Cybersecurity incidents often end with a familiar question: who is to blame? The answer is usually straightforward when an attacker exploits a vulnerability or steals credentials. But what happens when a breach is made possible by failures across multiple organizations? Where does responsibility begin, and where does it end?
A recent High Court ruling in Kenya has provided one of the clearest answers yet. In a landmark judgment, the High Court upheld an earlier decision requiring Safaricom PLC and Diamond Trust Bank (DTB) to compensate a customer who lost KSh 4.42 million through a SIM swap fraud. The court apportioned liability between the two institutions: 60% to Safaricom and 40% to DTB since the court found that each owed the customer an independent duty of care, and that failures by both contributed directly to the loss.
The case is more than a legal victory for one customer. It is a defining moment for Kenya’s digital economy, where mobile phones have evolved far beyond communication devices. Today, they serve as digital identities, banking credentials, payment channels, and gateways to countless online services.
The ruling sends a powerful message to every organization handling customer identity or digital transactions: meeting minimum procedural requirements is no longer enough. Organizations are expected to anticipate risk, detect abnormal behavior, and act before customers suffer preventable losses.
For business leaders, CISOs, IT managers, compliance officers, and boards, this case offers lessons that extend far beyond banking and telecommunications.
A Fraud That Followed the Process
The attack itself was not particularly sophisticated. On 6 February 2022, Mercy Wairimu Kariuki received notifications indicating that her Safaricom SIM card had been replaced without her authorization. Recognizing the danger, she immediately contacted Safaricom’s customer care and was advised to visit a customer service center, where her line was restored the following day.
For many organizations, this would appear to be a success story. The issue had been reported, customer support had responded, and the SIM had been restored. But the real attack had already begun. Two days later, Kariuki started receiving alerts from DTB informing her that KSh 4.42 million had been transferred from her account through unauthorized mobile banking and Pesalink transactions — staggered into smaller amounts to stay beneath the bank’s daily limits.
The fraudsters had exploited the short window created by the SIM swap to intercept authentication messages and access her financial accounts. The customer had done exactly what security awareness campaigns encourage: she noticed suspicious activity and reported it immediately. Yet the fraud still succeeded. That should concern every organization.
The Court Looked Beyond Technical Compliance
One of the most significant aspects of the judgment is that the court refused to accept procedural compliance as an adequate defense.
DTB argued that the transactions had been authenticated using the customer’s correct mobile banking PIN and that the transfers remained within the bank’s daily transaction limits. Safaricom argued that it merely provided telecommunications services and that the banking transactions fell outside its responsibility. The court rejected both arguments.
Justice Asenath Ongeri emphasized that each organization owed the customer its own independent duty of care. One organization’s failure did not excuse the other. The court set out several principles that will resonate well beyond this case. It held that a bank cannot hide behind a customer’s PIN when confronted with a series of transactions so far outside the ordinary that a reasonable banker would have been put on inquiry. It also rejected the argument that the transfers occurred on a non-business day, noting that modern banking systems operate around the clock and must be capable of detecting suspicious activity regardless of the day.
For the bank, multiple high-value transfers made within a short period to unfamiliar beneficiaries should have prompted further verification before the transactions were processed. For the telecommunications provider, the customer had already reported the unauthorized SIM swap and that report created an obligation to prevent the fraudulent SIM from remaining active and being used to facilitate further fraud.
The judgment reinforces a critical cybersecurity principle: security is measured not only by whether procedures were followed, but by whether foreseeable risks were effectively managed.
Cybersecurity Is No Longer About Individual Systems
One of the biggest misconceptions in cybersecurity is that organizations only need to secure the systems they directly control. That approach no longer reflects reality. Modern digital services are deeply interconnected. Banks rely on mobile networks for customer authentication. Telecommunications providers enable digital identities. Cloud platforms host critical applications. Payment gateways connect financial institutions. Every organization becomes part of a much larger trust ecosystem.
The Safaricom–DTB case illustrates how a weakness in one part of that ecosystem can quickly become a crisis for another. Neither organization caused the fraud independently. Instead, separate failures combined into one successful attack. That is precisely how many cyberattacks unfold today: attackers rarely defeat a single security control. They exploit the gaps between multiple organizations, technologies, and business processes.
Identity Has Become the New Attack Surface
The ruling also highlights a broader shift in cybersecurity. For years, organizations focused primarily on protecting networks, servers, and endpoints. Today’s attackers increasingly target identities instead.
A mobile phone number is no longer just a communication channel. It has become part of the identity infrastructure supporting banking, digital payments, password recovery, government services, and online authentication. When criminals successfully compromise that identity, they often gain access to far more than a single account.
Organizations must therefore rethink identity protection as a business-critical function rather than simply an IT responsibility. Traditional controls such as passwords and SMS-based one-time passwords remain valuable, but they should increasingly be complemented by stronger authentication methods, behavioral analytics, continuous risk monitoring, and adaptive verification.
The Real Lesson Isn’t About SIM Swaps
It would be easy to conclude that this case is simply about SIM swap fraud. It isn’t. It is about organizational resilience. It is about governance. It is about understanding that cybersecurity failures rarely result from a single mistake. Instead, they emerge when small weaknesses across different organizations align at exactly the wrong moment: a delayed response, an overlooked alert, an unusual transaction that appears routine, a verification process that no longer reflects today’s threat landscape.
Each may seem insignificant in isolation. Together, they become the pathway attackers need.
What Every Organization Should Do Now
Every organization should treat this ruling as an opportunity to ask difficult questions before regulators, customers, or courts do:
Conclusion
The High Court’s decision marks more than the end of a legal dispute. It reflects the evolving expectations placed on organizations operating in an increasingly digital world. Customers no longer judge organizations solely by the services they provide. They judge them by how well they protect their identities, their data, and their money.
For businesses, the lesson is clear. Cybersecurity is no longer about checking compliance boxes or deploying another security product. It is about building systems that anticipate risk, detect anomalies, respond decisively, and protect customer trust.
Because in today’s threat landscape, the organizations that earn trust won’t be those that never experience attacks they’ll be those that are prepared to stop them before customers pay the price.
Could your current security controls identify unusual behavior before it became a costly breach?
Let us talk.
? Telephone: +254 728 223333 | +254 717 335467
? Email: cybersecurity@southendtech.co.ke | info@southendtech.co.ke | dataprotection@southendtech.co.ke
“South-End Tech Limited — helping businesses build visible and cyber-resilient enterprises”