery capabilities.
What should an organisation test?
  • Authentication and account-takeover resistance.
  • Transaction anomaly and velocity controls.
  • Identity, device and session monitoring.
  • Digital-channel application and API security.
  • Fraud detection and response workflows.
04 ⚠
July 2023 • Government • Availability

eCitizen Distributed Denial-of-Service Disruption

Kenya's eCitizen platform was intermittently unavailable for three consecutive days during a distributed denial-of-service attack in July 2023, affecting access to public digital services.

The official public position distinguished service disruption from data compromise: availability was affected, while government stated that protected information was not compromised.
Security lesson: an attacker does not need to steal data to cause business or public-service impact. Availability is part of cybersecurity.
What should an organisation test?
  • DDoS resilience and upstream protection.
  • Capacity, failover and service continuity.
  • Monitoring, alerting and incident escalation.
  • Communication and recovery procedures.
  • Critical-service dependency mapping.
05 🔐
2025/2026 • SACCO • Data Governance

Data Governance & Protection Enforcement — Capital SACCO

The Office of the Data Protection Commissioner opened a suo-motu investigation involving Capital SACCO and ultimately issued an Enforcement Notice after finding non-compliance with data-protection requirements.

This is a governance and compliance case rather than a hacking incident. It demonstrates that security risk also includes how personal data is collected, processed, evidenced and governed.
Security lesson: cybersecurity assurance must include data governance, accountability and evidence — not only technical controls.
What should an organisation test?
  • Personal-data inventory and classification.
  • Consent and lawful-processing evidence.
  • Access, retention and disclosure controls.
  • Data-protection governance and accountability.
  • Ability to demonstrate compliance through records and evidence.
06 ⌘
Jul–Sep 2023 • Kenya • Critical Infrastructure

106,603 Web-Application Attack Attempts

KE-CIRT reported 106,603 web-application attack attempts targeting critical-infrastructure service providers during the quarter, including attacks against authentication portals, databases and web servers.

Reported attack classes included remote code execution and broken authentication or session management — exactly the kinds of weaknesses that warrant deeper application testing.
Security lesson: internet-facing systems require more than periodic scanning; organisations need to validate exploitability and attack paths.
What should an organisation test?
  • Authentication and session management.
  • Remote code execution and injection paths.
  • Application-to-database trust relationships.
  • Web server and TLS configuration.
  • Periodic vulnerability assessment and penetration testing.
07 🧾
February 2026 • SACCO • Insider Fraud

KSh 16.013M SACCO Fraud — Primary DCI Case

The Directorate of Criminal Investigations reported the arrest of a former SACCO accountant over an alleged fraud that caused a total loss of KSh 16,013,166. DCI said the suspect allegedly authorised cheque transactions using members' accounts in collaboration with external accomplices.

Primary DCI findings: 58 fraudulent cheques were issued, cleared and deposited into accounts belonging to an alleged accomplice and other unsuspecting members. DCI also reported forged withdrawal slips and that the cheques were omitted from the cheque ledger, indicating an apparent attempt to conceal the activity.
Security lesson: fraud detection must correlate insider behaviour, transaction patterns, beneficiary relationships, approval activity and ledger exceptions rather than relying on transaction value alone.
What should an organisation test?
  • Employee transaction initiation and authorisation privileges.
  • Cheque issuance, clearance and member-account relationship anomalies.
  • Forged or abnormal withdrawal-document patterns.
  • Ledger-to-transaction reconciliation and missing-record exceptions.
  • Repeated use of member accounts as fund-routing conduits.
  • Behavioural and transaction-correlation rules for fraud detection.
Evidence note: Quest Technologies did not investigate the public incidents above unless explicitly stated otherwise. Facts are drawn from cited public sources. Allegations, arrests and investigations are described as such and are not presented as final findings of criminal liability. Where a source does not establish a specific technical cause, the page identifies security questions and control areas that organisations should assess rather than attributing unverified causes.
From Access to Impact

How incidents become losses

Serious cyber and fraud incidents often develop through a chain of small failures rather than a single dramatic weakness.

🔑

Access

Weakness, stolen credentials or legitimate access provides an entry point.

↔

Movement

Privileges are expanded or access moves toward more valuable systems.

🗄

Action

Financial, administrative or data actions are performed.

👁

Hidden Activity

Weak monitoring allows activity to continue undetected.

💰

Impact

Money, data, availability, trust or operations are compromised.

Scanning Finds Vulnerabilities. Penetration Testing Reveals Exposure.

Vulnerability assessment is valuable — but a list of weaknesses does not automatically show which ones can be chained together into a path to critical systems, sensitive data or financial transactions.

Vulnerability Scanning

  • Finds known weaknesses and CVEs
  • Identifies open ports and exposed services
  • Highlights configuration issues
  • Supports patch and remediation planning
  • Shows what might be vulnerable
VS

Penetration Testing

  • Attempts realistic attack paths
  • Validates whether weaknesses are exploitable
  • Tests privilege escalation and lateral movement
  • Attempts to reach critical assets safely
  • Demonstrates potential business impact
The important question is not simply how many vulnerabilities exist. It is whether an attacker can combine them into a viable path to your money, systems, operations or data.

What Attackers Target

The easiest route into an organisation may be technical, human, third-party or physical.

  • 👤Credentials & IdentityPhishing, credential theft, privilege abuse and weak authentication.
  • ⌨Applications & APIsVulnerabilities, logic flaws, weak authentication and exposed interfaces.
  • 🖧Networks & SystemsMisconfiguration, open services, poor segmentation and outdated components.
  • 🗃Data & TransactionsSensitive information, financial operations and transaction manipulation.
  • 👥People & ProcessesSocial engineering, weak approvals, insider risk and poor governance.
  • 🏢Physical EnvironmentUncontrolled access, exposed devices, network ports, server rooms and monitoring gaps.
From Finding to Improvement

Our Cyber Risk Assurance Approach

Security improves when organisations move beyond finding weaknesses and repeatedly validate whether exposure is actually reducing.

🔎

Assess

Understand the environment, assets and risks.

🛡

Validate

Test attack paths safely to identify real exposure.

📊

Prioritise

Focus effort on what matters most to the business.

⚙

Remediate

Fix weaknesses and strengthen controls.

✓

Retest

Verify fixes and confirm exposure has reduced.

👁

Monitor

Detect, respond and improve continuously.

Reduce risk. Strengthen resilience. Protect what matters.

Current Threat Watch — SACCOs, Financial Institutions & Government

✉

Credential Abuse

Phishing, stolen credentials and account takeover remain major attack paths.

🔗

Third-Party Access

Vendors and partners may introduce privileged or poorly governed access pathways.

☣

Ransomware

Targeted attacks can disrupt systems and put operations, data and recovery under pressure.

👤

Insider Threat

Legitimate access can be misused or compromised when monitoring and segregation are weak.

☁

Cloud & Configuration Risk

Exposed storage, weak permissions and misconfiguration can create unintended data exposure.

Could This Happen to Your Organisation?
Test the Assumption Before an Attacker Does.

Identify weaknesses. Validate real attack paths. Strengthen controls before an incident becomes your next case study.