Mobile money giants M-Pesa and Airtel Money will be legally required to immediately disclose cyber incidents — including mobile money fraud and hacking attacks — to the Central Bank of Kenya under sweeping new regulatory proposals designed to protect millions of Kenyans’ hard-earned cash. The rules, jointly proposed by the National Treasury and the CBK, place a direct obligation on all payment service providers and payment system operators to notify the regulator the moment any cyber breach threatens their operations.
This is not a small procedural tweak. Kenya’s mobile money ecosystem moves billions of shillings daily, and for most ordinary Kenyans — especially the youth — M-Pesa is not just a convenience, it is the bank. When fraudsters drain someone’s mobile wallet, that person does not lose pocket change; they lose rent money, school fees, a small business’s working capital. The stakes could not be more personal, and the regulatory gap that allowed providers to quietly absorb or downplay breaches has long been a scandal hiding in plain sight.
What the New Rules Actually Mean
Under the proposed framework, payment service providers can no longer treat a cyber incident as an internal matter to be quietly resolved after the fact. Mandatory and immediate disclosure to the CBK becomes the baseline standard, stripping companies of the discretion they previously enjoyed to manage the narrative around breaches. The CBK gains real-time visibility into the integrity of the payment infrastructure that underpins the Kenyan economy, giving the regulator the power to intervene before a localised breach cascades into a systemic crisis affecting millions of accounts simultaneously.
The proposals signal a clear shift in how Kenyan authorities view the responsibility of tech-driven financial platforms. For too long, the burden of mobile money fraud fell almost entirely on the individual customer — left to chase call centres, file police reports that went nowhere, and absorb losses that the providers rarely publicised. Forcing companies to report breaches to the CBK creates an institutional paper trail, one that makes it far harder for providers to minimise the scale of incidents or delay accountability. Smart, skeptical Kenyans should read this for what it is: a long-overdue acknowledgment that self-regulation in this space simply has not worked.




