Sim swap fraud in Kenya
Digital & Cyber Forensics · Kenya The Fraud That Happens Faster Than You Can Call Your Bank. A SIM swap doesn’t announce itself. It arrives as a dead signal bar, then a silence where your OTPs used to be. By the time most victims understand what happened, the forensic window is already closing. 106AEvidence Act admissibility standard CMCA 2018Identity theft & unauthorised access <30 daysBefore telco record quality degrades In short A SIM swap is proven with three independent records, not one: the telco’s porting log and cell-site data, the victim’s device forensics, and the mobile money or bank transaction trail. None of these live on the phone the victim is holding — which is why most victims believe the evidence is gone. It usually isn’t, if an examiner is instructed quickly. Why SIM Swap Is a Forensic Problem, Not Just a Fraud Problem Most fraud leaves a fingerprint on the device it happened on. A SIM swap doesn’t. The victim’s phone is often untouched — the compromise happens upstream, at the telco, when a fraudster convinces an agent or exploits a porting process to move the victim’s number onto a SIM they control. From that moment, every OTP, every banking alert, every M-Pesa confirmation goes to the attacker instead. This is precisely why SIM swap cases are misunderstood by victims and, often, by the legal teams instructed to recover their losses. The instinct is to examine the phone. The evidence, in fact, sits in three separate custody chains — the mobile network operator, the financial institution, and whatever secondary device or account the attacker touched — and a forensic examiner’s job is to reconstruct all three into one timeline that satisfies Section 106A of the Evidence Act (Cap. 80). “The victim didn’t lose their phone. They lost control of who their phone believed they were.” Anatomy of a SIM Swap: What Actually Happens, Minute by Minute Reconstructed Attack Sequence Six Stages, Usually Under an Hour This sequence is drawn from the typology of SIM swap matters examined across Kenyan recovery and criminal proceedings. It is the reconstruction an examiner builds after the fact — not a warning about method. Stage 1 Target Profiling The attacker gathers enough personal detail — often from a prior data leak or social engineering — to pass identity verification for a line swap. Evidence: none yet Stage 2 The Porting Request A swap or replacement SIM request is filed against the victim’s line, at an agent outlet or through a channel with weaker verification. Evidence: telco porting log, agent ID, timestamp Stage 3 Signal Loss The victim’s genuine SIM goes dark. This is usually the only signal the victim experiences directly — and it is frequently dismissed as a network fault. Evidence: victim’s own device log, network deregistration event Stage 4 Account Takeover OTPs and password reset links now route to the attacker’s SIM. Banking apps, M-Pesa, and email accounts are reset in sequence. Evidence: bank/telco OTP delivery logs, login IP and device fingerprints Stage 5 Extraction Funds move — typically through mobile money to a chain of intermediary accounts or agent tills designed to fragment the trail quickly. Evidence: M-Pesa/bank transaction records, agent till mapping Stage 6 Discovery The victim regains signal — often hours later — to a phone with no missed alerts and accounts already drained. This is where most cases begin. It should be Stage 1. How a Forensic Examiner Traces It Reconstruction works backward from Stage 6 to Stage 2 — each stage confirmed by an independent, third-party record rather than the victim’s own account of events. 01 Call Detail Record (CDR) Analysis Cross-references the moment the genuine SIM deregistered against the network against the moment the replacement SIM activated — establishing the precise swap window. 02 Porting & Agent Audit Trail Examines the identification documents, agent code, and outlet used for the swap request — frequently the weakest link and the basis for a negligence claim against the telco. 03 OTP & Login Fingerprinting Maps every OTP delivery, password reset, and login event to a device and IP address — distinguishing the victim’s genuine activity from the attacker’s. 04 Mobile Money & Bank Transaction Mapping Follows the extracted funds through agent tills and intermediary accounts, producing the structured financial timeline Kenyan courts expect in recovery proceedings. 05 Victim Device Verification Confirms the victim’s own device holds no evidence of compromise — closing off a common defence argument that the victim authorised the transactions themselves. 06 Unified Evidentiary Timeline All five records are merged into one Order 18-compliant report, with each of the three Section 106A conditions addressed against every record relied upon. Where This Sits in Kenyan Law Computer Misuse & Cybercrimes Act 2018: unauthorised access and identity theft provisions form the criminal basis for prosecuting the swap itself. Evidence Act (Cap. 80), ss. 106A–106C: each of the telco, banking, and mobile money records must independently satisfy the “regular use, functioning properly, ordinary course of activity” test before a court will rely on it. Data Protection Act 2019: governs how examiners lawfully obtain and process the personal data within telco and financial records during reconstruction. Illustrative Matter · Nairobi · Recovery Litigation KES 2.3M Moved in 41 Minutes — Traced to an Agent Outlet Swap A victim’s line went silent mid-afternoon; by the time signal returned, KES 2.3 million had moved from a bank account through four mobile money agents. UFC’s CDR analysis pinpointed the exact deregistration and re-registration window, and porting-log examination identified the outlet and agent code used for the swap — evidence the telco’s own verification process had failed at that specific point. Financial timeline and porting failure documented for recovery proceedings against the telco and receiving accounts. Frequently Asked Questions Can a SIM swap be proven after the money is already gone? Yes, in most cases. The evidence does not live on the victim’s phone — it lives with the telco (porting requests, agent ID, cell-site data) and the receiving financial trail. Forensic