On a Saturday afternoon in Marsabit Town, a group of customers walked into a small M-Pesa shop the way hundreds of people do every day across Kenya. Nothing about them seemed unusual at first. They chatted, asked routine questions, and eventually convinced the operator to hand over the shop's M-Pesa SIM card under a pretext. Within a short window, detectives from the Directorate of Criminal Investigations say the group used that access to carry out a fraudulent SIM swap, giving them control of the line and, through it, unauthorised access to the operator's linked bank account. By the time the fraud was discovered, more than Sh1.2 million had been moved out. Eight suspects were later intercepted at the Merille Barrier in Marsabit South, travelling in a white Toyota Probox, and taken into custody as investigations continued.
What stands out in the DCI's own account of the case is how ordinary the crime looked while it was happening. There was no forced entry, no visible weapon, nothing that would have triggered an alarm in the moment. The syndicate relied on distraction and deception inside a small counter space, the kind of environment where a single operator has no second set of eyes and no record of who walked in, what they touched, or how long they lingered near the SIM card drawer. That gap, a shop with no monitored camera coverage and no access control separating the public counter from the SIM and cash-handling area, is exactly what a well-designed physical security layer is built to close.
A similar pattern shows up a few weeks later and a few hundred kilometres away, in Kimilili Town in Bungoma County, where police raided a shop trading as an ordinary electronics outlet. According to the DCI, officers found the premises was actually functioning as the operational base for a syndicate stealing, reprogramming, and reselling phones, recovering dozens of devices along with equipment used to alter phone identities. In both cases, the crime hid inside a legitimate-looking shop front, and in both cases, investigators eventually had to reconstruct what happened after the fact, using intelligence, informants, and vehicle tracking rather than a clear visual record of the crime as it occurred. A separate incident in Bungoma, where a bank customer was abducted minutes after a large cash withdrawal, shows the other side of that coin. There, investigators specifically went back to the bank's CCTV footage to establish whether the attackers had conducted surveillance inside the banking hall, precisely because footage is what turns a suspicion into evidence.
The Situation
Kenyan M-Pesa shops, mobile banking agents, and corporate paybill offices are, by the nature of the business, low-margin, high-trust environments. An agent often works alone or with one colleague, handles a steady stream of strangers, and has neither the time nor the staffing to interrogate every customer's intentions. That is precisely the environment fraud syndicates target, because it offers maximum opportunity for social engineering with minimal risk of being identified afterward. Without cameras covering the counter, the SIM storage point, and the entrance, there is no independent record of who was present when a swap or an unusual request occurred. Without access control separating customer-facing space from the back office where SIM cards, registers, and cash are kept, anyone willing to lean over a counter or ask to "see the phone" has a real chance of getting what they want.
The businesses most at risk share a familiar profile. They operate in single-room premises with an open counter design, they have no recorded video coverage or only a non-functional camera installed for appearances, and they have never had staff trained on how to use footage or access logs as part of an actual response plan. Cost is often the reason cited for skipping this layer, since a basic CCTV kit and access-controlled door can feel like an unnecessary expense against tight daily margins. But the Marsabit case put a number on what the alternative costs: over a million shillings gone in one sitting, with the only path to recovery running through detectives working backward from vehicle sightings and informant tips rather than a clear image of the suspects at the counter.
The Decision or Turning Point
For agents and corporate paybill operators who take this risk seriously, the response usually starts with treating CCTV and access control as core transaction security rather than decoration. A properly designed system covers the counter at face height, the SIM and document storage area, and the entrance and exit points, with footage retained for a set period and, ideally, backed up off-site or to the cloud so a burglary or tampering attempt cannot simply erase the evidence. Just as important is access control on the areas customers should never reach unsupervised. A locked partition or door between the public counter and the back office, opened only by staff using a PIN, card, or biometric reader, removes the easy opportunity a fraudster relies on when they ask to "quickly check" a phone or SIM.
The deterrent effect matters as much as the evidentiary one. Visible, well-labelled cameras and a clearly controlled entry point change the calculation for a syndicate scouting a shop before an attempt, since the entire method depends on being able to operate without being identified. Pairing this with live monitoring, where footage is watched or flagged in real time rather than only reviewed after a loss, adds a layer that can interrupt an attempt in progress, for instance when an operator triggers a discreet alert if a customer insists on handling a phone or SIM card directly.
Choosing a provider for this is where many small business owners get stuck, since the market is full of installers offering cameras with no clarity on licensing, response time, or what happens if a system goes down. This is where we can help in a concrete way. At Secuwatch, we let an agent or finance manager compare PSRA-licensed providers on staff vetting, monitoring response times, and transparent pricing before signing a contract, rather than trusting whoever happens to walk in with a sales pitch.
The Outcome
Where CCTV and access control have been properly installed and maintained, the realistic pattern is that most social-engineering attempts either get abandoned before they start, because the premises visibly is not an easy target, or get caught on footage that gives investigators a face, a vehicle, or a timestamp to work from immediately rather than weeks into an investigation. That second point matters more than it might seem. In the Marsabit case, detectives still managed an arrest because of intelligence work and a vehicle interception, but a shop with working cameras would likely have shortened that timeline considerably and made identification far more certain from the outset.
It would be misleading to claim this closes every gap. A camera pointed at a counter does not stop a determined fraudster from succeeding on that visit, it mainly changes what happens afterward and what risk the fraudster is willing to accept going in. Systems still fail when footage is not actually reviewed, when storage runs out and old recordings get overwritten before anyone notices a loss, or when access control is technically installed but staff prop the back door open out of habit. The technology only works as well as the routine built around it, which is why credible providers pair the hardware with a maintenance and monitoring schedule rather than a one-time installation.
Lessons and Takeaways
The practical lesson for anyone running an M-Pesa shop, mobile banking outlet, or a business handling a corporate paybill is that physical visibility and access discipline are not separate from cyber fraud prevention, they are the first layer of it. A SIM swap almost always starts with a physical interaction, someone at a counter, someone asking for a document or a phone, and that moment is exactly what cameras and access control are designed to catch. Agents should insist on camera coverage of the SIM handling point specifically, not just the entrance, and should never allow a customer behind the counter regardless of how convincing the reason sounds.
Before installing anything, verify that a provider is PSRA licensed, ask what their actual response time looks like if a camera goes offline or an alert is triggered, and get storage duration and backup arrangements confirmed in writing. Comparing vetted options through Secuwatch, rather than defaulting to the cheapest quote, is a small step that meaningfully reduces the odds of ending up with cameras that look reassuring but were never built to actually help an investigation.
Conclusion
The Marsabit case, alongside the Kimilili syndicate bust and the Bungoma abduction where footage became central to the investigation, all point to the same practical truth. Fraud syndicates in Kenya count on operating in blind spots, physical spaces with no recorded eyes and no controlled access. Closing that gap will not eliminate every attempt, but it changes the odds meaningfully, both by discouraging criminals who prefer easier, unmonitored targets and by giving investigators something concrete to work with the moment something does go wrong. For a business owner weighing whether a camera system and a locked back office are worth the cost, the honest answer is that the alternative, discovered only after the money is already gone, tends to cost far more.