Staff training built for M-Pesa fraud, SIM-swap, and the Data Protection Act
Wanjiru in accounts gets an M-Pesa message: "Sorry, wrong number - please send my KES 5,000 back." Otieno gets a text claiming to be from KRA about an iTax penalty, with a link to "clear it now." Both are scams Kenyan teams see constantly. We build training around that reality and map it openly to the Data Protection Act and the Computer Misuse and Cybercrimes Act.

Two laws are pushing staff training up the priority list
Data Protection Act, 2019
Kenya's data protection law requires controllers and processors to implement appropriate technical and organizational security measures, overseen by the Office of the Data Protection Commissioner (ODPC). We treat staff training as a measure that supports this obligation, not as a quoted legal requirement with a fixed cadence.
Computer Misuse and Cybercrimes Act, No. 5 of 2018
Criminalizes unauthorized access, fraud, and cyber harassment offences. It is the legal basis for why M-Pesa fraud, SIM-swap, and phishing can be reported and prosecuted as crimes in Kenya, which is useful context for why staff should report attempts rather than quietly ignore them.
Training mapped to your sector and the fraud it actually sees
Banks & SACCOs
Commercial banks and savings and credit co-operatives handling member funds and KYC data under CBK and SASRA oversight.
View training →M-Pesa Agents & Merchants
M-Pesa agents, till operators, and merchants who field the "wrong number, send it back" call multiple times a week.
View training →Fintechs
Digital lenders, payment processors, and licensed fintechs handling customer financial data and app-based onboarding.
View training →Fraud patterns taught as dedicated modules, not a generic deck
- M-Pesa reversal scams - recognizing the "wrong number, please send it back" message and why staff should verify in the M-Pesa app before refunding anyone.
- SIM-swap fraud - spotting a SIM swap in progress and protecting the mobile line tied to M-Pesa and banking.
- Fake KRA iTax & Huduma messages - never clicking a link or paying a "clearance fee" from a text claiming to be KRA, Huduma, or NTSA.
- Fake bank & M-Pesa "fraud department" calls - recognizing callers who pressure staff to read out a PIN or one-time code to "reverse" or "secure" a transaction.
- Predatory loan-app scams - spotting fraudulent loan apps that harvest contacts, photos, and personal data before disbursing nothing.
Frequently asked questions
Does Kenya's Data Protection Act require staff cybersecurity training?
The Data Protection Act, 2019 requires data controllers and processors to implement appropriate technical and organizational security measures, and the Office of the Data Protection Commissioner (ODPC) oversees compliance. We did not find a clause that sets an exact training frequency, so we describe training as supporting that obligation rather than quoting a specific cadence as a legal requirement.
What does the Computer Misuse and Cybercrimes Act cover?
The Computer Misuse and Cybercrimes Act, No. 5 of 2018 criminalizes unauthorized access, fraud, and cyber harassment offences in Kenya. It is the legal backdrop for why M-Pesa fraud, SIM-swap, and phishing are prosecutable crimes, not just policy violations - useful context for staff who need to understand why reporting matters.
What scams do Kenyan staff actually report?
The pattern we hear about most: an M-Pesa "wrong number, please send it back" message followed by a real refund sent to a fraudster, fake KRA iTax or Huduma messages asking someone to click a link or pay a "clearance fee," SIM-swap attempts used to intercept M-Pesa PINs and one-time codes, and calls impersonating a bank's fraud department.
Is this training only for banks and SACCOs?
No. We built sector pages for banks and SACCOs, M-Pesa agents and merchants, and fintechs, plus an All-Staff Core track that covers M-Pesa fraud, SIM-swap, and fake government-message scams for any Kenyan organization, regardless of sector.