Safaricom has issued a warning to users of its M-Pesa mobile money service about a new type of fraud known as the 'silent prompt scam', where criminals illicitly transfer funds without the account holder's direct authorisation. The alert comes in the wake of a Kenyan High Court ruling that found both Safaricom and Diamond Trust Bank (DTB) failed to protect a customer from a SIM swap fraud that resulted in a loss of 4.4 million Kenyan shillings. The court ordered the two companies to share the losses from the July 2025 incident.

According to reports, the 'silent prompt' scam exploits a feature within the M-Pesa system. Fraudsters, having gained access to a user's line through methods like SIM swap fraud, initiate a transaction that triggers a payment prompt on the victim's phone. They then use social engineering tactics, such as calling the victim and pretending to be from Safaricom's customer care, to convince the user to press a key that authorises the fraudulent transfer. Because the victim hears only the phone call and not the distinct M-Pesa transaction notification sound, they are often unaware they are approving a real financial transaction.

The recent court case, detailed in a judgement delivered on July 12, 2026, centred on a SIM swap attack that enabled fraudsters to drain 4.4 million shillings from a customer's DTB bank account, which was linked to their M-Pesa line. Justice Alfred Mabeya ruled that Safaricom's systems were compromised, allowing the unauthorised SIM swap to proceed, while DTB failed in its duty to detect and block the suspicious transactions. The judge stated that financial institutions and telecommunications companies must bear responsibility for systemic failures that enable such crimes, setting a precedent for customer liability in similar fraud cases.

This legal development and the emergence of the silent prompt tactic highlight the evolving challenges facing Africa's largest mobile money platform. M-Pesa, with tens of millions of users across Kenya and the region, has been a cornerstone of financial inclusion, but its success has made it a prime target for sophisticated fraud rings. The service's deep integration with banking systems, while convenient, can create vulnerabilities when security protocols at either the telco or bank level are breached.

In response to these threats, Safaricom continues to develop new security features. The company recently launched 'Shiriki Pay', a service designed to make shared payments for bills or group purchases more secure by allowing a payer to share a payment link instead of sharing their personal till number publicly. While this addresses one vector of fraud, the silent prompt scam underscores the need for continuous consumer education on social engineering techniques that bypass technical safeguards.

The ruling against Safaricom and DTB is being closely watched by Kenya's financial and telecommunications sectors. It signals a shift in judicial attitude, placing a greater burden of proof on service providers to demonstrate they have robust systems to protect customers. As digital financial services proliferate across Africa, regulators and companies are under increasing pressure to fortify defences against fraud without stifling the innovation and accessibility that have driven adoption.

Countries Mentioned