Bluepeak Technologies logoBluepeak Technologies
Back to Blog
Cybersecurity 30 May 2026 6 min read Bluepeak Technologies

The Phishing Scams Currently Targeting Kenyan Businesses

Fake supplier invoices, cloned M-Pesa messages and CEO fraud — what the latest wave looks like and how to shut it down.

The Phishing Scams Currently Targeting Kenyan Businesses

The current wave of business fraud is quiet and patient. Attackers read your email for weeks, then send one message at the exact moment a payment is expected.

The three patterns to teach your team

Almost every incident we investigate falls into one of these.

  • A supplier emails new bank details just before payment
  • A message appearing to come from a director requests an urgent transfer
  • A payment confirmation SMS arrives that never appears in your statement
Abstract digital security visual

Verify on a second channel

Any change of bank details must be confirmed by calling a number you already had on file — never the number in the email.

“If a request creates urgency and secrecy at the same time, treat it as fraud until proven otherwise.”

Lock down email

Two-factor authentication, mailbox rule audits and alerts on forwarding rules stop the surveillance stage before the fraud stage.

Working with Bluepeak

We run staff awareness sessions and secure business email setups. Reach out if you would like your team tested.

#Phishing#Fraud#Cybersecurity
Share this article

Related Articles

Never Miss a Technology Update

Receive technology tips, cybersecurity alerts, AI updates, and exclusive Bluepeak Technologies insights directly in your inbox.

Ask Ozzy