BettingBusinessCourtsCrime WatchEntertainmentEntertainmentHomeIn-Depth NewsIn-Depth News and InvestigationsMain StoryNational NewsNewsPoliticsSportsSports HighlightsTechTechnology

How Safaricom ‘allowed’ illegal sharing of 11.5 million subscribers’ private data

The court heard that the breach was a systemic breach and failure by Safaricom to put in any safeguards, warrants the intervention of the court

Kenya’s largest telecommunications firm, Safaricom PLC, is facing a fresh legal challenge over allegations that it unlawfully shared the personal data of more than 11.5 million subscribers, exposing them to serious privacy and security risks when confidential data belonging to 11.5 million subscribers were stolen by its former employees and shared with betting firms.

How Safaricom ‘allowed’ illegal sharing of 11.5 million subscribers’ private data.

Eleven petitioners, led by Augustine Onalo, have moved to the High Court seeking conservatory orders to bar the telco from further sharing, transferring, or disseminating subscriber data pending the determination of their constitutional petition.

Appearing before Bahati Mwamuye, the group argued that they only recently discovered that their data may have been compromised in 2019, when confidential subscriber information was allegedly accessed by former Safaricom employees and shared with betting firms over an extended period.

However, the court declined to issue interim orders, noting that two similar cases are already pending before the High Court, alongside a related criminal case.

Justice Mwamuye directed that the matter proceed after hearing from all parties and clarifying the status of the existing proceedings.

Through their lawyer, the petitioners argued that the alleged breach persisted for more than 11 months and stemmed from systemic failures within Safaricom’s data protection systems. They claimed the company failed to implement adequate safeguards to secure sensitive customer information.

Court filings indicate that the data allegedly accessed included identity details, financial activity, device information, geolocation, and betting behaviour.

The petitioners say the exposure of such information subjected them to stigma, reputational damage, and psychological distress.

One of the petitioners, Austine Musungu, told the court that he was an active punter before May 2019 and later discovered that his personal and betting data had allegedly been included in the leaked dataset without his consent.

See also  No African Head of State made the cut in Trump's inauguration guest list

The group contends that the alleged actions violate constitutional rights to dignity, privacy, and consumer protection under Articles 28, 31, and 46, arguing that Safaricom breached its duty as a custodian of sensitive personal data.

The eleven led by Onalo had urged the court to issue conservatory orders, stopping Safaricom and its employees from further sharing of their personal data.

How Safaricom ‘allowed’ illegal sharing of 11.5 million subscribers’ private data.

On Thursday, April 16, 2026, the petitioners through their lawyer submitted that the breach happened for a sustained period of more than 11 months and Safaricom did not do anything to safeguard the data.

The court heard that the breach was a systemic breach and failure by Safaricom to put in any safeguards warrants the intervention of the court.

The petitioners added that Safaricom had in fact admitted that the persons who accessed the data were allowed to do so by the telco.

Safaricom opposed the application and submitted that the petitioners were aware of the three other cases and the fact that they had been suspended by the court.

The telco said there is an injunction preventing the publishing of the data. Further, some of the petitioners had sought to join the cases pending before the court but were denied.

According to Safaricom, the petitioners were seeking the same orders that have been prayed in the pending cases.

In the cases pending before the court, Safaricom claimed that two of its former senior managers and another man illegally accessed confidential customer data belonging to 11.5 million subscribers.

The data was nearly sold to a sports betting company before they were arrested and charged.

See also  2022 crash programme to resume

The telco alleges that the massive confidential data was obtained from its servers.

“Pending the hearing and determination of the petition, a conservatory order be issued retraining Safaricom, and its servants from sharing, transferring or disseminating their personal data or those of the 11.5 million subscribers’ data, obtained in 2019 without lawful order of the court,” the petitioners submitted.

In an affidavit, Austine Musungu said the nature of the disclosed information included the behaviour, financial activity, device identity, and geolocation data, all of which constituted deeply personal and socially sensitive material.

The disclosure, he said, exposed them to stigma, social embarrassment, reputational injury and psychological vulnerability.

Musungu said he was an active punter before May 2019 with various betting firms where they deposited money to their betting accounts.

The sim cards they held had their private information including their identity numbers, passport numbers, and certificate of incorporation numbers, among others.

The data also included information the amount spent by each subscriber, the number of betting companies, number of pay-ins, latest bet and their location.

They said that they learnt last year that in May 2019, Safaricom extracted the information of over 11.5 million subscribers and shared it with third parties.

They said the telco admitted the breach and instituted a civil case, and pursued criminal proceedings against its former officials.

“The petitioners aver that at no point did they give consent for their data to be released to the public and indeed, there is no valid court order or otherwise sanctioning the release,” he said.

The petitioners argued that the telco violated their rights and the rights of over 11.5 million punters under Articles 28, 31(c) and (d) and 46 of the constitution.

See also  Uhuru remarks on handshake trigger storm in Jubilee

They want compensation for damages for alleged violation of their rights to privacy, dignity, and consumer protection.

The petitioners further aver that Safaricom stood in a position of constitutional trust as custodian and controller of intimate subscriber data and exercised immense technological and informational power over millions of citizens, which trust it chose to breach.

“By harvesting and disseminating their personal and behavioural data without their consent or lawful authority, the company fundamentally breached that constitutional trust, abused informational dominance and undermined their dignity and legitimate expectation of confidentiality in communications,” he said.

They contended that gambling activity on the Kenyan social context often carries moral judgment and familial consequences and the involuntary exposure of such data therefore, inflicted harm far beyond pecuniary loss.

Other than conservatory orders, the petitioners want their case consolidated with matter pending before the court.

In response, Safaricom opposed the application, stating that the issues raised are already the subject of ongoing cases, some of which are currently suspended.

Safaricom further said that an existing court order bars the publication or dissemination of the disputed data.

The telco maintains that the breach was the work of two former senior managers and another individual who allegedly accessed subscriber data illegally with the intent to sell it to a betting firm and criminal proceedings have already been instituted against the suspects.

The petitioners are seeking compensation for alleged violations of their rights and have asked the court to consolidate their case with the existing matters.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button