Home » Business » Cyber cafés to give State users’ names, computer logs

Share This Post

Business

Cyber cafés to give State users’ names, computer logs

Cyber cafés to give State users’ names, computer logs

Cyber cafés in Kenya will from Friday be required to keep customers’ records such as names, identification numbers, the computer used and login time in fresh efforts to curb cybercrimes like mobile money theft and SIM swap fraud.

New regulations published by the Communications Authority of Kenya (CA) demand that the internet shops issue receipts and keep the records for a minimum of three years, during which the regulator can request them for investigation.

Public internet cafés do not enforce strict user identification, making them attractive to cybercriminals seeking to browse, steal data and hack without being traced through their personal IP addresses.

They also give criminals access to a large pool of personal data like ID numbers, names, passwords and phone numbers of users who log into their accounts using unsecured public computers.

The new regulations come amid a surge in SIM swap and mobile money fraud in Kenya, leading to billions of shillings in losses.

“Put in place a mechanism for registering customers,” say the new CA licensing regulations for public communications access centres, which take effect on August 14.

“Maintain basic user logs of service usage, essentially a customer session log (excluding personal browsing history), which will cover the terminal ID, session start and end time.”

Customer session logs record users’ interactions with websites or apps, tracking login times, page views, and clicks. Terminal IDs are unique codes that help businesses track which of their computers processed a transaction. Such data helps IT system managers monitor behaviour, troubleshoot errors, and audit security to nab fraudsters.

“The licensee shall grant the authority’s authorised officers’ reasonable access to premises, systems, records, and equipment for the purpose of inspection, audit, or investigation,” the rules say.

Those in breach of the regulations face fines equivalent to 0.2 percent of their annual turnover, with the minimum penalty set at Sh500,000. They also face business closure.

Kenyans lost Sh491.6 million ($3.8 million) and cryptocurrency after cyber-criminals hijacked victims’ mobile phone numbers in the SIM-swap fraud.

International Criminal Police Organization (Interpol) reckons that Kenya’s SIM swap fraud surged by 327 per cent last year on the back of increased use of mobile money platforms.

The surge in attacks highlights the risk of cyber heists in the wake of lenders’ heavy investments in tech and mobile banking.

Through SIM swap fraud, fraudsters hijack victims’ phone numbers, gaining unauthorised access to sensitive accounts such as banking, mobile phone wallets and cryptocurrency platforms. It occurs when a fraudster convinces a mobile carrier to transfer a victim’s phone number to a SIM card they control, exploiting the legitimate feature of mobile number portability.

Once the swap is complete, the victim’s phone loses network connectivity, and the fraudster receives all calls and texts, including one-time passwords for account access.

Kenya built a reputation as a pioneer of financial inclusion through its early adoption of a mobile money system that enables people to transfer cash and make payments on cellphones with or without a bank account.

This has become a hackers’ paradise. Mobile banking was the hardest hit, with criminals siphoning off Sh810.68 million in 2024, translating to a 344 percent rise from Sh182.41 million in the prior year.

The thefts often happen on Friday and Saturday night, with millennials—individuals born between 1981 and 1996— being the most affected.

Cyber cafés in Kenya boomed in the late 2000s and early 2010s in the cities and larger towns.

But widespread use of smartphones and cheaper, faster mobile data have largely replaced the need for traditional internet browsing at cyber cafés.

Cybercriminals are exploiting public internet shops by installing malware on their unsecured computers to record customer usernames, passwords, and banking details, and intercepting their networks to snoop on customers’ activity.

The criminals run their activities anonymously because police struggle to track them as the majority of the cafés do not enforce strict user ID checks.

The CA previously proposed mandatory CCTV surveillance for all cafés but has dropped the requirement in the latest rules.

The new rules also require cyber cafés to install software and set network filters in their computers that block access to illegal websites and scan web traffic in real time to stop dangerous downloads or illegal files.

They also bar café owners from bandwidth reselling – buying bulk data or a high-capacity connection from internet service providers and breaking it down to sell smaller amounts to end users – without the CA’s approval.

The new rules also seek to stamp out other internet offences like piracy, document forgery, identity theft and cyberbullying. Businesses in breach of the new regulations face closure.

“The authority may suspend the licensed services where the licensee has breached a condition in this licence and the licensee has been notified of the breach of the licence condition and has been given notice to comply within a specified period and failed to comply,” the CA says.

Share This Post

Leave a Reply