When the 70 ghost accounts made the 260 withdrawals, the altered code automatically generated a standard, clean "Transaction Successful" status code back to the system dashboard.
The network of 70 accounts consisted primarily of "ghost" identities, cloned or fraudulently registered SIM cards using stolen ID numbers.
Since the logic change overwrote the core validation checks, the external network operator (MTN Rwanda) was fooled into paying out real cash out of the bank's float, even when those target account balances were empty.
The system never crashed, no security alarms went off, and no error logs were generated. To the bank's automated oversight systems, it simply looked like normal, heavy consumer mobile banking activity over the MTN Rwanda network.
The moment the reconciliation script threw a hard error, the bank’s risk team knew this was not a glitch. A routine weekly audit instantly turned into an active crime scene response.
The IT administrators immediately revoked all active third-party API tokens and vendor access credentials.
Engineers ran a forensic Git comparison to see exactly what lines of code had changed since the maintenance window began on June 6.
Once the system logs pointed directly to the unauthorized 5:33 AM code deployment by Ronford Digital Limited's employee, Evans Nandwa profile, the bank bypassed standard internal protocols and immediately called in the DCI Banking Fraud Investigation Unit (BFIU).
Because the digital access signature, the specific code repository credentials used to deploy the logic change, belonged directly to Nandwa, he was isolated by the bank and the DCI BFIU as the primary internal threat actor executing the technical side of the conspiracy.
Following the bank’s forensic audit report, detectives from the DCI Banking Fraud Investigations Unit (BFIU) tracked Nandwa down in Nairobi and placed him under arrest. He was arraigned before Milimani Law Courts Magistrate Benmark Ekhubi.
In banking and fintech cybersecurity, tech vendors and developers are routinely scheduled to push code updates, run migrations, and test integrations between 12:00 AM and 6:00 AM when customer traffic is at its absolute lowest.
Because banks process millions of commercial transactions during standard working hours (8:00 AM to 5:00 PM), making structural changes to a mobile money banking pipeline during the day risks freezing the system, dropping active user calls, and halting transactions.
On June 6, 2025, at around 5:30 A.M, NCBA Bank officially activated the vendor contract and granted a consultancy firm, Ronford Digital Limited's employee, Evans Nandwa, a live backend privileges to begin system maintenance and upgrades for its NCBA Rwanda subsidiary.
According to DCI Banking Fraud Investigation Unit (BFIU) court filings, at 5:33 AM, just three minutes after receiving live backend access, Nandwa altered the core application codebase.
He specifically manipulated the mobile integration logic governing the MTN mobile money network in Rwanda. Under his modified logic, whenever a withdrawal request hit the network, the system was forced to bypass validation checks entirely and automatically return a fake "Success" status code. This script was pre-programmed with 70 ghost account profiles.
The code was hardcoded with a highly specific filter that applied only to those exact 70 ghost accounts. If a withdrawal request came from any of the specific 70 ghost account numbers on Nandwa's list, the system would skip the balance check entirely, never looked at how much money they had, not to check if the account is fake, and instantly send a "Success" signal to MTN Rwanda.
By restricting the loophole to just those 70 accounts, the fraudsters achieved two critical goals: It ensured that only their pre-programmed script and automated wallets could siphon the money.
Two, random members of the public wouldn't accidentally discover the glitch and start withdrawing funds, which would have triggered immediate chaos and alerts.
For almost a week, the architectural flaw remained invisible. From June 6 until June 14, 2025, everything looked perfectly normal on the surface to NCBA Bank, as core systems reported standard operational metrics while the exploit quietly ran in the background.
Because the exploit was hidden deep inside the database queries, it was completely invisible to the daily operational dashboards. The bank only realized they had been shortchanged when the physical cash balances were tallied during the standard end-of-week settlement on June 14.
On June 14, NCBA's technical risk team performed a routine end-of-week settlement and reconciliation audit, and discovered a massive cash deficit of 57.5 million shillings that came from 70 ghost accounts, matching 260 transactions that were pushed through the Rwandan MTN mobile network.
In banking sector, an end-of-week reconciliation is a standard administrative process. The bank's systems automatically cross-reference two primary data sets; What the bank's internal database says customers withdrew, and What the telecom partner (MTN Rwanda) actually paid out in cash.
Normally, these two figures match down to the exact cent. However, on June 14, 2025, the automated script flagged a massive, irreconcilable deficit.
While the external telecom ledger showed that MTN Rwanda had successfully paid out Ksh 57.5 million to mobile money users, NCBA's internal deposit accounts showed no corresponding debit entries, fees, or even valid account holders for those transactions. The money had simply vanished into the mobile ecosystem through "ghost" approvals.
The exploit was designed to bypass system validation across the board. It cleared transactions for 70 ghost accounts that the system forced into a "success" state.
The Communications Authority of Kenya has opened a regulatory sandbox for tech developers.
The platform allows startups to test 5G, IoT and cybersecurity solutions in a controlled environment before applying for full market licences.
Reminder to go touch grass
A scientist in Japan demonstrated that the air inside a forest strengthens your immune system for a full month
The study is incredibly fascinating:
Qing Li, an immunologist at Nippon Medical School in Tokyo, took 12 men on a 3-day forest trip. These were slow walks with no breathing exercises and no set route.
Then he tested their blood and found a surge in natural killer cells -- the immune cells your body uses to fight cancer and virus-infected cells.
Remarkably, the effect didn't fade when they went home, it was still measurable 30 days later.
A control group that walked the same distance through a city showed no change at all.
Pine, cedar, and cypress trees release compounds called phytoncides to defend themselves from insects and bacteria. You breathe them in, and Li believes they switch your immune cells into high gear.
He estimates one forest walk a month may be enough to keep those cells elevated all year.
The best medicine might not even need a prescription -- just a walk among the trees.
KRA has introduced new critical rules for importers.
Starting today, 3rd August 2026, KRA has introduced a new import requirement for all sea cargo coming into Kenya.
If you import goods into Kenya by sea, there is a new system that you need to master.
It's called the Advance Cargo Declaration (ACD) System.
Every sea cargo destined for Kenya must be declared in this ACD system and have an ACD reference code before it leaves the exporting country.
Think of it as KRA saying: Before you send that cargo, tell me what it is you are bringing into Kenya. So I can prepare accordingly.
Here is how it works.
Before the goods are loaded onto the ship, the exporter logs into KRA's ACD system and uploads the following cargo documents:
• Draft Bill of Lading
• Commercial Invoice
• Freight Invoice
• Export Declaration
If everything is in order, KRA issues an ACD reference code.
That code must then be written on the final Bill of Lading.
Who is responsible for obtaining the ACD code?
The exporter or the shipper is responsible for obtaining the ACD code.
If you are importing from China, Mushaina, who is your seller & exporter, is responsible for obtaining the ACD code.
Every shipment gets its own unique ACD reference code. You cannot reuse an old one for another shipment.
KRA has reiterated that your freight forwarder is not allowed to obtain an ACD code for your cargo using their own account.
The Chinese exporter must apply to KRA for its own account. And submit it's company registration details, tax ID and contact details.
Shipping lines and carriers must also verify that the ACD code is valid. And ensure that it is correctly shown on the final Bill of Lading before the goods are loaded for Kenya.
Your responsibility as the Kenyan importer is to make sure that the ACD reference code has been obtained and added to the bill of lading.
Once the goods reach Mombasa port, your clearing agent shall use the same code to clear the goods.
Without a valid ACD reference, the cargo may face clearance delays, penalties, rejection, or even seizure.
KRA has stated the system is free for now. But can start charging in future.
Key takeaway.
Before your supplier loads the cargo, ask them:
- Have you obtained the ACD reference code and added it to the Bill of Lading?
Ensure your HR is a lawyer or at the very least has a solid grasp of Employment Law. Otherwise, one wrongful dismissal or unlawful HR decision and you'll be crying
kwikwikwi in court.
KRA tried to tax the same money twice.
There is a company called Equator Bottlers. They cook and sell sodas in Kisumu Dala.
I went there to apply for an attachment in April 2015.
Nikakaa kwa reception nimengojea waniulize nakunywaga soda gani. Wakaninyima. Imagine.
As Equator was busy cooking sodas. KRA was busy cooking their tax bill.
When KRA was done, what came out was a maddening tax bill.
Between 2019 and 2022, Equator hired technicians and IT gurus from South Africa to automate its soda making machines.
Equator paid them in full. They packed their bags and went back home.
Then KRA audited Equator. They looked at the payments and announced.
- Guys, you should have withheld tax before paying the South Africans. Instead, you let them carry all the money. Now what will Kenya eat?
You must now pay that money from your pockets.
Equator Bottlers fired back:
- True, we did not withhold tax.
But the South Africans have already paid tax on that income in South Africa.
If Kenya taxes the same income again, that would be double taxation. And Kenya and South Africa have a tax treaty that exists to stop exactly that.
KRA became even more firm: We tupatieni pesa. We want our taxes.
As the arguments intensified, shrewd accountants at Equator remembered one hidden sentence inside the Kenya–South Africa tax treaty.
It says:
- If a taxpayer believes the same income is being taxed in both countries, they can ask either country's tax authority to talk to the other country's tax authority and agree on who should tax it.
Think of it as. Nyinyi kaisari endeni muongee. Mkisikilizana mutaniambia nimlipe nani.
Equator quickly told the South African suppliers to approach the South African Revenue Service (SARS). And complain about double taxation.
They did. And SARS agreed there was a genuine issue and formally opened discussions with KRA.
But while the two tax authorities were talking, KRA sent a maddening tax demand to Equator.
Equator ran to court. It argued that,
- KRA was at the talking stage with SARS.
- KRA should first complete the discussions with SARS, decide which country had the right to tax the income, and only then demand tax, if any was still payable.
- Equator prayed the court to pause the case until the two revenue authorities reached an agreement.
KRA fired back and argued that:
- Equator was simply buying time and delaying the case.
- KRA also argued that Equator, as the taxpayer, should have approached KRA directly to initiate the Mutual Agreement Procedure instead of going through its South African supplier.
- For that reason, KRA urged the court not to pause but proceed with the case and deliver its judgment.
The tax tribunal looked at the case. And noted that,
- a genuine Mutual Agreement Procedure was already underway because KRA had agreed and started talking to SARS.
The Tribunal paused the case and ruled that:
- Equator & KRA and SARS should continue talking under the Mutual Agreement Procedure for the next four months.
If they agree, well and good.
If they do not agree, the matter will go for full court hearing and judgement.
Lessons.
• Kenya's tax treaties are real. If you're facing double taxation, use them.
• The Mutual Agreement Procedure is simply two tax authorities talking so the taxpayer doesn't pay tax twice.
• Structure your cross border payments carefully. Or KRA will structure them for you.
I know how powerful family trusts are in Kenya.
They give one immense assets protection and tax benefits.
But if you are in your sunset years and you have responsible children,
Why lock your wealth in a family trust and dispense it to them kidogo kidogo like medicine?
That they can only access money for healthcare, education, dowry, and other approved purposes.
If your children are irresponsible, it is completely understandable. You are preserving the wealth for your grandchildren.
But if they are responsible, why not transfer the wealth to them directly and let them manage it as they see fit?
What am I missing?
Junet Mohamed, you have just confirmed what millions of Kenyans have believed for years: Parliament has become the weakest link in Kenya's democracy.
You openly boast that MPs were "paid" during a constitutional process, as though bribery is something to celebrate. That is the public humiliation of Parliament.
The National Assembly was created to defend the Constitution, hold the Executive to account and represent the people. Instead, it has been reduced to an auction house where loyalty is traded, conscience is sold and constitutional duty comes with a price tag.
Your words are an indictment not just of yourself, but of an institution that has lost the confidence of the people. Parliament is no longer feared by the Executive because too many MPs have chosen to become its employees instead of its watchdogs.
While such admissions are made in broad daylight, the anti-corruption agencies remain conspicuously silent. That silence is just as damning.
I see lots of people here complain about difficulties working for 'Muhindi'.
So it is proper to talk about my experience with Patel.
Patel an old 'muhindi' had a house and lived at Parklands opposite MP Shah Hospital where we used to keep beehives.
Those hives used to be very productive, and so he decided to buy hives for his employees.
One time we delivered hives to his branch in Kitui.
What surprised me is that Patel knew the village homes of most of his employees.
He personally drove us to the village and I was shocked to see him greet each of the kids by name.
He knew every kid mpaka the class they were. Each of the 4 kids presented their school report cards... and there was no pretence.. genuine concern.
One kid was unwell. You could sense the deep sympathy and concern.
He had about 12 machinery shops all over Kenya. We visited three and same thing repeated.
He once visited my place in Riruta, (remember the beekeeping project and the Chief?)...
Sikua namjua then, we ate rice and half cooked cabbages. Later, I came to know the old man was a millionare.
Kumbe he used to personally pay school fees for his employee's kids!
He is now retired but we still chat.
People can decide to be reasonable, no matter their race, color or status.
The Court of Appeal had held thay You can't keep someone working for years, call them a casual and then deny them permanent employment rights.
The Court of Appeal has made it clear, the law looks at the reality of the job, not the label on the contract.
If you're doing permanent work on endless short-term or "casual" contracts, you may already be entitled to the rights of a permanent employee.
The era of exploiting workers through fake casual contracts has come to an end.
In 2015 Lenovo shipped laptops with software that broke HTTPS for every user.
Installed deliberately for ad revenue.
Lenovo pre-installed a piece of adware called Superfish on consumer laptops starting September 2014. Its purpose was to scan every image you view on the internet and inject ads for similar products.
To do that on HTTPS pages, it needed to intercept your encrypted traffic.
So it did something catastrophic.
it installed itself as a trusted root certificate authority on your laptop. Meaning your browser treated Superfish as a trusted source of certificates, the same level of trust as VeriSign, DigiCert, or your bank's own certificate authority.
Everything you did over HTTPS- banking, email. shopping. medical records was being decrypted by Superfish, analyzed for images, and re-encrypted before it reached you.
then it got worse.
Every Lenovo laptop shipped with the exact same certificate and the exact same private key.
The password protecting that private key was cracked in three hours by Security researcher, Rob Graham (Errata Security).
The password was "komodia."
The name of the Israeli company that made the code.
Once cracked, anyone with that private key could impersonate any website to any Lenovo user on earth. your bank. your email. any HTTPS site. a fake page would show a valid padlock and your browser would trust it completely.
Lenovo's initial response: "we have thoroughly investigated this technology and do not find any evidence to substantiate security concerns."
Then the password was posted publicly online.
Lenovo paid $7.3 million to settle the class action lawsuit.
The EFF called it "catastrophically irresponsible."
Crazy stuff.
Idris Elba says he was given one warning before auditioning for The Wire: don’t let them know you’re British.
Trevor Noah: “I’ve seen people get shocked when they find out you’re not American.”
Idris Elba: “I was unemployed, bro.”
“I was living in New Jersey. I was bartending, working the door, DJing.”
“Before you know it, you just start speaking like an American.”
“Then my casting director said, ‘This thing has come up. It’s called The Wire.’”
“‘But if you go in, you cannot let them know you aren’t American.’”
“‘This is about Baltimore. It’s very specific.’”
“So I auditioned for four weeks straight in an American accent.”
“Then at the fourth audition, they looked at me and said…”
“‘Idris… where are you from?’”
Trevor Noah: “‘Where are you from?’ That’s the phrase every immigrant is terrified of hearing.”
Idris Elba: “My palms started sweating.”
“I’m thinking… they told you not to say anything.”
“I looked at them and said…”
“‘I’m from East London.’”
“The room just exploded.”
“‘Oh my God… we had a bet.’”
“‘We knew you weren’t from Baltimore or Brooklyn, but we never guessed England.’”
“‘You got the job.’”
“‘We don’t want you to play Avon.”
“We want you to play Stringer Bell.’”
“I walked out thinking…”
“‘Did my life just change?’”
🚨 BREAKING: The government has entered full gaslighting mode.
Aden Duale says President Ruto is being hated because he has brought development to Kenya.
Think about what that means.
The public anger over police brutality, abductions, a struggling healthcare system, rising electricity costs, higher taxes, and an unbearable cost of living is being dismissed as nothing more than "hatred for development."
According to Duale, you should be deeply in love with this regime for:
🔹 The "Development" of Pain: Burying, abducting, and harming young Kenyans whose only crime was demanding accountability and a better future.
🔹 The Luxury vs. Lean Budget: Giving students just 95 KSH per term while billions are spent on travel, hospitality, and luxury.
🔹 The Healthcare Collapse: Forcing a troubled SHA/SHIF transition on citizens while insisting everything is working perfectly.
🔹 Economic "Progress": Higher taxes, expensive electricity, a rising cost of living, and families struggling to make ends meet.
In other words, Duale's message is simple:
"We are serving you pain, and you should be grateful for it."
In 1990,Kenya shilling collapsed, crashing from 30 KSh per US dollar to over 70 KSh per US dollar by 1994. It was caused by Koinange (Jeff's uncle), Pattni and Kanyotu, together,they swindled the government 10% of GDP(about 1.3 trillion today), it would be later known as.....