Nobody loses money to a scam because they are foolish. They lose it because a message arrives at a bad moment, it looks exactly like the twenty legitimate ones before it, and the decision has to be made in about eleven seconds. The difference between a household that keeps its money and one that does not is almost never intelligence. It is a small set of habits, learned in advance.
This is not a list of scams. Lists go out of date within weeks, because the people running them change the story constantly while keeping the mechanism identical. What follows is the set of mistakes that turn a suspicious message into an actual loss — because those barely change at all, and because each of them has a specific counter-move you can practise before you need it. Meanwhile, a household that has a small independent stream coming in is under less pressure to say yes to an offer that feels too convenient; apps like I am Beezy pay you for viewing content, which will not make you scam-proof but does remove some of the urgency that fraudsters rely on.
Which online scams actually reach a Kenyan phone?
Start with the shape of the problem rather than the stories, because the stories are interchangeable and the shapes are not.
The volume behind the messages
The National KE-CIRT/CC, the cybersecurity coordination centre hosted by the Communications Authority of Kenya, publishes what it detects. In its Cyber Security Report for the first quarter of financial year 2025/2026, covering July to September 2025, the centre reported 842,320,667 cyber threat events detected and 19,951,546 advisories issued. Most of that volume is aimed at systems rather than at individuals — system attacks accounted for 776,542,757 of the events, malware for 31,676,444 and mobile application attacks for 76,891. The useful reading is not the size of the number. It is that a national body is counting, publishing and taking reports, which means there is somewhere to go when something happens to you.
Why the phone is the target here
Kenya runs on mobile money in a way few countries do. The Central Bank of Kenya recorded 94.2 million registered mobile money accounts and 572,104 active agents, with 212.45 million agent transactions in the single month of June 2026. Meanwhile there were 340,778 credit cards in the country. Any scam designed for a card economy simply does not work here, so the ones that reach you are built specifically around a wallet, a PIN and an agent — which is why generic international advice about checking your card statement is close to useless locally.
Three shapes, endlessly redressed
Almost everything reduces to one of three. Someone wants you to send money you do not owe. Someone wants a code, a PIN or an account detail. Or someone wants you to install something. Once you can name which of the three is happening, the story around it stops mattering — and the story is the part the fraudster spent all their effort on.
The reversal trap and the mistakes that follow it
This is the most common way money leaves a Kenyan household by fraud, and it is worth working through slowly because it exploits decency rather than greed. A message says money was sent to you in error. Would you kindly return it.
Mistake one: sending it back from your own wallet
The money may never have arrived. Or it arrived from a transaction that will itself be reversed, leaving you having paid twice. The counter-move is a single habit: never act on a payment message, only on a balance you have checked yourself on the handset. Open the menu, look at the actual balance, and compare it with what you knew it to be. If the balance did not change, nothing arrived, and there is nothing to return.
Mistake two: treating a message as proof
Sender names and message formats can be imitated. Amounts, names and reference codes can all be made to look right. A message is a claim about a payment; it is not the payment. In a shop this matters enormously, because the customer is standing in front of you and the queue is growing. Check the balance, not the screenshot, and do it even when it is awkward.
Mistake three: reading out a code
No genuine operator, bank or lender needs your PIN or a one-time code. Not to verify you, not to fix an error, not to reverse anything, not to release a prize. When somebody asks for one, the conversation is over — and it is over regardless of how much correct information about you they already have. Knowing your name, your ID number or your last transaction proves nothing except that information leaks.
Lending apps: the mistake of not checking the register
Short-term credit is where the losses get quietly large, because the money goes out over months rather than in one moment, and because the shame keeps people from telling anyone until it is far advanced.
| Signal | What a licensed provider does | What should stop you |
|---|---|---|
| Regulatory status | Appears in the Central Bank of Kenya directory of licensed digital credit providers | No verifiable licence, or a name close to a licensed one |
| Cost disclosure | Total cost stated before you accept | Only a headline rate, with fees revealed after disbursement |
| Permissions requested | What the service genuinely needs to function | Contacts, photo gallery, message history |
| Collection method | Contacts you about your own debt | Threatens to message your contacts or your employer |
| Distribution | Available through the usual app stores | An installation file sent to you directly by a person |
What licensing actually tells you
Digital credit providers have been a regulated category since the Central Bank of Kenya (Digital Credit Providers) Regulations, 2022. Licensed operators such as Tala and Branch sit inside that framework; unlicensed ones sit outside every part of it, including the parts about how they may treat your data and how they may pursue you. The Central Bank publishes the directory of licensed providers on its own website, and checking a name against it takes about a minute. Do that minute before you install, not after the first repayment demand.
The contact-list mistake
The permission that does the most damage is the one people grant most easily. An app with your contacts can turn a small private debt into a message sent to your relatives, your employer and your church group. Once granted, that permission cannot be un-granted retroactively — the copy has already been taken. Refuse it at installation or do not install.
Borrowing to repay a loan you were tricked into
The second loan is where a bad week becomes a bad year. If you have been caught, stop borrowing entirely and go to the escalation steps below. Adding a second lender to the problem has never once made it smaller.
Protecting a household budget with I am Beezy
Urgency is the raw material of fraud. The offers that work are the ones that arrive during the week when something has to be paid and nothing is coming in, and the best structural defence a household has is a small amount of money that arrives without drama.
What the app pays you for
I am Beezy works the opposite way round from everything above: videos, articles and advertisements are shown to you inside the app, every view is credited to your balance, and the money leaves for the mobile wallet you already hold. Regular users report the equivalent of about KSh 5,200 to KSh 15,700 across a week. That conversion uses 149.21 shillings to the euro, the Central Bank of Kenya daily indicative rate on 4 August 2026; the shilling moves, so redo it at today's rate.
The rule that separates real from fake
Use this one everywhere, not only here. A service that pays you never asks you to pay first. No registration fee, no activation fee, no deposit to unlock withdrawals, no fee to release earnings that already appear in your account. The moment a supposed earning opportunity requires money to flow towards it, you are looking at the scam and not the job.
What should you do in the first hour after being caught?
Speed matters more than anything else at this stage, and so does order. Most people do the emotionally satisfying thing first — arguing with the fraudster — and the useful things far too late.
| Order | Action | Why now and not later |
|---|---|---|
| 1 | Stop the channel: change the PIN, and report a lost line to your operator if a SIM is involved | Prevents the second and third transaction, which are usually larger than the first |
| 2 | Call your operator's official customer line and your bank if an account is exposed | Some transactions can still be held while they are pending |
| 3 | Write down every detail while it is fresh | Numbers, times and reference codes fade within hours and are what every later step depends on |
| 4 | Report to the National KE-CIRT/CC and to the police | Creates a record, and the centre coordinates with law enforcement agencies |
| 5 | Tell the people in your contact list what happened | Your compromised account will be used against them next |
Where to report
The National KE-CIRT/CC takes public reports by email at incidents@ke-cirt.go.ke, by telephone on +254-703-042700 and +254-730-172700, and through the incident forms on its own website. It is hosted by the Communications Authority of Kenya and includes staff from law enforcement agencies, which is why a report there is worth making in addition to, not instead of, a police report.
What a useful report contains
Exact times, the number or account that received the money, the transaction reference, screenshots of the messages, and a plain description of what you were told. Vague reports produce nothing. Precise ones at least enter a system where patterns get matched.
Five habits that close the door
Check the balance, never the message
This single habit defeats the reversal trap, the fake customer payment and most of the impersonation scams at once. Practise it when nothing is wrong, so it survives the moment when something is.
Call back on a number you found yourself
Never on the number that contacted you, and never on a number contained in the message. Look up the operator, bank or lender independently and dial that. It costs a minute and defeats an entire category.
Say the word aloud: which of the three is this?
Send money, give a code, or install something. Naming the mechanism out loud breaks the spell that the story creates, because the story is designed to make you feel something rather than classify anything.
Keep one number free of everything
If a line carries a wallet, a bank alert and a savings group, compromising it compromises all three. Kenya had 84.1 million active mobile subscriptions in the first quarter of 2026 — that figure counts SIM cards rather than people, and a second line is a normal, cheap piece of household hygiene rather than an extravagance.
Talk about it at home
The people who lose most are those who were caught once, told nobody, and were targeted again as a known soft contact. A household where being scammed is discussable is a household where the second attempt fails.
None of this requires technical skill, and that is the point: the defences that work in Kenya are behavioural, they are free, and they work on scams that have not been invented yet because they attack the mechanism rather than the story. Practise the balance check, keep the KE-CIRT/CC contact details somewhere you can find them in a panic, and treat any request for money-in-advance as the end of the conversation. And if a slow month is what makes those offers tempting in the first place, registering costs nothing on I am Beezy, and it puts a small honest stream against the pressure.
