Cyber cafes across the country will from Friday be required to keep detailed records of their customers, including names, identification numbers, the computer used and login times, as part of fresh government efforts to curb cybercrimes such as mobile money theft and SIM-swap fraud.
New licensing regulations published by the Communications Authority of Kenya (CA) require internet shops to issue receipts for every transaction and retain customer records for a minimum of three years, during which the regulator can demand access to them for investigation.
“Put in place a mechanism for registering customers,” the new CA licensing rules for public communications access centres state, adding that operators must “maintain basic user logs of service usage, essentially a customer session log (excluding personal browsing history), which will cover the terminal ID, session start and end time.”
The rules take effect on August 14, 2026.
Regulators have long worried that public internet cafes offer criminals an easy layer of cover, since customers are rarely asked to prove who they are before logging on. Without that check, someone can browse, extract data or break into systems from a shared machine with little chance of ever being traced back through a personal IP address.
The risk cuts the other way too: those same unsecured, shared computers can provide a rich source of login details for anyone looking to harvest them, as well as ID numbers or phone numbers left behind by ordinary customers simply signing into their own accounts.
Under the new rules, the CA’s officers must be given “reasonable access to premises, systems, records, and equipment for the purpose of inspection, audit, or investigation.”
Cybercafe operators will also need software and network filters on their machines that can flag and block illegal websites and scan traffic passing through in real time to catch dangerous downloads before they spread.
Cafe owners are also barred from a practice known as bandwidth reselling, in which they buy a large, discounted data package or connection from an internet provider and quietly split it up to sell to individual customers, unless the CA has specifically signed off on it first.
Beyond the mobile money angle, the rules are also pitched as a tool against piracy, forged documents, identity theft and online harassment.
Those found in breach of the new regulations face a fine set at 0.2 per cent of a business’s annual turnover, with a floor of Sh500,000 regardless of how small the operation is, and the possibility of being shut down entirely.
“The authority may suspend the licensed services where the licensee has breached a condition in this licence and the licensee has been notified of the breach of the licence condition and has been given notice to comply within a specified period and failed to comply,” CA says.
In recent times, SIM-swap fraud has drained Sh491.6 million from victims, on top of stolen cryptocurrency, after criminals took control of people’s phone numbers to bypass security checks.
- Four arrested in Nairobi over Sh600,000 fake NIS job scam
- Kenyan man in $11M Minnesota fraud case vanishes after missing court date
International Criminal Police Organisation (Interpol) figures put the scale of the problem in Kenya even more sharply, estimating a 327 per cent jump in SIM-swap cases over the past year, a rise the policing body links to how deeply mobile money has embedded itself in everyday Kenyan life.
Mobile banking fraud has grown just as sharply, with Sh810.68 million stolen through it in 2024, more than four times the Sh182.41 million lost the year before. Much of this activity, reports suggest, clusters around weekends, and millennials, those born between 1981 and 1996, appear to be the most affected.
The mechanics of a SIM swap are straightforward but devastating. A fraudster persuades a mobile network to move a victim’s number onto a new SIM card under the fraudster’s control, exploiting the same portability feature that lets genuine customers switch networks without losing their number.
The moment the swap goes through, the real owner’s phone goes silent, cut off from the network, while every call, text and one-time password meant for them now lands with the fraudster instead, often clearing the final hurdle standing between them and someone’s bank account.
The irony is that Kenya earned its reputation as a global leader in financial inclusion precisely because mobile money made banking accessible to people who had never held a bank account. That same accessibility is now part of what makes the system a target.
Cyber cafes, once a fixture of town centres, have lost relevance as smartphones became widespread and mobile data got cheaper and faster. Those that remain are still vulnerable, with criminals using malware or cafe networks to steal passwords and banking details, often shielded by weak customer identification checks.

