• About
  • Advertise
  • Careers
  • Contact Us
Thursday, July 17, 2025
  • Login
No Result
View All Result
NEWSLETTER
Tech | Business | Economy
  • News
  • Tech
    • DisruptiveTECH
    • ConsumerTech
    • How To
    • TechTAINMENT
  • Business
    • Telecoms
    • Mobility
    • Environment
    • Travel
    • StartUPs
      • Chidiverse
    • TE Insights
    • Security
  • Partners
  • Economy
    • Finance
    • Fintech
    • Digital Assets
    • Personal Finance
    • Insurance
  • Features
    • IndustryINFLUENCERS
    • Guest Writer
    • EventDIARY
    • Editorial
    • Appointment
  • TECHECONOMY TV
  • Apply
  • TBS
  • BusinesSENSE For SMEs
  • Chidiverse
  • News
  • Tech
    • DisruptiveTECH
    • ConsumerTech
    • How To
    • TechTAINMENT
  • Business
    • Telecoms
    • Mobility
    • Environment
    • Travel
    • StartUPs
      • Chidiverse
    • TE Insights
    • Security
  • Partners
  • Economy
    • Finance
    • Fintech
    • Digital Assets
    • Personal Finance
    • Insurance
  • Features
    • IndustryINFLUENCERS
    • Guest Writer
    • EventDIARY
    • Editorial
    • Appointment
  • TECHECONOMY TV
  • Apply
  • TBS
  • BusinesSENSE For SMEs
  • Chidiverse
No Result
View All Result
Tech | Business | Economy
No Result
View All Result
Home Business Telecoms

Safaricom Shuts Down Six-Year Internet Theft Loophole After Millions Lost

by Joan Aimuengheuwa
July 16, 2025
in Telecoms
0
Safaricom Shuts Down Six-Year Internet Theft
Safaricom

Safaricom

UBA
Advertisements

Safaricom has finally resolved a deep-rooted security flaw in its Home Fibre network that allowed internet theft for nearly six years. 

The breach, tied to outdated authentication protocols, reportedly drained the company of tens of millions of Kenyan shillings before it was closed in 2024.

According to two engineers directly involved, the vulnerability arose from Safaricom’s use of a Point-to-Point Protocol over Ethernet (PPPoE) system that assigned unique usernames but permitted a single, generic password across all accounts.

“People would often use someone’s account number as the username and apply the general password,” one engineer revealed, speaking anonymously to TechCabal.

This loophole, known to insiders for years, allowed thousands of users to bypass Safaricom’s official billing. In many instances, outsourced sales agents facilitated the fraud, accepting informal payments as low as KES 1,000 to reset routers and input fresh credentials. 

This restored internet services without routing payments through official Safaricom channels. Monthly charges for legitimate fibre packages typically ranged from KES 2,999 to KES 20,000.

The breach reveals huge gaps in Safaricom’s internal security. Although the company tops Kenya’s fixed internet market, holding a 36.5% market share with over 678,000 subscribers, it failed to promptly address backend weaknesses linked to legacy infrastructure. 

Engineers disclosed that fixing the problem required fundamental backend changes, not simple software patches. “This wasn’t something you could patch with one update,” said another source familiar with the system.

Insiders claim the vulnerability continued partly because addressing it risked disrupting ongoing expansion efforts. Between early 2024 and Q1 2025 alone, Safaricom added over 56,000 new connections, intensifying operational pressure.

By 2024, however, decisive changes were enforced: every Home Fibre account now carries unique, complex passwords, and session management protocols have been tightened to restrict accounts to a single active session at any given time.

“If one were to somehow get hold of the username and password, they would still not be able to use it as only one session is allowed,” an engineer confirmed.

Safaricom has not disclosed the financial damage, but internal estimates suggest tens of millions of shillings were lost. The company did not respond to direct requests for comment.

This incident stresses the risks across African broadband markets, where aggressive network expansion usually outpaces cybersecurity upgrades.

The flaws in Safaricom’s system show challenges faced by providers globally who rely on outdated PPPoE systems without upgrading to more secure authentication methods like MAC-based or certificate-based access.

At the recent Connected Africa Summit 2025, Safaricom itself acknowledged sector-wide risks, advocating for shared infrastructure models to cut deployment costs and enhance oversight.

Loading

Advertisements
MTN ADS

Author

  • Joan Aimuengheuwa
    Joan Aimuengheuwa

    Joan thrives at helping individuals and businesses scale via storytelling...

    View all posts
0Shares
Tags: broadband securitycybersecurity breachfibre broadband fraudHome Fibreinternet theftISP revenue leakKenya internet providersnetwork loopholePPPoE vulnerabilityrouter reset fraudSafaricomSafaricom Internet TheftSafaricom market shareSafaricom password fixSafaricom revenue loss
Joan Aimuengheuwa

Joan Aimuengheuwa

Joan thrives at helping individuals and businesses scale via storytelling...

Next Post
Let’s unpack the top financial lessons from billionaires and business icons, so you can learn from their wins and build your financial freedom.

Top 7 Financial Lessons From Successful People

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Recommended

Governor Charles Soludo of Anambra State

Digitalization: Anambra to Hold Inaugural Hybrid ICT Stakeholders Workshop

2 years ago

NDPB, FCCPC Sign MoU on Consumer Rights, Data Protection

3 years ago

Popular News

    Connect with us

    • About
    • Advertise
    • Careers
    • Contact Us

    © 2025 TECHECONOMY.

    No Result
    View All Result
    • News
    • Tech
      • DisruptiveTECH
      • ConsumerTech
      • How To
      • TechTAINMENT
    • Business
      • Telecoms
      • Mobility
      • Environment
      • Travel
      • StartUPs
        • Chidiverse
      • TE Insights
      • Security
    • Partners
    • Economy
      • Finance
      • Fintech
      • Digital Assets
      • Personal Finance
      • Insurance
    • Features
      • IndustryINFLUENCERS
      • Guest Writer
      • EventDIARY
      • Editorial
      • Appointment
    • TECHECONOMY TV
    • Apply
    • TBS
    • BusinesSENSE For SMEs

    © 2025 TECHECONOMY.

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In
    Translate »
    This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.