Kenya

Staff training built for M-Pesa fraud, SIM-swap, and the Data Protection Act

Wanjiru in accounts gets an M-Pesa message: "Sorry, wrong number - please send my KES 5,000 back." Otieno gets a text claiming to be from KRA about an iTax penalty, with a link to "clear it now." Both are scams Kenyan teams see constantly. We build training around that reality and map it openly to the Data Protection Act and the Computer Misuse and Cybercrimes Act.

Illustration representing security awareness training for organizations in Kenya
Regulatory drivers

Two laws are pushing staff training up the priority list

Data Protection Act, 2019

Kenya's data protection law requires controllers and processors to implement appropriate technical and organizational security measures, overseen by the Office of the Data Protection Commissioner (ODPC). We treat staff training as a measure that supports this obligation, not as a quoted legal requirement with a fixed cadence.

Computer Misuse and Cybercrimes Act, No. 5 of 2018

Criminalizes unauthorized access, fraud, and cyber harassment offences. It is the legal basis for why M-Pesa fraud, SIM-swap, and phishing can be reported and prosecuted as crimes in Kenya, which is useful context for why staff should report attempts rather than quietly ignore them.

Kenya-specific modules

Fraud patterns taught as dedicated modules, not a generic deck

  • M-Pesa reversal scams - recognizing the "wrong number, please send it back" message and why staff should verify in the M-Pesa app before refunding anyone.
  • SIM-swap fraud - spotting a SIM swap in progress and protecting the mobile line tied to M-Pesa and banking.
  • Fake KRA iTax & Huduma messages - never clicking a link or paying a "clearance fee" from a text claiming to be KRA, Huduma, or NTSA.
  • Fake bank & M-Pesa "fraud department" calls - recognizing callers who pressure staff to read out a PIN or one-time code to "reverse" or "secure" a transaction.
  • Predatory loan-app scams - spotting fraudulent loan apps that harvest contacts, photos, and personal data before disbursing nothing.
See the full All-Staff Core track →

See the Kenya-specific modules in action

Book a free demo and we'll walk through the Data Protection Act-aligned training for your sector.

Frequently asked questions

Does Kenya's Data Protection Act require staff cybersecurity training?

The Data Protection Act, 2019 requires data controllers and processors to implement appropriate technical and organizational security measures, and the Office of the Data Protection Commissioner (ODPC) oversees compliance. We did not find a clause that sets an exact training frequency, so we describe training as supporting that obligation rather than quoting a specific cadence as a legal requirement.

What does the Computer Misuse and Cybercrimes Act cover?

The Computer Misuse and Cybercrimes Act, No. 5 of 2018 criminalizes unauthorized access, fraud, and cyber harassment offences in Kenya. It is the legal backdrop for why M-Pesa fraud, SIM-swap, and phishing are prosecutable crimes, not just policy violations - useful context for staff who need to understand why reporting matters.

What scams do Kenyan staff actually report?

The pattern we hear about most: an M-Pesa "wrong number, please send it back" message followed by a real refund sent to a fraudster, fake KRA iTax or Huduma messages asking someone to click a link or pay a "clearance fee," SIM-swap attempts used to intercept M-Pesa PINs and one-time codes, and calls impersonating a bank's fraud department.

Is this training only for banks and SACCOs?

No. We built sector pages for banks and SACCOs, M-Pesa agents and merchants, and fintechs, plus an All-Staff Core track that covers M-Pesa fraud, SIM-swap, and fake government-message scams for any Kenyan organization, regardless of sector.