Digital & Cyber Forensics · Kenya

The Fraud That Happens Faster Than You Can Call Your Bank.

A SIM swap doesn’t announce itself. It arrives as a dead signal bar, then a silence where your OTPs used to be. By the time most victims understand what happened, the forensic window is already closing.

106AEvidence Act admissibility standard
CMCA 2018Identity theft & unauthorised access
<30 daysBefore telco record quality degrades
In short

A SIM swap is proven with three independent records, not one: the telco’s porting log and cell-site data, the victim’s device forensics, and the mobile money or bank transaction trail. None of these live on the phone the victim is holding — which is why most victims believe the evidence is gone. It usually isn’t, if an examiner is instructed quickly.

Why SIM Swap Is a Forensic Problem, Not Just a Fraud Problem

Most fraud leaves a fingerprint on the device it happened on. A SIM swap doesn’t. The victim’s phone is often untouched — the compromise happens upstream, at the telco, when a fraudster convinces an agent or exploits a porting process to move the victim’s number onto a SIM they control. From that moment, every OTP, every banking alert, every M-Pesa confirmation goes to the attacker instead.

This is precisely why SIM swap cases are misunderstood by victims and, often, by the legal teams instructed to recover their losses. The instinct is to examine the phone. The evidence, in fact, sits in three separate custody chains — the mobile network operator, the financial institution, and whatever secondary device or account the attacker touched — and a forensic examiner’s job is to reconstruct all three into one timeline that satisfies Section 106A of the Evidence Act (Cap. 80).

“The victim didn’t lose their phone. They lost control of who their phone believed they were.”

Anatomy of a SIM Swap: What Actually Happens, Minute by Minute

Reconstructed Attack Sequence

Six Stages, Usually Under an Hour

This sequence is drawn from the typology of SIM swap matters examined across Kenyan recovery and criminal proceedings. It is the reconstruction an examiner builds after the fact — not a warning about method.

Stage 1

Target Profiling

The attacker gathers enough personal detail — often from a prior data leak or social engineering — to pass identity verification for a line swap.

Evidence: none yet
Stage 2

The Porting Request

A swap or replacement SIM request is filed against the victim’s line, at an agent outlet or through a channel with weaker verification.

Evidence: telco porting log, agent ID, timestamp
Stage 3

Signal Loss

The victim’s genuine SIM goes dark. This is usually the only signal the victim experiences directly — and it is frequently dismissed as a network fault.

Evidence: victim’s own device log, network deregistration event
Stage 4

Account Takeover

OTPs and password reset links now route to the attacker’s SIM. Banking apps, M-Pesa, and email accounts are reset in sequence.

Evidence: bank/telco OTP delivery logs, login IP and device fingerprints
Stage 5

Extraction

Funds move — typically through mobile money to a chain of intermediary accounts or agent tills designed to fragment the trail quickly.

Evidence: M-Pesa/bank transaction records, agent till mapping
Stage 6

Discovery

The victim regains signal — often hours later — to a phone with no missed alerts and accounts already drained.

This is where most cases begin. It should be Stage 1.

How a Forensic Examiner Traces It

Reconstruction works backward from Stage 6 to Stage 2 — each stage confirmed by an independent, third-party record rather than the victim’s own account of events.

01

Call Detail Record (CDR) Analysis

Cross-references the moment the genuine SIM deregistered against the network against the moment the replacement SIM activated — establishing the precise swap window.

02

Porting & Agent Audit Trail

Examines the identification documents, agent code, and outlet used for the swap request — frequently the weakest link and the basis for a negligence claim against the telco.

03

OTP & Login Fingerprinting

Maps every OTP delivery, password reset, and login event to a device and IP address — distinguishing the victim’s genuine activity from the attacker’s.

04

Mobile Money & Bank Transaction Mapping

Follows the extracted funds through agent tills and intermediary accounts, producing the structured financial timeline Kenyan courts expect in recovery proceedings.

05

Victim Device Verification

Confirms the victim’s own device holds no evidence of compromise — closing off a common defence argument that the victim authorised the transactions themselves.

06

Unified Evidentiary Timeline

All five records are merged into one Order 18-compliant report, with each of the three Section 106A conditions addressed against every record relied upon.

Illustrative Matter · Nairobi · Recovery Litigation

KES 2.3M Moved in 41 Minutes — Traced to an Agent Outlet Swap

A victim’s line went silent mid-afternoon; by the time signal returned, KES 2.3 million had moved from a bank account through four mobile money agents. UFC’s CDR analysis pinpointed the exact deregistration and re-registration window, and porting-log examination identified the outlet and agent code used for the swap — evidence the telco’s own verification process had failed at that specific point.

Financial timeline and porting failure documented for recovery proceedings against the telco and receiving accounts.

Frequently Asked Questions

Can a SIM swap be proven after the money is already gone?

Yes, in most cases. The evidence does not live on the victim’s phone — it lives with the telco (porting requests, agent ID, cell-site data) and the receiving financial trail. Forensic examiners reconstruct the swap from these third-party records even when the victim’s device shows nothing unusual.

Whose fault is a SIM swap under Kenyan law — the victim, the telco, or the bank?

It depends on where the forensic evidence places the failure. If the porting request was improperly verified, liability can shift toward the telecommunications provider. If OTPs were phished from the victim, the picture changes. Forensic reconstruction of the full timeline is what determines which party’s negligence enabled the fraud — this is usually the central question in recovery litigation.

How quickly must a victim act for forensic evidence to still exist?

Telco call detail records and porting logs are retained on finite cycles, and mobile money agent-till records get harder to trace as funds move through further transactions. Evidence quality drops fast after 30 days and continues to degrade. Instructing an examiner within days of discovery materially improves recoverability.

Does UFC deal directly with Safaricom or other telcos to obtain SIM swap records?

UFC does not compel telco disclosure directly — that requires a court order or a formal law enforcement request, which we advise your legal team on securing. Once records are obtained, UFC’s role is the forensic reconstruction: correlating CDRs, porting timestamps, device data and mobile money records into a single, court-ready evidentiary timeline.

Every Hour Costs You Evidence.

If you suspect a SIM swap, the telco and financial records that prove it are already ageing. Free, confidential case assessment — response within 4 hours.