Why Kenyan SMEs Are Being Targeted by Hackers
A familiar payment request, one convincing email, and a growing business can suddenly be in crisis. Here is why Kenyan SMEs are being targeted and how to respond.
A familiar payment request, one convincing email, and a growing business can suddenly be in crisis. Here is why Kenyan SMEs are being targeted and how to respond.
At 4:47 on a Friday afternoon, Amina receives an email from a supplier her business has worked with for years. The invoice looks normal. The language sounds familiar, the logo is correct, and the amount matches an order her team is expecting. There is only one change: the supplier has “updated” its payment details.
A few minutes later, a WhatsApp message appears from someone using the managing director’s name and photograph. Please process this before the weekend. It is urgent.
Amina is careful, but she is also busy. Customers are waiting, deliveries are moving, and the finance team is trying to close the week. The request does not look like a cyberattack. It looks like work.
That is precisely why it is dangerous.
This story is a fictional example, but the situation is familiar to many growing businesses. Modern cybercrime rarely begins with dramatic code scrolling across a screen. It often begins with an ordinary email, a believable payment request, or a login page that looks almost identical to the real one.
Many business owners assume criminals are mainly interested in banks, telecommunications companies, and large international organizations. Those institutions certainly face attacks, but they also invest heavily in security teams, monitoring systems, access controls, and staff training.
A growing SME can present an easier opportunity.
The business may use Microsoft 365 or Gmail for every important conversation. Customer records might live in shared spreadsheets. Payments move through bank accounts and M-Pesa. Several employees may share a password because it feels convenient, while the person responsible for IT is also handling operations, procurement, or customer support.
To an attacker, this does not look like a small business. It looks like a connected network of email accounts, customer relationships, payment instructions, and valuable information—with fewer obstacles in the way.
Attackers do not always target the business with the most money. They often target the business where trust is easiest to imitate.
Imagine that Amina clicks the link in the supplier’s email. It opens what appears to be a Microsoft sign-in page. She enters her email address and password, but the page returns an error. She assumes the link is broken and continues with her day.
The attacker now has her password.
If multi-factor authentication is not enabled, the attacker may be able to enter her mailbox immediately. They do not have to act at once. They can quietly read conversations, learn how invoices are approved, identify the people who authorize payments, and observe which suppliers the company trusts.
When the timing is right, they can create a forwarding rule, hide warning emails, or reply inside a genuine conversation. The fraudulent request feels convincing because much of it is real. Only the destination of the money has changed.
This is known as business email compromise. It is effective because it attacks the company’s working relationships rather than only its computers.
Other attacks follow a similar path. A fake KRA notification can lead to a stolen login. A malicious attachment can install ransomware. A reused password from an unrelated website can unlock a company email account. A compromised mailbox can then expose social media pages, advertising accounts, cloud storage, and customer information.
One account becomes the doorway to the rest of the business.
Kenyan SMEs often succeed because they move quickly. Owners make decisions directly, teams communicate through WhatsApp, and employees solve problems without layers of approval. That speed is a competitive advantage—but attackers can turn it against the business.
Messages such as the director needs this now, the paybill has changed, or your account will be suspended today are designed to prevent reflection. The criminal wants the employee to react before verifying.
The answer is not to make every payment painfully slow. It is to introduce a second channel of trust. If bank details change, the finance team should call a known supplier number—not a number provided in the suspicious email. If a director requests an unusual payment on WhatsApp, another authorized person should confirm it. For significant transactions, two people should approve the release.
These small pauses can interrupt an attack without disrupting normal business.
Now imagine a different Monday morning. Employees switch on their computers and discover that shared files will not open. A message demands payment to restore them. The team feels reassured because files are “backed up”—until someone tries to restore the backup and discovers that it is incomplete, connected to the infected system, or has not run successfully for months.
A backup is only useful if the business can recover from it.
This is why cybersecurity is not simply about installing antivirus software. It is about keeping the organization operational when something goes wrong. A practical recovery plan should answer three questions: which information is essential, where a protected copy is stored, and who is responsible for restoring it.
Testing the recovery of one important folder can teach a business more than assuming an entire backup system works.
The fictional attack at the beginning did not require an enterprise security department to prevent it. Multi-factor authentication could have stopped the stolen password from being enough. A password manager could have prevented reuse. A phone call to the supplier’s known number could have exposed the changed payment details. A second approver could have questioned the urgency.
Most growing businesses can make meaningful progress in one month.
During the first week, secure identity: enable MFA on business email, banking, cloud storage, social accounts, and any system that contains customer information. Give every employee an individual account and review who still has administrator access.
In the second week, protect money movement. Document how new payment details are verified and decide which transactions require approval from two people. Make it acceptable for employees to question an urgent message, even when it appears to come from a director.
Use the third week to update work devices, phones, browsers, routers, and business applications. Remove old accounts and remote-access tools that are no longer needed. Updates are not glamorous, but they close known weaknesses that attackers routinely exploit.
In the fourth week, test recovery. Restore an important folder, confirm that critical information has a protected backup, and write a one-page incident plan. The plan should identify who can disable an account, contact the bank, notify customers, and coordinate technical recovery.
The goal is not perfect security. The goal is to make one stolen password, one hurried employee, or one infected device less capable of stopping the entire business.
As a company grows, informal controls become harder to manage. More employees create more accounts. New software introduces more connections. Customer information appears in more places, and payment processes involve more people.
If your organization processes payments, holds personal customer information, or depends heavily on email and cloud systems, a focused cybersecurity audit can identify the few weaknesses most likely to cause serious harm. A useful audit should not leave you with a frightening technical document and no direction. It should give you a prioritized, realistic plan based on how your team actually works.
AvaBerg provides practical cybersecurity services in Kenya, including Microsoft 365 hardening, email protection, staff awareness, and security reviews. For organizations that need continued assistance, managed IT support can help keep accounts, devices, updates, and recovery processes under control.
Cybersecurity becomes manageable when it moves from an IT problem to a business habit. Ask your team what happens when payment details change. Check whether every important account uses MFA. Find out when somebody last restored a backup. Make sure employees know whom to contact when a message feels unusual.
Hackers target Kenyan SMEs because ordinary business trust can be valuable—and because that trust is sometimes poorly protected. The good news is that a few thoughtful controls can change the odds significantly.
Do not wait for Amina’s Friday afternoon to happen in your business.
Book a security consultation or request a cybersecurity review for your Nairobi or Kenya-wide team.
Explore related services
Need help implementing this?
Our team helps Kenyan businesses with software, security, and IT every day.
A new employee, a shared password, and one unexpected payment request reveal how everyday habits shape an SME’s security—and how to improve them affordably.