The Kenyan government has introduced new regulatory proposals requiring payment service providers such as M-Pesa and Airtel Money to immediately disclose cyber incidents, including mobile money fraud and hacking, to the Central Bank of Kenya (CBK). This move aims to strengthen safeguards for customers' cash and provide early warnings of potential attacks that could disrupt financial services.
The proposed rules, which are part of the National Payment System Bill, 2026, define a material event as a significant data breach or cybersecurity incident, a prolonged or systemic service outage affecting payment processing or settlement, and the loss, unauthorized access to or misappropriation of customer funds. Payment service providers that fail to report such incidents could face fines of up to Sh1 million or risk having their permits revoked.
According to official data, mobile banking was the hardest-hit channel by cyber fraud in 2024, with criminals siphoning Sh810.68 million, up from Sh182.41 million in 2023. The majority of these thefts occurred on Friday and Saturday nights, with millennials being the most affected. In 2025, Kenyans lost $3.8 million (Sh492.3 million) in cash and cryptocurrency due to SIM-swap fraud.
The rapid growth of Kenya's digital payment ecosystem has increased exposure to cyber threats, financial crime, operational disruptions, and systemic risks. The CBK and Treasury attribute this to the country's early adoption of mobile money systems, which has made it a target for hackers. The proposed rules aim to address these risks and enhance cybersecurity and technology risk management.
The current National Payment System Act, enacted in 2011, does not require payment providers to immediately report cyber breaches. The Treasury and CBK believe that this law is no longer fully aligned with the pace of technological change and creates regulatory gaps that hinder innovation while exposing the financial system to risks.
Similar measures have been adopted in other markets globally, including the European Union, where payment service providers are required to report major operational or security incidents within four hours of classification, or within a maximum of 24 hours after becoming aware of an incident. Thailand also requires payment providers to disclose cybersecurity incidents and data breaches under a framework overseen by the Bank of Thailand.
The proposed law seeks to strengthen cybersecurity and technology risk management through enhanced incident reporting, threat intelligence, security testing, third-party risk management, and stronger supervisory arrangements. Authorities also point to the growing interconnection between banks, payment service providers, fintechs, payment systems, and third-party technology providers as a source of new risks.
Key points
- Payment service providers in Kenya will be required to report cyber incidents to the CBK under proposed rules.
- The proposed rules aim to enhance customer safeguards and prevent cyber threats.
- Similar measures have been adopted in other markets globally, including the European Union and Thailand.