Fake SHA Registration Exposes Alleged SIM-Swap Fraud Ring Targeting Kenyans as Suspect Arrested


A suspected SIM-swap fraudster allegedly posing as a government official carrying out Social Health Authority (SHA) registration has been arrested in Mtwapa, Kilifi County, following an intelligence-led operation by detectives.

The suspect, identified as 37-year-old Phyllis Njagi, was arrested by officers from the Directorate of Criminal Investigations (DCI) attached to Kilifi South and Nyali after detectives received intelligence about a group allegedly moving from one area to another while posing as government officials.

According to investigators, the suspects had been operating in areas including Mwea, Machakos, Kitui and Mwingi, where they allegedly targeted unsuspecting members of the public, particularly elderly people.

The group is suspected of using the ongoing SHA registration exercise as a cover to gain access to sensitive personal information belonging to potential victims.

Detectives allege that after collecting the information, the suspects would use it to facilitate SIM-card swaps, potentially giving them access to victims’ mobile-money accounts and other digital wallets.

Suspect arrested in Mtwapa

The breakthrough came after detectives mounted an operation in the Kwa Chief area of Mtwapa, where they intercepted Njagi.

At the time of her arrest, she was reportedly driving a Mazda CX-5, registration number KDT 012M, which detectives detained for further examination as investigations continued.

However, a suspected accomplice identified as John Mutesa Mango reportedly managed to evade arrest during the operation.

Mango is now being sought by detectives, who have appealed to members of the public to assist in tracing him.

A search of the vehicle allegedly resulted in the recovery of several insurance documents and number-plate casings.

Among the items recovered were five insurance certificates bearing registration number KDT 012M, two duplicate insurance certificates for motor vehicle KDP 019N, three insurance certificates for KDS 150J, as well as two number-plate casings.

Detectives are examining the items as part of investigations into the suspected fraud network.

How the alleged SHA registration scam worked

The alleged scheme highlights a growing concern around the amount of personal information that criminals can attempt to obtain by exploiting legitimate government or commercial activities.

Read Also  Murkomen Warns Of Consequences On Claims Of Organ Harvesting

In this case, the suspects allegedly presented themselves as officials conducting SHA registration, giving them an opportunity to interact directly with members of the public.

The information allegedly collected could then be used as part of attempts to impersonate victims and obtain replacement SIM cards.

Once criminals gain control of a victim’s mobile number through a fraudulent SIM swap, the consequences can extend beyond telephone communication.

A mobile number in Kenya is often connected to mobile-money accounts, bank services, email accounts and other digital platforms, meaning control of the number can potentially expose a victim to further financial or identity-related fraud.

Safaricom has previously warned customers against sharing personal information, M-PESA details and PINs with people claiming to be representatives of the company.

The telecommunications company also advises customers to contact it immediately if they suspect that their phone or personal details have been compromised.

SIM-swap fraud remains a serious concern

The latest case comes amid other SIM-swap investigations in Kenya.

In April 2026, DCI detectives arrested eight suspects in Marsabit over an alleged SIM-swap scheme in which more than Sh1.2 million was reportedly stolen from an M-PESA operator.

Investigators alleged that the suspects posed as customers before manipulating the situation to facilitate a SIM swap and gain unauthorised access to funds.

In another case reported in June 2026, detectives arrested a suspect over an alleged SIM-swap fraud involving approximately Sh450,500 from a woman’s M-PESA account.

More recently, a man was arrested in Garissa after allegedly posing as a Safaricom agent and using a purported line-upgrade exercise to facilitate a SIM swap, according to reports citing the DCI.

The incidents demonstrate how fraudsters can exploit ordinary customer-service processes, including SIM replacement, upgrades and requests for personal information.

Why personal information matters

A SIM swap itself is a legitimate telecommunications process used when a customer loses, damages or needs to replace a SIM card.

The danger arises when criminals allegedly manipulate that process by impersonating the genuine owner.

Once a fraudulent replacement has been activated, communications sent to the affected number may potentially reach the person controlling the replacement SIM.

This can become particularly dangerous where the number is linked to financial accounts or services that use the mobile number for authentication.

Read Also  Probe as thieves steal Sh2.5 million from locked car outside Mombasa Hospital

Safaricom says customers should never disclose their M-PESA PIN, personal identification details or other confidential information to unknown callers or people claiming to assist them.

The company also warns customers against following instructions from strangers to enter codes on their phones.

The telecommunications company has also introduced a SIM-swap whitelist option that allows customers to restrict replacement of their numbers to authorised Safaricom shops or care desks after the number has been whitelisted.

Elderly Kenyans among vulnerable targets

The alleged targeting of elderly members of the public in the latest case raises particular concern because criminals can exploit limited familiarity with digital services and government registration procedures.

A person who believes they are dealing with a legitimate government official may be more willing to provide information that they would ordinarily keep private.

However, members of the public should remember that being asked for information during a legitimate registration process does not mean every person claiming to represent the government is genuine.

Anyone carrying out a registration exercise should be independently verified before sensitive information is provided.

People should also be cautious if a stranger asks to take possession of their mobile phone, SIM card or requests a PIN, password or one-time password (OTP).

DCI appeals for information

Detectives have appealed to members of the public to help trace John Mutesa Mango, who remains at large.

Anyone who knows his whereabouts, or anyone who believes they may have been targeted by the alleged scheme, has been urged to report to the nearest police station or contact the DCI through #FichuaKwaDCI.

The DCI has provided the toll-free number 0800 722 203 and WhatsApp number 0709 570 000 for reporting information.

Members of the public have also been urged not to surrender their mobile phones, SIM cards, M-PESA PINs, passwords, OTPs or other sensitive information to strangers claiming to be conducting registration exercises.

The case remains under investigation, and the allegations against the arrested suspect and her alleged accomplice will be subject to the ongoing investigations and due legal process.

 

 

FOLLOW NAIROBI NEWS ON FACEBOOK 

 

 

If you like our work, you can buy us a soda

Buy us a soda 🥤
Email your news TIPS to Editor@nairobinews.co.ke — this is our only official communication channel