The Fraud That Happens Faster Than You Can Call Your Bank.
A SIM swap doesn’t announce itself. It arrives as a dead signal bar, then a silence where your OTPs used to be. By the time most victims understand what happened, the forensic window is already closing.
A SIM swap is proven with three independent records, not one: the telco’s porting log and cell-site data, the victim’s device forensics, and the mobile money or bank transaction trail. None of these live on the phone the victim is holding — which is why most victims believe the evidence is gone. It usually isn’t, if an examiner is instructed quickly.
Why SIM Swap Is a Forensic Problem, Not Just a Fraud Problem
Most fraud leaves a fingerprint on the device it happened on. A SIM swap doesn’t. The victim’s phone is often untouched — the compromise happens upstream, at the telco, when a fraudster convinces an agent or exploits a porting process to move the victim’s number onto a SIM they control. From that moment, every OTP, every banking alert, every M-Pesa confirmation goes to the attacker instead.
This is precisely why SIM swap cases are misunderstood by victims and, often, by the legal teams instructed to recover their losses. The instinct is to examine the phone. The evidence, in fact, sits in three separate custody chains — the mobile network operator, the financial institution, and whatever secondary device or account the attacker touched — and a forensic examiner’s job is to reconstruct all three into one timeline that satisfies Section 106A of the Evidence Act (Cap. 80).
Anatomy of a SIM Swap: What Actually Happens, Minute by Minute
Six Stages, Usually Under an Hour
This sequence is drawn from the typology of SIM swap matters examined across Kenyan recovery and criminal proceedings. It is the reconstruction an examiner builds after the fact — not a warning about method.
Target Profiling
The attacker gathers enough personal detail — often from a prior data leak or social engineering — to pass identity verification for a line swap.
Evidence: none yetThe Porting Request
A swap or replacement SIM request is filed against the victim’s line, at an agent outlet or through a channel with weaker verification.
Evidence: telco porting log, agent ID, timestampSignal Loss
The victim’s genuine SIM goes dark. This is usually the only signal the victim experiences directly — and it is frequently dismissed as a network fault.
Evidence: victim’s own device log, network deregistration eventAccount Takeover
OTPs and password reset links now route to the attacker’s SIM. Banking apps, M-Pesa, and email accounts are reset in sequence.
Evidence: bank/telco OTP delivery logs, login IP and device fingerprintsExtraction
Funds move — typically through mobile money to a chain of intermediary accounts or agent tills designed to fragment the trail quickly.
Evidence: M-Pesa/bank transaction records, agent till mappingDiscovery
The victim regains signal — often hours later — to a phone with no missed alerts and accounts already drained.
This is where most cases begin. It should be Stage 1.How a Forensic Examiner Traces It
Reconstruction works backward from Stage 6 to Stage 2 — each stage confirmed by an independent, third-party record rather than the victim’s own account of events.
Call Detail Record (CDR) Analysis
Cross-references the moment the genuine SIM deregistered against the network against the moment the replacement SIM activated — establishing the precise swap window.
Porting & Agent Audit Trail
Examines the identification documents, agent code, and outlet used for the swap request — frequently the weakest link and the basis for a negligence claim against the telco.
OTP & Login Fingerprinting
Maps every OTP delivery, password reset, and login event to a device and IP address — distinguishing the victim’s genuine activity from the attacker’s.
Mobile Money & Bank Transaction Mapping
Follows the extracted funds through agent tills and intermediary accounts, producing the structured financial timeline Kenyan courts expect in recovery proceedings.
Victim Device Verification
Confirms the victim’s own device holds no evidence of compromise — closing off a common defence argument that the victim authorised the transactions themselves.
Unified Evidentiary Timeline
All five records are merged into one Order 18-compliant report, with each of the three Section 106A conditions addressed against every record relied upon.
Where This Sits in Kenyan Law
- Computer Misuse & Cybercrimes Act 2018: unauthorised access and identity theft provisions form the criminal basis for prosecuting the swap itself.
- Evidence Act (Cap. 80), ss. 106A–106C: each of the telco, banking, and mobile money records must independently satisfy the “regular use, functioning properly, ordinary course of activity” test before a court will rely on it.
- Data Protection Act 2019: governs how examiners lawfully obtain and process the personal data within telco and financial records during reconstruction.
KES 2.3M Moved in 41 Minutes — Traced to an Agent Outlet Swap
A victim’s line went silent mid-afternoon; by the time signal returned, KES 2.3 million had moved from a bank account through four mobile money agents. UFC’s CDR analysis pinpointed the exact deregistration and re-registration window, and porting-log examination identified the outlet and agent code used for the swap — evidence the telco’s own verification process had failed at that specific point.
Frequently Asked Questions
Can a SIM swap be proven after the money is already gone?
Yes, in most cases. The evidence does not live on the victim’s phone — it lives with the telco (porting requests, agent ID, cell-site data) and the receiving financial trail. Forensic examiners reconstruct the swap from these third-party records even when the victim’s device shows nothing unusual.
Whose fault is a SIM swap under Kenyan law — the victim, the telco, or the bank?
It depends on where the forensic evidence places the failure. If the porting request was improperly verified, liability can shift toward the telecommunications provider. If OTPs were phished from the victim, the picture changes. Forensic reconstruction of the full timeline is what determines which party’s negligence enabled the fraud — this is usually the central question in recovery litigation.
How quickly must a victim act for forensic evidence to still exist?
Telco call detail records and porting logs are retained on finite cycles, and mobile money agent-till records get harder to trace as funds move through further transactions. Evidence quality drops fast after 30 days and continues to degrade. Instructing an examiner within days of discovery materially improves recoverability.
Does UFC deal directly with Safaricom or other telcos to obtain SIM swap records?
UFC does not compel telco disclosure directly — that requires a court order or a formal law enforcement request, which we advise your legal team on securing. Once records are obtained, UFC’s role is the forensic reconstruction: correlating CDRs, porting timestamps, device data and mobile money records into a single, court-ready evidentiary timeline.
Every Hour Costs You Evidence.
If you suspect a SIM swap, the telco and financial records that prove it are already ageing. Free, confidential case assessment — response within 4 hours.