Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Safaricom PLC

Safaricom PLC Vendor Cyber Rating & Cyber Score

safaricom.co.ke

Safaricom is the leading provider of converged communication solutions in Kenya. In addition to providing a broad range of first-class products and services for Telephony, Broadband Internet and Financial services, Safaricom seeks to uplift the welfare of Kenyans through value-added services and support for community projects. With over 29 Million subscribers and an estimated market share of 67%, the Company has the widest modern mobile network coverage in Kenya and prides in its experienced shareholders, attractive tariffs, a nationwide network of effective dealers, high caliber staff and management enabling it to maintain its position as the region’s mobile market leader. M-PESA has over 23 million subscribers, supported by a


Safaricom PLC A.I CyberSecurity Scoring

Safaricom PLC
Company Information
Website:http://safaricom.co.ke/
Employees number:17,457
Number of followers:579,204
NAICS:517
Industry Type:Telecommunications
Homepage:safaricom.co.ke
Safaricom PLC Risk Score (AI oriented)
Between 700 and 749
logo
Safaricom PLCTelecommunications
Updated:
13/09/2026
728/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Safaricom PLC Global Score (TPRM)
xxxx
logo
Safaricom PLCTelecommunications
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Safaricom PLCModerate
Current Score
728Ba (MODERATE)
01000
2 incidents
-53 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
728Before Incident
AUGUST 2026
778Before Incident
Breach
06 Aug 2026Safaricom PLC
Safaricom: Court upholds sacking of Safaricom manager over data leaks

Safaricom Data Breach Involving Former Executive Brian Njoroge Wamatu

725After Incident
CRITICAL-53
SAF1786084206
Safaricom Wins Court Battle Over Former Executive’s Dismissal for Data Breach The Employment and Labour Relations Court has upheld Safaricom’s decision to dismiss Brian Njoroge Wamatu, its former Head of Regional Expansion, following allegations of unauthorized access and sharing of confidential company and customer data. The court ruled that Safaricom had valid grounds and followed fair disciplinary procedures before terminating Wamatu’s employment in June 2019. The dispute stemmed from a 2019 investigation into claims that Safaricom employees had illegally accessed, compiled, and sold subscriber data. Wamatu was arrested on June 7, 2019, after being forcibly taken from a Nairobi restaurant by unidentified men and held for interrogation before facing charges of computer fraud and conspiracy to commit a felony. He alleged his arrest was orchestrated by Safaricom to scapegoat him for data losses, a claim the company denied, stating it had merely reported suspected criminal conduct to authorities. Safaricom’s internal investigation linked Wamatu to the unauthorized acquisition and proposed sale of confidential subscriber and corporate data, including internal security details and senior managers’ remuneration. The court accepted Safaricom’s position, ruling that the company had sufficient evidence to justify disciplinary action for breaching confidentiality obligations. Wamatu’s claims of unfair termination, defamation, and loss of employee share benefits were dismissed. The court found that Safaricom had complied with disciplinary procedures, including issuing a show-cause letter, reviewing Wamatu’s responses, and allowing an appeal. It also rejected his argument that he was denied a fair hearing, noting he failed to attend a scheduled disciplinary session despite having time to do so after a DCI meeting. The ruling emphasized that employment law does not require proof of misconduct beyond reasonable doubt for dismissal, provided the decision is based on a genuine belief supported by evidence. Wamatu’s defamation claim was also dismissed due to a missed filing deadline and lack of evidence proving reputational harm. The case highlights Safaricom’s efforts to address internal data breaches and enforce confidentiality policies.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial Gain (Proposed sale of data)
IMPACT
Data Compromised: Confidential subscriber data, internal security details, senior managers’ remunerationIdentity Theft Risk: High
DATA BREACH
Confidential subscriber dataInternal security detailsSenior managers’ remunerationSensitivity Of Data: HighData Exfiltration: Proposed sale of dataPersonally Identifiable Information: Yes
JULY 2026
778Before Incident
JUNE 2026
778Before Incident
MAY 2026
777Before Incident
APRIL 2026
777Before Incident
MARCH 2026
777Before Incident
FEBRUARY 2026
777Before Incident
JANUARY 2026
777Before Incident
DECEMBER 2025
776Before Incident
NOVEMBER 2025
776Before Incident
OCTOBER 2025
776Before Incident
JANUARY 2018
789Before Incident
Breach
01 Jan 2018Safaricom PLC
Safaricom: Register for free and read this article

Safaricom Data Breach and Privacy Violations

709After Incident
CRITICAL-80
SAF1779179446
Kenyan High Court Orders Safaricom to Pay KES 9.9 Million for Data Breach Violations The Kenyan High Court has ruled that Safaricom, the country’s largest telecommunications provider, must compensate 11 subscribers a total of KES 9.9 million (KES 900,000 each) for violating their constitutional rights to privacy, dignity, and consumer protection. The case, filed by Austin Taabu and 10 other complainants, stemmed from a 2018-19 data breach in which Safaricom’s internal systems were compromised, leading to unauthorized access to customer data. The court determined that Safaricom failed to adequately safeguard personal information, exposing subscribers to potential misuse. The ruling underscores growing legal accountability for data protection failures in Kenya, particularly under constitutional and consumer rights frameworks. The case highlights the financial and reputational risks companies face when mishandling sensitive customer data.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: KES 9.9 millionData Compromised: Customer personal informationSystems Affected: Internal systemsBrand Reputation Impact: Reputational risks due to mishandling sensitive customer dataLegal Liabilities: Violation of constitutional rights to privacy, dignity, and consumer protectionIdentity Theft Risk: Potential misuse of customer data
DATA BREACH
Type Of Data Compromised: Personal informationSensitivity Of Data: High (constitutional rights to privacy and dignity violated)Personally Identifiable Information: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Safaricom PLC ?
?
What was Safaricom PLC's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Safaricom PLC's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Safaricom PLC's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Safaricom PLC's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Safaricom PLC's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Safaricom PLC's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Safaricom PLC's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Safaricom PLC's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Safaricom PLC's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Safaricom PLC's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Safaricom PLC's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Safaricom PLC's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Safaricom PLC ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Safaricom PLC's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Safaricom PLC Cyber Scoring History | Rankiteo