Independent · Self-funded · Non-political · Since 2010

HomeAbout UsNewsResourcesTraining

Fraud

I & M Bank and Safaricom in the dock: Whitelisted, yet swapped: How a Nairobi firm allegedly lost Sh11 million overnight

Mara North Holdings Limited says it lost millions in a SIM-swap fraud. Now it is demanding answers from Safaricom and I&M Bank.

I & M Bank in Nairobi: A firm is blaming the bank and Safaricom for loss of Sh11M through a SIM swap
I & M Bank in Nairobi: A firm is blaming the bank and Safaricom for loss of Sh11M through a SIM swap

A company says fraudsters cloned its manager's SIM while he held the phone, then drained seven bank accounts. Its lawyers want answers in 14 days. Mara North Holdings Limited says it lost millions in a SIM-swap fraud. Now it is demanding answers from Safaricom and I&M Bank. The claim is set out in two demand letters dated 16 September 2026. They were written by Oyomba Mosota & Wamwea Advocates, and signed by Collins Oyomba.

The lawyers act for Mara North and its General Manager, Justin Philip Valentine. According to the letters, the trouble began on or about 14 and 15 April 2026. Mr Valentine's Safaricom line, 071714XXXX, was allegedly swapped without authority.

That line ran the firm's internet banking. It received the one-time passwords that authorised transactions at I&M Bank. The letters make a striking claim. The SIM was allegedly "whitelisted" in Safaricom's system.

Mr Valentine was allegedly holding and using his phone at the time. The swap allegedly happened anyway. Whoever held the new SIM then allegedly entered the bank's platform. The letters say they withdrew Sh11,828,656 from seven accounts, two in dollars and five in shillings.

The client was a customer of over 15 years, at I&M's Langata Link branch. There is an unexplained gap in the figures. The letter headings cite a loss of Sh11,159,656. The bodies cite Sh11,828,656 withdrawn. That is a difference of Sh669,000.

The letters do not explain it. The lawyers allege both firms owed a duty of care and breached it. They say the money went to three mobile numbers, 011799XXXX, 074063XXXX and 076960XXXX, as confirmed by I&M statements. The holders of those numbers are not named, and no wrongdoing by them is stated beyond that they received funds. The firm has hired PKF Digital Technology Solutions (PKF dts) for a forensic audit. Its director, Hezekiah Ndungu, wrote detailed information requests dated 4 September.

From Safaricom, PKF wants 15 items. These include the SIM's full record, who processed the swap and where, the ID presented, cell-tower logs, SMS logs, and any audit trail of how the whitelist was bypassed.

From I&M, PKF wants 16 items. These include two years of platform login logs, transaction records, fraud-alert logs, and multi-factor authentication settings. Each demand carries a 14-day deadline. That window lapses around 30 September. The lawyers cite significant public interest. They say the clients remain open to an amicable settlement. Both letters were copied to the Directorate of Criminal Investigations' Banking Fraud Investigations Unit on Kiambu Road, and to the Consumer Federation of Kenya. These are allegations. Liability has not been determined by any court. Safaricom's and I&M Bank's responses to the letters were not available, and this newspaper has not seen any reply from either. What the case raises The whitelisting claim is the sharpest question. Safaricom's 100100# self-whitelist is meant to lock a line so it can only be replaced at a Safaricom shop or care desk with ID, not by an agent.

If a whitelisted line was still swapped while its owner used it, either the control failed or someone inside bypassed it. That is why PKF is hunting for an audit trail and an agent's identity. The bank side raises another. Kenyan lenders lean heavily on SMS one-time passwords.

When seven accounts in two currencies are drained over two days to three mobile numbers, anomaly-detection systems should fire. PKF's requests probe exactly that: did any alert trigger, and did anyone act? The scale is documented.

INTERPOL's African Cyberthreat Assessment Report 2026 found SIM-swap fraud in Kenya surged 327 per cent in 2025, with more than 123,000 fraudulent SIM cards and an estimated Sh491.6 million drained.

Central Bank of Kenya data show mobile-banking fraud losses jumped 344 per cent, from Sh182.41 million in 2023 to Sh810.68 million in 2024, as total bank fraud losses hit Sh1.6 billion. The law is shifting toward victims. On 18 June 2026 at Machakos, Justice Asenath Ongeri held Safaricom and Diamond Trust Bank jointly liable for Mercy Wairimu Kariuki's Sh4,418,601 SIM-swap loss, splitting it 60:40.

She ruled "a bank cannot hide behind a customer's PIN" when transactions are "so glaringly out of the ordinary that a reasonable banker would have been put on inquiry." Both firms owed concurrent, independent duties of care. Kenya has criminalised unauthorised SIM swaps under a 2024 amendment to the Computer Misuse and Cybercrimes Act, assented to in October 2025.

The Data Protection Act 2019 grants data-access rights, which PKF's requests effectively invoke. Article 46 of the Constitution guarantees consumer rights. Abroad, regulators are retreating from SMS codes, and Britain made scam reimbursement mandatory on 7 October 2024, capped at £85,000.

What to watch The 14-day clock runs out around 30 September. If it lapses without agreement, expect a lawsuit or complaints to the Communications Authority, the Central Bank and the data commissioner. The DCI is already copied.

For businesses, the lesson is blunt. Do not rest OTPs on a single SIM. Whitelist lines. Demand stronger authentication than a texted code.

COFEK will be keen to join the impending legal tussle

Filed underI & M Bank, Safaricom, Mara, Holdings, Whitelisting, Fraud, COFEK

File a complaint