Why Yusuf Omari - run ABSA Kenya Bank Remains Under Siege Over Leaked Client Data
An Absa credit manager has told the Mombasa High Court he received M-Pesa payments from a borrower's director, but denied any bribe or leak. He also said an internal investigation found no wrongdoing by him or other employees.

Banking runs on trust, and trust runs on secrecy. Absa Bank Kenya is now in court, and before regulators, over whether it kept that secrecy. Every allegation below is untested and the bank denies wrongdoing, but the legal exposure is already serious.
The case Transport firm New Mega Africa Ltd is suing Absa for Sh1.5 billion, alleging the bank mishandled its restructuring and leaked confidential information to third parties, costing it business on the Kenya-Uganda clinker route.
An Absa credit manager has told the Mombasa High Court he received M-Pesa payments from a borrower's director, but denied any bribe or leak. He also said an internal investigation found no wrongdoing by him or other employees.
Pressure has since moved beyond the courtroom. Senator Okiya Omtatah wrote to the CBK and the DCI on 17 September 2026, asking CBK to test Absa against the Banking Act, its consumer-protection rules and the Data Protection Act, and to refer the matter to the EACC and the Data Protection Commissioner.
A former senior officer alleges management stopped him from disciplining the officer over the alleged disclosure, warning that acknowledging the breach could amount to an admission of liability.
Why the exposure is structural
First, the duty of confidentiality is old and settled. Since Tournier v National Provincial Bank (1924), a bank owes its customer a duty of secrecy, qualified only by compulsion of law, public duty, the bank's own interest, or the customer's consent.
Kenya's Banking Act reinforces it. A credit officer's curiosity, or a third party's request, is not a qualified exception.
Second, the Data Protection Act, 2019 makes the bank a data controller, accountable for security safeguards. Article 31 of the Constitution gives every person a right to privacy, expressly covering information relating to their family or private affairs.
The Act also requires breach notification to the Data Protection Commissioner and, where there is a risk to rights, to the affected person. Section 65 gives a data subject a right to compensation.
Kenyan courts have awarded damages in data-protection cases, and a recent news report notes Ferdinand Omanyala was among Kenyans awarded millions for such breaches in 2025. Absa cannot treat this as a novel risk.
Third, vicarious liability. Even if the bank proves a rogue employee acted for personal gain, it must still show it had access controls, monitoring and audit trails robust enough to meet its statutory duty.
The credit manager's testimony that his access was limited to a corporate credit risk system, not account statements, cuts both ways. It suggests access controls exist. It also raises the question of how the information reached outsiders at all, if it did.
The cover-up problem
The deepest danger is not the original leak but the institutional response. The allegation is that management cautioned against admitting the breach to the customer or disciplining the officer, and that the customer was never told the findings.
If proven, that moves the case from negligence towards concealment. It engages the notification duty directly, undermines any defence of reasonable diligence, and invites regulators to ask what the bank's governance did with a red flag. A bank that treats acknowledgement as an admission has put its litigation posture ahead of its customer. A regulator will read that very differently from an isolated lapse.
Why the siege persists
Three reasons. The dispute is more than three years old and still live, with the bank fighting on several fronts, including enforcing its auction rights over the customer's property while the damages claim is pending. That sequencing looks like leverage rather than neutrality.
Parallel referrals to CBK, the DCI, the EACC and the Data Protection Commissioner mean no single ruling closes the file. And the evidential trail is documentary: M-Pesa records, WhatsApp chats and the bank's own investigation file. Documents, unlike memories, do not fade.
What Absa must do
Publish the scope and findings of its internal investigation to the regulators. Notify affected customers. Independently audit access logs. Separate its commercial recovery actions from its response on the data question.
Anything less will confirm the narrative that the bank protects itself before it protects its customers.
Kenya has a constitutional privacy right, a data protection statute and an active regulator. The question is whether a bank of Absa's standing will be held to them.
Filed underABSA, Kenya, Bank, Leaking, Confidential, Customer, Data, Consumer


