Homeâ€șBlogâ€șEmail Phishing: How Kenyan Businesses Are Targeted and What to Do
Guide4 min read

Email Phishing: How Kenyan Businesses Are Targeted and What to Do

Kenyan businesses lose millions to email phishing attacks each year. Here's how criminals target your inbox and the practical steps to protect yourself.

cybersecurityphishingemailKenya
20 September 2026
Email Phishing: How Kenyan Businesses Are Targeted and What to Do

Kenyan businesses are losing money to email phishing attacks at an alarming rate. A taxi firm in Nairobi wired 2.3 million shillings to what they thought was their landlord. A logistics company in Mombasa handed over M-Pesa credentials after clicking a link in a message that looked like it came from their bank. These aren't isolated incidents—they're part of a growing pattern of email phishing targeting small and medium enterprises across Kenya.

Email phishing works because it exploits trust. The attacker doesn't break into your system. They convince you to do it for them.

How the Attack Starts

A phishing email typically arrives looking legitimate. It might claim to be from your bank, your email provider, or a vendor you work with regularly. The sender address looks close to the real thing—maybe support@safaricom.co.ke becomes support@safaricomm.co.ke (notice the extra 'm'). These details matter because they're designed to pass a quick glance.

The message usually creates urgency. Your account is locked. There's suspicious activity. You need to verify your identity now. A link takes you to a fake login page that looks pixel-perfect identical to the real thing. You enter your credentials. The attacker now has them.

What happens next depends on what you've just handed over. If it's your bank login, money moves. If it's your email credentials, the attacker can reset passwords for every service linked to that email. If it's your M-Pesa PIN, they can drain your mobile wallet.

Some phishing attacks are more sophisticated. They target specific people in your organization—your accountant, your HR person, whoever controls money or sensitive data. These are called spear phishing, and they're researched. The attacker knows your company name, your employee names, your vendors. The email feels like it came from someone you actually know.

What Kenyan Businesses Should Do Right Now

Train your team to spot the signs. Legitimate companies rarely ask you to click a link and log in. Banks don't request passwords via email. If something feels off, it probably is. A few minutes of training—showing staff real examples of phishing emails—cuts your risk significantly.

Enable two-factor authentication everywhere. This is non-negotiable. Even if an attacker gets your password, they can't access your account without the second code. Set it up for your email, your banking apps, your business accounts. If you work with sensitive systems, find a verified Kenyan expert on Kaziiko who can audit your security setup.

Use strong, unique passwords. If you reuse the same password across multiple services and one gets compromised, all your accounts are at risk. A password manager like Bitwarden or 1Password makes this manageable without the headache of remembering 20 different combinations.

Check sender addresses carefully. Hover over the sender name to see the actual email address before clicking anything. Attackers are clever with display names, but the actual email address is harder to fake convincingly.

Never trust a link in an unsolicited email. If your bank sends you a message about account activity, go directly to the bank's website or app. Type the URL yourself. Don't click the link in the email.

Set up email filters and monitoring. Most email providers let you flag suspicious messages as phishing. Do it. Also consider that cybersecurity consultants in Kenya can help set up more advanced filters for business accounts.

Report phishing attempts to your bank and the relevant authority. If you receive a phishing email pretending to be from your bank, report it to the bank directly and to the Communications Authority of Kenya. This helps protect other businesses.

Frequently Asked Questions

What should I do if I already clicked the link and entered my password?

Change your password immediately from a different device. If it was a banking or financial account, contact your bank directly (use the number on your card, not a number in the email). Check your recent account activity for unauthorized access. Enable two-factor authentication if it's not already active.

Can phishing emails spread viruses to my computer?

Some phishing emails contain malware attachments that can infect your device. Never open attachments from untrusted sources, especially executable files (.exe, .zip). If you're unsure, ask someone you trust before opening anything.

Why do phishing emails look so real?

Attackers study real emails from legitimate companies. They copy logos, fonts, and layouts. They use similar language and formatting. They'll even buy domains that look almost identical to the real ones. This is why checking the actual sender email address—not just the display name—is critical.

Is my small business really a target for phishing?

Yes. Attackers don't only go after big corporations. Small and medium businesses are common targets because they often have fewer security measures in place. A single employee with access to business accounts is all an attacker needs.

KaziikoKazi IkoKenya's Digital Expert Marketplace

Skip the queue — hire a verified expert

Pay via
M-PESA

Our vetted specialists handle KRA, eCitizen, NTSA, SHA, NSSF and more — remotely, in hours.

✓ Verified & background-checked experts
✓ Pay securely via M-Pesa — no cash
✓ Work delivered remotely in hours
✓ Dispute protection on every order
eCitizenKRA & TaxNTSASHABusiness Reg.CV Writingkaziiko.co.ke

You might also like

All articles â€ș
Guide

How to Apply for a Kenya Revenue Authority Objection

4 min read
Guide

How to Register for Ajira Digital in Kenya and Get Paid

4 min read
Guide

How to Change Your Name Officially After Marriage in Kenya

4 min read