Kenyan court orders Stanbic Bank to refund Sh511,000 after account takeover fraud exposes digital security gaps

Stanbic Bank Kenya has been ordered to refund a customer after a court found failures in its digital verification systems enabled fraudsters to hijack his account and transfer over Sh1 million. The ruling highlights evolving legal standards for bank security in Kenya amid rising digital fraud risks.

Stanbic Bank Kenya has been ordered to refund a customer Sh511,000 after a court found that weaknesses in its digital onboarding and verification systems allowed fraudsters to take control of his account and move more than Sh1 million within minutes. The ruling adds to a growing body of Kenyan case law testing how far banks must go to protect customers from account takeover fraud and whether basic authentication tools are enough when a new digital channel is activated on an existing account.

According to the court, the dispute turned on the bank’s OMNI platform and the ease with which a digital profile was created using information already available in stolen documents. James Njoroge, a long-standing customer who said he had never signed up for internet or mobile banking, lost his mobile phone, identity card and other personal items in a robbery on July 13, 2025. Fraudsters then registered a new profile on the account at 2.48pm and executed three transfers totalling Sh1,001,000 between 3.09pm and 3.25pm. The theft was reported later that afternoon, and the bank subsequently recovered Sh490,000 from one receiving account and returned it to him.

The Small Claims Court said the lender had a duty to apply stronger know-your-customer checks before allowing a previously offline account to be switched into a powerful digital channel. It found that relying on an identity card number, date of birth, account number and a one-time password sent to a stolen phone did not amount to meaningful verification for a new service. “The information provided 10 years ago to open a physical account is the same information that the fraudster now possesses. It does not serve as a robust verification for a new and powerful channel,” the court said. It also rejected the bank’s claim that the customer’s delay in reporting the robbery absolved it of responsibility, saying the loss would have been avoided had the bank had better safeguards.

The court further criticised the use of SMS-based one-time passwords, saying a “closed-loop” system was commercially unreasonable given the known risks of stolen handsets and SIM cards. Stanbic argued that the transfers were authenticated through the customer’s own credentials and that it could not have known the activity was fraudulent, while also saying nearly 11 hours passed before the robbery was reported. But the judge found that Njoroge had been drugged and incapacitated during the attack, and that his wife alerted the bank as soon as reasonably practicable. The court ordered Stanbic to pay Sh511,000 plus interest at 12 per cent a year from the date the suit was filed.

The case comes amid a wider pattern of disputes over banking fraud and liability in East Africa. In a separate Nairobi matter reported by Breaking Kenya News, a court dismissed a claim against Equity Bank after finding that disputed withdrawals were carried out using the customer’s own login details, email address and Kenyan phone number. Other recent rulings involving Stanbic have centred on different issues, including interest-rate disputes, alleged employee fraud and wrongful debits, underscoring the pressure on lenders to tighten controls and document their internal procedures carefully.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.