guides

How to Check Which Numbers Are Registered to Your ID, and Why You Should Do It Carefully

How to Check Which Numbers Are Registered to Your ID, and Why You Should Do It Carefully
Image Credit: Safaricom PLC

Every SIM card in Kenya is tied to a national ID or equivalent document, a rule meant to make phone numbers traceable and mobile money accounts harder to hijack. In practice, that same registration system has become one of the first places fraudsters look for a foothold, and it is also where an ordinary subscriber can accidentally lock themselves out of their own internet connection while trying to check for fraud.

That contradiction sits at the centre of a growing conversation in Kenya about who holds a subscriber's personal details, how those details move between businesses, telcos and agents, and what happens when a number nobody recognises turns up registered under a person's identity.

Why This Matters Now

Kenya's exposure to identity-linked fraud has widened sharply. INTERPOL's African Cyberthreat Assessment Report 2026 recorded a 327 percent jump in SIM-swap fraud investigations in Kenya during 2025, with more than 123,000 fraudulent SIM cards uncovered, most of them used to hijack mobile money accounts. The same report estimates that SIM-swap fraud drained roughly 491.6 million shillings, about 3.8 million US dollars, from mobile wallets over the year.

The Communications Authority of Kenya's own complaints data tracks the same trend from a different angle. Quarterly consumer complaints reviewed by the regulator show fraud evolving beyond traditional scam calls and texts into phishing, impersonation, fake promotions, social engineering, fraudulent mobile money transactions and online marketplace scams. Separate reporting citing CA figures for the first half of 2026 puts recorded SIM-swap cases at 1,240, alongside a sharp rise in banking-sector fraud losses over the same period.

A SIM swap is not a technical exploit in the traditional sense. It relies on convincing a telco or an agent that the fraudster is the legitimate subscriber, after which the victim's number, and every one-time password that number receives, moves to a SIM card the fraudster controls. A recent Machakos High Court ruling illustrates how costly this has become for the institutions involved: Safaricom and Diamond Trust Bank were ordered to jointly cover 4.4 million shillings stolen from a customer after her line was fraudulently swapped in 2022, with the court rejecting the banks' longstanding defence that a correctly entered PIN was proof the transactions were authorised. Justice Asenath Ongeri held that a bank cannot rely on a customer's PIN when confronted with a pattern of transactions that should have triggered scrutiny, and that permitting the swap in the first place was a direct cause of the loss.

Where Your Details Actually Leak From

Fraud of this kind depends on fraudsters first getting hold of a name, ID number and phone number that match. Several everyday, mostly legal, touchpoints supply exactly that combination.

Retail and hospitality outlets capture a customer's phone number the moment a Lipa na M-Pesa transaction goes through, then reuse it for marketing without separately asking permission. Kenya's Data Protection Act treats this as unlawful, and the Office of the Data Protection Commissioner has been enforcing it. In February 2026, the regulator ordered CJ's Limited, the company behind the Café Javas restaurant chain, to pay 75,000 shillings to a customer, Steve Onwonga Omwenga, after he received three unsolicited promotional SMS messages advertising delivery services in September 2025. The Data Commissioner determined that CJ's had processed the complainant's mobile phone number for marketing purposes without establishing a lawful basis as required under the Data Protection Act, and the company had continued sending messages even after Omwenga objected directly.

That case was not isolated. A similar ruling the previous year fined Pepinos Pizza Inn 250,000 shillings for the same conduct, after the company argued unsuccessfully that consent obtained during an M-Pesa payment transaction also covered marketing use. The regulator rejected that argument outright, establishing what is now treated as settled principle: consent for payment processing does not equal consent for marketing, and data collected for one purpose cannot be repurposed for another without permission. Nairobi City Water has separately been fined 250,000 shillings for a related data-handling failure, sending repeated payment demands over a non-existent bill tied to outdated customer records.

Mobile money agents represent a second, less regulated leak point. Cash deposits and withdrawals routinely require an agent to see or record a customer's ID and phone number, and unlike a corporate marketing database, that information often sits in handwritten logs or informal spreadsheets with no consistent security standard. The Communications Authority's new licensing rules for public communications access centres, which took effect on 14 August 2026, attempt to address a parallel problem in cyber cafes by requiring operators to issue receipts for every transaction and retain customer records for a minimum of three years, with basic user logs covering terminal ID and session times, records the regulator can demand during an investigation.

Mobile money transaction messages themselves have also functioned as an unintentional data broker. Every M-Pesa payment historically displayed the sender's phone number to the recipient, a detail that could be saved, shared or sold to actors involved in SIM swap fraud. That specific exposure is now being addressed at the regulatory level. The Central Bank of Kenya has approved a Safaricom request to mask phone numbers in peer-to-peer M-Pesa transfers, so that recipients who want to see a sender's full number will need to request it, and the sender can consent or decline.

Checking Your Own Registration, Without the Detour

Because SIM registration in Kenya is tied to national ID, both Safaricom and Airtel allow subscribers to check which lines are registered against their identity document. Dialling *106# returns a menu that, after selecting the ID verification option and entering the relevant document number, triggers an SMS listing every active line registered to that identity. A second code, *100*100#, lets a subscriber flag their line against unauthorised swaps, adding a layer of protection before a fraudulent request even reaches a customer service agent.

The check is straightforward. The judgment call that follows it is less so. Safaricom's fixed Home Fibre service is typically billed against a fixed account number rather than a mobile line, but its 4G and 5G Wireless Home Internet routers work differently: they connect using a physical SIM card or an embedded SIM profile, which means each router is assigned a standard mobile number, in the familiar 07xx or 01xx format, just like a phone line. That is why a router can show up on a *106# list looking exactly like an unfamiliar personal number, even though it has never been used to make a call or send a text. A number appearing on the list that a subscriber does not immediately recognise is not automatically evidence of fraud. It may simply be the line quietly running a home router, a postpaid data plan, or a service opened months earlier and forgotten.

Deregistering that number through the same USSD menu takes effect immediately and disconnects whatever service depends on it. That deregistration request must originate from the verified anchor line, the primary number tied to the subscriber's ID, and cannot be triggered from a secondary or newly discovered line on the list. The restriction is a deliberate security feature: it stops a rogue secondary SIM, whether fraudulently registered or compromised, from being used to deregister a victim's primary number and lock them out of their own line. It does not, however, prevent a subscriber from mistakenly deregistering a legitimate secondary service, such as a router, from their own primary number. Reactivating it is not instant. Once a line has been deregistered, Safaricom places it into a cooling-off period, and customer care agents have told affected subscribers they cannot process reactivation until roughly six hours have passed, regardless of how the deregistration happened or how quickly the customer noticed the mistake. For a household relying on that line for home internet, the practical result is several hours without connectivity while the safeguard designed to prevent SIM swap fraud runs its course.

What a Careful Check Looks Like

Security practitioners and consumer advocates covering Kenya's fraud landscape generally recommend a sequence rather than a single action:

  • Audit: Dial *106#, select the ID verification option, and note down every masked or full MSISDN returned against your identity document.

  • Identify device SIMs: Before flagging an unfamiliar number, check router stickers, tracker units, alarm systems, or postpaid contracts that may already account for it.

  • Lock, don't just delete: Dial *100*100# to flag verified lines against unauthorised swaps, rather than treating deregistration as the default response to anything unrecognised.

  • Report through verified channels: Escalate genuinely unverified numbers through official customer care, on 100 or 400, or forward suspicious messages to short code 333, rather than resolving uncertainty by unilaterally cutting a line.

The underlying risk that makes this check worth doing has not gone away. Once a fraudster controls a subscriber's number, whether through a manipulated SIM swap at an agent outlet or a fraudulently registered line, they can intercept the one-time passwords banks and mobile lenders rely on, open loan app accounts in the victim's name, and move funds out of linked bank accounts before the subscriber notices anything is wrong. The Machakos ruling against Safaricom and DTB shows courts are increasingly willing to hold institutions financially accountable when that chain of failures plays out. It does not, however, undo the damage once it has happened, which is why regulators and telcos alike keep pointing subscribers back to the same starting point: know what is registered under your identity, verify before you act, and treat an unfamiliar number as a question to answer rather than a switch to flip.

Sandra Safari
ABOUT THE AUTHOR

Sandra Safari

Software Staff Writer,Sandra Safari serves a unique dual role at TechInKenya as both a Software Engineer and a Tech Journalist. Operating at the intersection of infrastructure engineering and media, s...see full bio

Weekly Tech Digest

Join the community getting the best Kenyan tech news delivered every Friday.

Comments

to join the discussion.