Starting Friday, August 14, 2026, a Kenyan walking into a cyber café to print a form or check email will need to hand over their name and national ID number before they can log on. The Communications Authority of Kenya (CA) has finalised licensing conditions requiring cyber café operators to register every customer, tie each session to a specific terminal, and retain those records for three years, all in the name of fighting cybercrime.
The justification is not manufactured. The CA cites 3.37 billion cyber threat events detected by the National KE-CIRT/CC in the first quarter of 2026 alone, and cybercrime losses estimated at KSh 29.9 billion in the 2024/2025 period, according to the Africa Cybersecurity Report. Those numbers are real and the underlying concern, that Kenya's digital economy has expanded faster than its ability to police it, is legitimate. The question worth asking is narrower: does identity registration at cyber cafés actually address where that threat is coming from?
A Shrinking Target, By CA's Own Numbers
The rule targets a segment of internet access that is already marginal. CA's own Audience Measurement and Industry Trends survey for the quarter ending December 2025 found that 97.9 percent of Kenyan internet users go online via smartphone, while only 0.9 percent use a desktop computer, the category cyber cafés fall into. That is not a rounding error; it is close to the entire market having already moved elsewhere.
None of this makes the rule irrelevant. Rural residents, people without smartphones or reliable data, and anyone needing eCitizen services, job applications, or document scanning still depend on cafés as their access point. But it does mean the rule is aimed at a shrinking, low-resource corner of the internet economy, not the parts driving the bulk of Kenya's recorded cybercrime activity.
Where the Threat Data Actually Points
Look at what KE-CIRT/CC's Q1 2026 figures actually break down into: system attacks accounted for more than 3.23 billion of the 3.37 billion recorded incidents, with malware, brute-force attempts, web application attacks and distributed denial-of-service activity all rising. Separately, an INTERPOL assessment found Kenyans lost an estimated KSh 491.6 million to SIM-swap fraud in 2025, a 327 percent increase in cases, with more than 123,000 fraudulent SIM cards linked to criminal activity.
None of these attack categories describe what happens on a shared desktop running outdated software in a neighbourhood shop. System attacks, brute-force campaigns and DDoS activity require sustained bandwidth, scripting environments, and infrastructure that can be spun up, torn down and rotated quickly, exactly the profile cyber cafés don't offer. SIM-swap fraud runs through telecom systems and agent networks, not shared PCs.
Security research on how these attacks are actually staged bears this out. Cybersecurity firm Darktrace documented a 2025 campaign in which attackers rented Virtual Private Servers for as little as five dollars to hijack business email accounts, riding live sessions rather than just stealing passwords, specifically because cheap VPS hosting gives them a clean IP address that blends in with legitimate traffic. Separate research into so-called "bulletproof hosting" providers found dedicated infrastructure for phishing and scam sites available for as little as fifteen dollars a month, offering exactly the anonymity, uptime and geographic flexibility that a public terminal, bound to one physical location and one shared network, cannot match. If the goal is masking origin while running a sustained, resourced operation, a VPS in another country beats a cyber café in Nairobi on every metric that matters: bandwidth, uptime, tooling and the ability to disappear.
That leaves a narrower category of crime where the café rule genuinely applies: low-skill, walk-in fraud where a criminal simply wants a computer that isn't traceable back to their own device, filing a fraudulent loan application, forging a document, or logging into a stolen account without leaving a personal digital fingerprint. Cafés have functioned as a soft spot precisely because they sit outside the identity checks that already apply to SIM cards and mobile money accounts. That is a real gap. It is also a much smaller gap than the billions of system-level incidents the CA cites to justify the rule.
A Log Without Verification Solves Half a Problem
Even within that narrower category, the rule's design has a structural weakness. The CA's finalised conditions require operators to log a customer's name and ID number, but there is no requirement to verify that the ID belongs to the person presenting it, no document scan, no biometric check, nothing beyond what a customer states or a physical card shows at the counter. The earlier draft of these rules, published in December 2024, included mandatory CCTV surveillance, which would have given operators a way to independently confirm who used a given terminal. That requirement was dropped in the final version issued this month.
What remains is a paper log without a verification layer behind it. Anyone using a stolen, borrowed or fabricated ID number would be recorded under someone else's name, and the person whose identity was used has no independent record, no camera footage, no biometric trail, to contest that entry months or years later within the three-year retention window the rule requires. A log that can be filled with any name a customer chooses to give is attribution in form only.
The Rule Creates a New Data Liability
There is also a cost the rule introduces rather than solves. Our review of the requirement flagged that Kenya's Data Protection Act of 2019 already obligates anyone processing personal data, including small cyber café operators, to secure it properly and avoid holding more than necessary. The Office of the Data Protection Commissioner has issued real fines under that law, including penalties up to five million shillings or one percent of annual turnover. A three-year archive of customer names and ID numbers sitting on a single-operator café's back-office computer, with none of the security budget a bank or telco can deploy, is precisely the kind of dataset that law was designed to protect and precisely the kind of dataset likely to go unsecured in practice. National compliance surveys have found that while most Kenyan businesses know the Data Protection Act exists, a large share have not appointed anyone to actually manage compliance with it.
In other words, the rule meant to close a fraud gap may open a second one: concentrated identity records held by operators least equipped to protect them, with penalties for breaching the CA's licence conditions (0.2 percent of turnover, KSh 500,000 minimum) but no parallel enforcement mechanism ensuring the data itself is kept safe.
What a More Targeted Rule Might Look Like
None of this means the CA should have left cyber café licensing untouched. The instinct behind the rule, closing an anonymity gap that has genuinely been exploited for document forgery and low-skill fraud, is defensible. But a narrower rule would better match the actual risk: identity verification (not just self-reported registration) for the specific transaction types most linked to fraud, such as government service applications or financial transactions conducted from a café terminal, paired with minimum data-security standards for operators holding that information, rather than blanket registration for every printing or browsing session regardless of what it's used for.
As written, the rule adds a real compliance cost, technical filtering systems, registration infrastructure, three-year secure storage, to a sector CA's own data shows is down to under one percent of how Kenyans access the internet, in pursuit of a threat category that its own incident data suggests is concentrated somewhere else entirely.
Comments