Digital Forensics

Sim swap fraud in Kenya

Digital & Cyber Forensics · Kenya The Fraud That Happens Faster Than You Can Call Your Bank. A SIM swap doesn’t announce itself. It arrives as a dead signal bar, then a silence where your OTPs used to be. By the time most victims understand what happened, the forensic window is already closing. 106AEvidence Act admissibility standard CMCA 2018Identity theft & unauthorised access <30 daysBefore telco record quality degrades In short A SIM swap is proven with three independent records, not one: the telco’s porting log and cell-site data, the victim’s device forensics, and the mobile money or bank transaction trail. None of these live on the phone the victim is holding — which is why most victims believe the evidence is gone. It usually isn’t, if an examiner is instructed quickly. Why SIM Swap Is a Forensic Problem, Not Just a Fraud Problem Most fraud leaves a fingerprint on the device it happened on. A SIM swap doesn’t. The victim’s phone is often untouched — the compromise happens upstream, at the telco, when a fraudster convinces an agent or exploits a porting process to move the victim’s number onto a SIM they control. From that moment, every OTP, every banking alert, every M-Pesa confirmation goes to the attacker instead. This is precisely why SIM swap cases are misunderstood by victims and, often, by the legal teams instructed to recover their losses. The instinct is to examine the phone. The evidence, in fact, sits in three separate custody chains — the mobile network operator, the financial institution, and whatever secondary device or account the attacker touched — and a forensic examiner’s job is to reconstruct all three into one timeline that satisfies Section 106A of the Evidence Act (Cap. 80). “The victim didn’t lose their phone. They lost control of who their phone believed they were.” Anatomy of a SIM Swap: What Actually Happens, Minute by Minute Reconstructed Attack Sequence Six Stages, Usually Under an Hour This sequence is drawn from the typology of SIM swap matters examined across Kenyan recovery and criminal proceedings. It is the reconstruction an examiner builds after the fact — not a warning about method. Stage 1 Target Profiling The attacker gathers enough personal detail — often from a prior data leak or social engineering — to pass identity verification for a line swap. Evidence: none yet Stage 2 The Porting Request A swap or replacement SIM request is filed against the victim’s line, at an agent outlet or through a channel with weaker verification. Evidence: telco porting log, agent ID, timestamp Stage 3 Signal Loss The victim’s genuine SIM goes dark. This is usually the only signal the victim experiences directly — and it is frequently dismissed as a network fault. Evidence: victim’s own device log, network deregistration event Stage 4 Account Takeover OTPs and password reset links now route to the attacker’s SIM. Banking apps, M-Pesa, and email accounts are reset in sequence. Evidence: bank/telco OTP delivery logs, login IP and device fingerprints Stage 5 Extraction Funds move — typically through mobile money to a chain of intermediary accounts or agent tills designed to fragment the trail quickly. Evidence: M-Pesa/bank transaction records, agent till mapping Stage 6 Discovery The victim regains signal — often hours later — to a phone with no missed alerts and accounts already drained. This is where most cases begin. It should be Stage 1. How a Forensic Examiner Traces It Reconstruction works backward from Stage 6 to Stage 2 — each stage confirmed by an independent, third-party record rather than the victim’s own account of events. 01 Call Detail Record (CDR) Analysis Cross-references the moment the genuine SIM deregistered against the network against the moment the replacement SIM activated — establishing the precise swap window. 02 Porting & Agent Audit Trail Examines the identification documents, agent code, and outlet used for the swap request — frequently the weakest link and the basis for a negligence claim against the telco. 03 OTP & Login Fingerprinting Maps every OTP delivery, password reset, and login event to a device and IP address — distinguishing the victim’s genuine activity from the attacker’s. 04 Mobile Money & Bank Transaction Mapping Follows the extracted funds through agent tills and intermediary accounts, producing the structured financial timeline Kenyan courts expect in recovery proceedings. 05 Victim Device Verification Confirms the victim’s own device holds no evidence of compromise — closing off a common defence argument that the victim authorised the transactions themselves. 06 Unified Evidentiary Timeline All five records are merged into one Order 18-compliant report, with each of the three Section 106A conditions addressed against every record relied upon. Where This Sits in Kenyan Law Computer Misuse & Cybercrimes Act 2018: unauthorised access and identity theft provisions form the criminal basis for prosecuting the swap itself. Evidence Act (Cap. 80), ss. 106A–106C: each of the telco, banking, and mobile money records must independently satisfy the “regular use, functioning properly, ordinary course of activity” test before a court will rely on it. Data Protection Act 2019: governs how examiners lawfully obtain and process the personal data within telco and financial records during reconstruction. Illustrative Matter · Nairobi · Recovery Litigation KES 2.3M Moved in 41 Minutes — Traced to an Agent Outlet Swap A victim’s line went silent mid-afternoon; by the time signal returned, KES 2.3 million had moved from a bank account through four mobile money agents. UFC’s CDR analysis pinpointed the exact deregistration and re-registration window, and porting-log examination identified the outlet and agent code used for the swap — evidence the telco’s own verification process had failed at that specific point. Financial timeline and porting failure documented for recovery proceedings against the telco and receiving accounts. Frequently Asked Questions Can a SIM swap be proven after the money is already gone? Yes, in most cases. The evidence does not live on the victim’s phone — it lives with the telco (porting requests, agent ID, cell-site data) and the receiving financial trail. Forensic

Sim swap fraud in Kenya Read More »

Fake TikTok Accounts Targeting Kenyan Brands | How to Stop Them

Brand Protection · TikTok Fake TikTok Accounts Are Targeting Kenyan Brands — Here’s How to Get Them Removed A practical guide to spotting, evidencing, and reporting brand impersonation on TikTok, with the legal options available under Kenyan law. 📅 Updated June 2026 🕐 8 min read ✍️ Ultimate Forensic Consultants If your business has any presence on TikTok — or even if it doesn’t — there’s a real chance someone else is already pretending to be you on the platform. TikTok’s growth in Kenya has been fast enough that brand impersonation has outpaced most businesses’ ability to monitor for it, and the accounts doing the impersonating aren’t always obvious at a glance. Quick Answer To get a fake TikTok account impersonating your brand removed, report it in-app under “Pretending to be someone” for straightforward impersonation, or file TikTok’s dedicated trademark infringement form if your logo or registered mark is involved — this routes the case to TikTok’s IP review team rather than general moderation. Capture full screenshots of the profile, its videos, and any direct messages before submitting any report, since evidence often becomes inaccessible once a report is actioned. If customers were defrauded, the matter can also be reported to Kenya’s DCI Cybercrime Unit under Section 29 of the Computer Misuse and Cybercrimes Act, 2018. 📰 According to a public statement reported by Kenyans.co.ke in May 2025, the National Transport and Safety Authority had to warn Kenyans about a fake TikTok account using its name, which the authority itself described as a scheme to defraud followers — an account that had already gathered more than 8,600 followers before anyone formally flagged it. If a national government agency can be impersonated at that scale before detection, smaller businesses are at least as exposed, usually with far less capacity to respond quickly. Why TikTok Specifically Is a Growing Risk for Kenyan Brands TikTok occupies a different position than Facebook or Instagram in the brand-impersonation landscape, for a few reasons worth understanding before you build a response plan. First, the audience skews younger and faster-moving — content spreads through the algorithm rather than through a follower’s existing network, which means a fake account can reach thousands of people who have never seen your real brand before, with no way to compare. Second, the platform’s most common scam formats — fake giveaways, “instant earnings” offers, romance-style approaches, and bogus brand-deal messages — are specifically built around urgency and trust, which makes a convincing fake business account more dangerous per-follower than on other platforms. Third, TikTok Shop adds a commerce layer that Instagram and Facebook don’t have in the same way, meaning impersonation isn’t always just reputational — it can be a direct financial scam wearing your brand’s name. The Four TikTok Impersonation Patterns Showing Up Most in Kenya 01 Cloned Business Accounts A near-identical account using your logo, brand name, and stolen product or service photos — often messaging your actual followers directly to redirect them toward a scam offer or fraudulent payment request. 02 Fake Giveaway & “Instant Earnings” Videos Accounts using a recognisable brand name to promise unrealistic returns or free products in exchange for an upfront M-Pesa payment or personal details. 03 Counterfeit Listings on TikTok Shop Products listed using your brand name, packaging, or photos, sold by an account with no actual connection to your business. 04 Fake Verification & Partnership Offers Messages claiming to offer TikTok verification, brand partnerships, or paid collaborations — usually designed to harvest credentials or extract a “processing fee.” How to Actually Report a Fake Account on TikTok TikTok’s in-app reporting tool splits impersonation reports into three categories, and choosing the right one matters for how fast — and how seriously — your report gets handled. Pretending to be someone Use when the account is directly impersonating your brand or a specific person — especially if you can reference your own verified or established account as the real one. Fraud & scams Use when the account is actively collecting payments or running a scam, whether or not it involves your specific trademark. IP violation Use for cases involving your logo, registered trademark, or copyrighted content — this routes the report to TikTok’s dedicated IP review team rather than general community moderation. For straightforward impersonation and fraud cases, selecting the right category and submitting is usually enough to get a review started. Trademark and copyright cases take longer, since TikTok routes them through separate dedicated forms that require more detailed proof of ownership — but they also tend to carry more weight once submitted correctly, because they’re reviewed against documented rights rather than general community guidelines. For counterfeit products specifically sold through TikTok Shop, the report path is different again: it runs through the platform’s IP Protection Centre rather than the standard account-report flow, and brand owners can file directly if they hold a registered trademark. What to Do Before You Report a Fake TikTok Account — Not After The single most common mistake brands make is reporting a fake account the moment they find it, without capturing evidence first. Once TikTok actions a report — whether by removing the account or simply restricting it — the content, message history, and follower-facing claims often become unavailable. If the case later needs to support a police report, a civil claim, or even a stronger escalation within TikTok itself, that evidence is gone. Before submitting any report, capture: A full screenshot of the profile page, including the bio, profile photo, and follower count Screenshots of at least two or three posted videos showing the misuse of your branding or claims The exact account handle and profile URL Any direct messages sent to followers or customers, if accessible The date and time you observed the account Where TikTok Impersonation Becomes a Legal Matter, Not Just a Platform Issue A successful platform takedown solves the immediate visibility problem. It does not, on its own, address what happens if customers were actually defrauded, or if the impersonation involved unauthorised

Fake TikTok Accounts Targeting Kenyan Brands | How to Stop Them Read More »

whatsapp-message-defamation-kenya

Is a WhatsApp Message Defamation in Kenya? What the Courts Have Ruled WhatsApp groups have become Kenya’s most common battleground for disputes — estate management committees, school parent groups, family groups, professional networks, and workplace chats. When a disagreement turns into an accusation, an insult, or a damaging claim sent to a group of people, the question that follows is almost always the same: can I sue for that? Quick answer: Yes. A defamatory statement sent in a WhatsApp group in Kenya is treated as “published” for the purposes of defamation law the moment it is communicated to a third party — and a WhatsApp group, by definition, consists of multiple third parties. Kenyan courts have awarded substantial damages in WhatsApp-related defamation cases, including a KES 2.5 million award in a 2024 Nakuru estate dispute and damages in the KES 1.5–2.5 million range in other group-chat matters. The size of the group does not need to be large — Kenyan courts have made awards based on statements sent to groups of fewer than 100 members. If you have been defamed in a WhatsApp group, the same legal framework covered in our guide on how to sue for online defamation in Kenya applies in full. The Legal Starting Point: Publication To succeed in a defamation claim in Kenya, you must prove five elements: that the statement was published to a third party, that it referred to you, that it was false, that it was defamatory in nature, and that it caused harm to your reputation. Of these five, “publication” is the one that people most often assume creates a problem for WhatsApp cases — and it doesn’t. Publication simply means the statement was communicated to someone other than you and the person who made it. Kenyan courts have repeatedly confirmed that publication on the internet — including on social media platforms and group chats — satisfies this requirement just as much as publication in a newspaper. The Court of Appeal’s foundational test for what makes a statement defamatory, set out in SMW v ZWM [2015] eKLR, defines a defamatory statement as one that tends to lower a person in the estimation of right-thinking members of society generally, or exposes them to public hatred, contempt, or ridicule, or causes them to be shunned or avoided. This test applies regardless of the medium — a WhatsApp message that meets this definition, and that has been sent to even a small group, is defamatory in exactly the same legal sense as a newspaper article that does. The practical reality of WhatsApp groups makes the publication question almost academic in most cases. A typical estate, school, church, or professional WhatsApp group has dozens or hundreds of members. The moment a defamatory message is sent to that group, it has been published to every member who reads it — each one a third party for legal purposes. What Kenyan Courts Have Actually Decided This is not a theoretical question. Kenyan courts have heard, and decided, multiple WhatsApp defamation cases in recent years — and the pattern is clear: WhatsApp group statements are treated with the same seriousness as any other published defamatory content. The Nakuru Estate WhatsApp Case (2024) In November 2024, Justice Samuel Muchochi ordered Sarah Rosborg, an officer of a charity organisation, to pay Anne Marie Tipper general damages of KES 2.5 million over a statement published concerning donor finances in their estate’s WhatsApp group. The court found the publication defamatory and awarded substantial damages — confirming that statements made in a residential estate’s WhatsApp group, even one limited to local residents, are treated by the courts as a serious publication capable of causing significant reputational harm. The Greenpark Cluster WhatsApp Case In a related estate dispute, a defendant published a statement in the “Greenpark Cluster Three” WhatsApp group — a platform with 73 members — commenting on an ongoing dispute regarding children’s welfare in the estate. The defendant argued he was justified in commenting on a matter affecting the estate and that his words were not motivated by malice. The court nonetheless found the statement caused a debate among group members and resulted in one individual being removed from the group altogether — and found the plaintiff entitled to damages for defamation. This case is particularly instructive because the defendant’s defence — that he was simply participating in a legitimate community discussion, without malicious intent — did not succeed. Believing your statement is a fair contribution to a group discussion does not protect you if the statement is, in fact, false and defamatory. The Broader Pattern: Social Media Generally Beyond WhatsApp specifically, Kenyan courts have consistently held that publication on the internet constitutes publication for defamation purposes — applying this principle to Facebook posts, X (Twitter) posts, blog articles, and group chats alike. Courts have explicitly recognised that because social media allows information to spread rapidly, the extent of publication — how far and how fast a statement travelled — is a key factor in assessing the resulting damages. A statement that triggers a heated debate, gets screenshotted and forwarded beyond the original group, or results in someone being ostracised from their community, is treated as having caused exactly the kind of reputational harm that the law is designed to compensate. “But I Was Just Sharing What Someone Told Me” One of the most common misconceptions about WhatsApp defamation is the belief that forwarding or repeating someone else’s claim is somehow safer than originating it. It is not. If you repost or forward a defamatory statement, you become a publisher of it too — and can be held liable in the same way as the original author. Kenyan legal commentary has been explicit on this point: a third party who reposts a defamatory tweet or message is republishing the defamatory statement and may also be liable if a defamation claim is brought. This matters enormously in the WhatsApp context, where forwarding messages between groups — often with a caption like “see what’s

whatsapp-message-defamation-kenya Read More »