Following a data breach of a Safaricom central development server (CDS) operated by its finance department, about 43 million customer records were leaked in what the company considers to be an act of internal fraud. Consequently, Safaricom conspired with the ODPP/DPP and the DCI (notably the Serious Crimes Unit and the Digital Forensics Lab) to use fabricated evidence, while suppressing critical evidence, to obstruct the course of justice. This has resulted in a (Kenya Shillings) KES 1.432 billion lawsuit that was filed on February 24, 2025, against Safaricom PLC, the Attorney General, and the DPP. As well, I reached out to Amazon Web Services regarding some of the exhibits, and their response allowed me to prove that DCI and ODPP presented fabricated evidence in court. The Corporate Security Division of Safaricom fabricated some of the evidence that was submitted to court. Relatedly, did the compressed parquet file opened and examined by Victor Asila Wendo show that the data of 41,415,410 Safaricom customers leaked? Should Dilip Pal resign? What was the role of Vodafone in instigating and sustaining the criminal case related to this data leak? This post covers these questions, as well as describes the crimes committed by DCI, Safaricom, and ODPP. My opinion is that Amazon.com, Incorporated, should sue Safaricom PLC and the Attorney General (of the Government of Kenya) for the illegal use of AWS resources, including AWS infrastructure resources, for commission of statutory crimes.
Should Safaricom as a publicly listed company (PLC) be described (or designated) as a criminal that has committed statutory crimes?
Entities Named in Lawsuit
- Safaricom PLC
- Attorney General
- The Director of Public Prosecutions (DPP/ODPP)
- Directorate of Criminal Investigations (DCI)
Safaricom Executives
- Nicholas Mulila
- Morten Bangsgaard
- Dilip Pal
- Peter Ndegwa
- David Nyamai
- Patrick Kinoti M’arithi
- Eric Anderson Kabugo Mugo
- Odhiambo Ooko
- Patrick Omondi
- Victor Asila Wendo
- Huzaira Bashir
- George Matuthu
- Hillary Murefu Wangila
- Martin Stephen Macharia
- Matthew Mutiso
- Anthony Nyaga Irungu
- Samuel Ochieng
- Annette Wanjiru
- Peter Mbatha
These reference boxes contain names of some of the companies, entities, and people mentioned in this post. These reference boxes allow for easy referencing of individuals and companies.
Safaricom PLC suffered a data leak where about 43 million customer records, including MPESA data, subscriber registration data, phone types, and call records, were exfiltrated from the Central Development Server (CDS), which was part of a hybrid computing ecosystem dubbed Big Data environment that was domiciled in the department of Big Data and Business Analytics – whose departmental head reported to Dilip Pal, the Chief Financial Officer of Safaricom. In an internal Safaricom investigation report done by the Ethics and Compliance department and seen by Kagirison Research, the Big Data and Business Analytics department was reorganized to better operate as part of the finance department. This means that the CDS and this Big Data environment were operated by the finance department when this data breach (and consequent data leak) occurred.
Safaricom cannot claim that there was no data leak because I have seen documented samples of the leaked data that were patently out of the custody of Safaricom. So, it is impossible for Safaricom to argue that it did not lose custody of the leaked data because it caught the employee who was trying to cart off customer data from Safaricom’s premises (both online premises [i.e Safaricom servers and its computing ecosystem] and on-site [offline or physical] premises). Ideally, Safaricom should have notified the statutory authorities of this leak in a timely manner, but it did not.
Safaricom investigated this data breach as an insider leak.
Interestingly, the hacker(s) using an anonymous protonmail email account notified Nicholas Mulila, Morten Bangsgaard, Dilip Pal, and Peter Ndegwa that (s)he had breached Safaricom servers and exfiltrated customer data. To date, the real identity of this hacker(s) is unknown.
Kagirison Research is in possession of the memorandum of plaint, affidavits, statements, and related documentation of the aforementioned lawsuit, which altogether runs to 1022 pages; and includes evidence and supporting documentation. Also, this lawsuit is related to two other cases that are described in a different post. This lawsuit was filed after a criminal case involving the plaintiff was concluded, with the court acquitting the plaintiff (who was then the accused).
At its crux, this lawsuit lifts the hood at what happens inside Safaricom, beyond the veil of the well-crafted corporate image that the company presents to the public and its investors. This lawsuit exposes felony crimes, discrimination, incompetence, fraud, collusion, and corporate malfeasance, as well as how Safaricom conspires with the Directorate of Criminal Investigations (DCI) and the Office of the Director of Public Prosecutions (ODPP) to defeat justice and persecute victims of Safaricom’s corporate crimes – including maligning their reputation and bending the (criminal) justice system of Kenya to serve malicious actors. Also described are allegations of evidence tampering during custody, with the goal of using inauthentic evidence to pervert the course of justice.
When this post was first published, the summons were still not delivered to Safaricom PLC, the DPP, and the State Law Office that hosts the Attorney General of Kenya who is being sued on behalf of DCI via invocation of Article 156 of the constitution of Kenya.
On April 10, 2025, Safaricom was served with summons to enter an appearance in this suit. On the same date, summons were also served to the DPP (located at ODPP House) and the State Law Office.
The loss of data custody ensuant to the data extrusion from the Big Data environment required internet access to the privileged servers, such as this CDS. The investigation conducted internally by Safaricom’s Corporate Security Division settled on the (data) leak originating in the CDS. Any granting of internet access to CDS is subject to approval by the data management committee, which included David Nyamai, Sharon Holi, and Fred Waithaka. So, was internet access granted to CDS? If no, then how was data extruded from this CDS?
From the documented testimonies available, this data extrusion was achieved through cloud storage upload(s) whereby Safaricom data were illegally exported from the CDS to Amazon Web Services (AWS) cloud where it was stored in a simple storage service (S3) bucket named safcomdata. Obviously, this required internet access to CDS.
The leaked data that was shared with Safaricom’s Data Protection Office, Integrity Team, Morten Bangsgaard, and Dilip Pal was stored in the folder/directory named phonedata in the aforementioned S3 data bucket.
Was the Leaked Data an Anonymized Aggregate Data or Unanonymized Structured Datasets?
The data leaked was unencrypted, unanonymized structured datasets that were the output of federated data that had been processed in a data pipeline. This reveals that this (leaked) data was processed by a server that had access to the MPESA server, the subscriber registration server, and the call records server. I know this because the verified documented samples of the leaked data that I have seen show unique subscriber data, along with phone type, income range, age cohort, and usage of data and voice services. “With this data it was possible to know where one lives. Given the multitude, it was considered a national security (sic)”, deponed Samuel Ochieng – a Safaricom cyber security expert – concerning the magnitude of the data leak.
The hacker(s) sent to Safaricom employees 2 snippets of the leaked data that contained 2,048,075 customer records, and this allowed Safaricom investigators to confirm that indeed the hacker(s) was in possession of authentic, yet illegally acquired Safaricom customer data. Samuel Ochieng confirmed receipt of these snippets during a meeting with Patrick Kinoti, Titus Mwenda, David Nyamai, Eric Mugo, James Yogo, Kennedy Kaberia, and Odhiambo Ooko. Samuel Ochieng stated in court that they downloaded one of the files sent by the hacker(s) for analysis.
The verified documented samples of the leaked data that I have seen show unique subscriber data, along with phone type, income range, age cohort, and usage of data and voice services.
According to the aforementioned internal Safaricom investigation report, aggregated data was found in the directory whose data was leaked (and became the subject of the investigation). Aggregated data is anonymized, and is considered to be proprietary company data that is subjected to statutory protections that are different to those accorded to personal data. So, did the hacker only leak the structured dataset and not the aggregated data? Or, was the report trying to obliquely justify a way to avoid proper acknowledgment of the data leak as per statutory laws? This questions can never be conclusively answered, but it is important I raise them here.
Unanonymized structured datasets are personal data that must be protected according to the Data Protection Act of 2019. This act also mandates the data controller – in this case, Safaricom PLC – to inform the data subjects about the fraudulent leakage of their data, in line with provisions of §43 of this act.
The data that leaked was clustered unanonymized datasets that were fit to be stored in a data lake or a data lakehouse. So, the leaked data was personal data of Safaricom customers.
Amazon Web Services
After an ad hoc meeting held to discuss the data leak, Patrick Kinoti instructed Eric Mugo to trace the source of the leak and compile a report of his findings. In his report, Eric Kabugo Mugo states that the leaked data was uploaded to an Amazon account that did not belong to Safaricom. “The Amazon was (sic) account where the (leaked) data was uploaded to was not a Safaricom amazon account but a personal account”. So, does Safaricom own AWS accounts for storing data (either in data lakes or data lakehouses)? If yes, which servers upload data to these AWS accounts? Was the CDS procedurally configured to upload data to AWS account(s)? If yes, was any data uploaded into any of these AWS accounts on the purported date of the data leak? If yes, who uploaded the data and was the upload procedural or illicit?
According to an unstamped and unsigned report of examination created by Peter Mbatha (service number 90597) for the Cybercrime Forensic Unit of the National Police Service (NPS), this exfiltrated data was hosted in an AWS account named “studyudemys”. As will be explained later, this forensic report will be contested in court as fabricated evidence that was submitted in the trial court by Peter Mbatha (attached to the Digital Forensics Lab [DFL] of the Directorate of Criminal Investigations[DCI]). This same fabricated evidence was used by Patrick Omondi (service number 93647 and then attached to Serious Crimes Unit [SCU] of DCI) to amend the charge sheet. How Eric Kabugo, David Nyamai, and Patrick Kinoti are associated with this fabricated evidence is explained later.
A question can be asked at this point: Antony, why are you accusing DCI of fabricating evidence? Do you have any evidence that DCI used fabricated evidence? Why do you state that crimes were committed by DCI policemen?
Are you influenced to make these claims by charges made against you by Victor Amadala of TheStar Kenya via the DCI for reporting that Safaricom made staggering OMV equity losses amounting to KES 1 trillion? These charges are described in A Case to Win? where I explain how lame threats of lawsuit by Brian Onyango of Emacar Ndeda & Onyango Partners led to DCI and ODPP – through Joyce Gacheru – making a miscellaneous criminal application at Kahawa Law Courts which was heard exparte by Boaz Maure Ombewa in March 2025. I also explain why a judicial review of the judicial indiscretion by Ombewa is warranted.
For this post, the focus is on statutory crimes committed by Safaricom and DCI. The findings in this post help confirm the arguments in A Case to Win? that corporate crimes, occupational crimes, and state-corporate crimes have been committed by Safaricom PLC and its employees.
According to the laws of Kenya, it is illegal for any DCI policeman (or policewoman) to fabricate evidence or willfully submit fabricated evidence in a trial court…Is the laptop that Patrick Omondi (No.93647) menacingly confiscated from the plaintiff the same laptop that was presented in the trial court as evidence?
For now, the question that needs to be answered is whether fabricated evidence was presented in the trial court? If yes,then who submitted this fabricated evidence?
Fabricated Evidence and Evidence Tampering

Is there proof of fabricated evidence? The answer is yes. The proof is the fabricated evidence that the Digital Forensic Lab (DFL) of DCI submitted in court as exhibit C that the DCI policeman, whose service number is 90597, described as the storage drive taken from CDS (which was the server of interest in the investigation).
Relatedly, I reached out to Amazon Web Services (AWS) and provided it (AWS) with some of the exhibits (that were submitted in court), and they helped confirm that these exhibits were fabricated evidence.
According to the laws of Kenya, it is illegal for any DCI policeman (or policewoman) to fabricate evidence or willfully submit fabricated evidence in a trial court. Not only are the implicated DCI policemen/women committing criminal offenses that can be prosecuted under the Criminal Procedure Code (Cap 75) and the Penal Code (Cap 63), but they also show contempt of court and undermine Article 50 of the Constitution of Kenya of 2010 (CoK2010). This also calls into question the conduct of the prosecutor (and the ODPP) who allowed fabricated evidence to be used for malicious prosecution of the plaintiff, who has instituted this lawsuit that seeks damages amounting to KES 1,432 millions.
As is explained later, Mbatha committed perjury. Likewise, the ODPP knowingly built its case on contested fabricated evidence, and this perverts the course of justice, as well as amounts to professional misconduct and abuse of office, besides contravening Article 157 of CoK2010.
Another issue that needs to be considered is whether Patrick Omondi (No.93647 and then attached to SCU of DCI) tampered with evidence or produced fabricated evidence in court. Is the laptop that Patrick Omondi menacingly confiscated from the plaintiff the same laptop that was presented in the trial court as evidence? Accompanied with Sergeant Joseph Kipruto, Patrick Omondi menacingly, and without a court warrant, dispossessed the plaintiff of a Lenovo laptop whose serial number was duly noted in the inventory list they signed at DCI headquarters, but the laptop that Omondi submitted the next day to the digital forensic unit at DCI headquarters had a different serial number (which was duly noted by Corporal Yvonne Anyango, No.92399). The laptop that was then produced in court did not have a serial number as per the memorandum of plaint of this lawsuit.
So, were the serial number of the laptop tampered with while it was in custody (and eventually erased), or were three (3) different laptops used as evidence in this case? To make matters worse, Omondi (No.93647) could not recognize the server which was breached when asked to identify it in court and admitted that he had no knowledge of the exhibit memo confirming that the breached server was taken into DCI custody. “I do not know how the server reached the (DCI) Forensic Lab”, said Omondi (No.93647) in court. As the investigating officer, what was he really investigating if he could not identify the server that was breached?
Interestingly, Mbatha states that he investigated the server that was breached. Did he investigate the actual (physical) server or the (virtual) server image? To answer this question, one must answer an obvious question, how did Mbatha get access to this server? I am asking this question because no one states that the server was released (temporarily) by Safaricom to DCI forensic lab. It is not mandatory for the physical server – which was breached – to be taken into DCI custody for investigations to be done. The forensic image of this server can be obtained, and this server image can serve as exhibit in the investigation. However, Omondi (No.93647) stated that there was no exhibit memo showing that DCI received the server or server image for investigation!
The Corporate Security Division of Safaricom – through Eric Mugo – reported that the “aggregate” data that was leaked was initially hosted in a CDS directory in the breached server. This directory is contained in a physical server storage drive, and this storage drive can be imaged as stated above. In this forensic drive image will be the image of the directory that contained the leaked data. Omondi of DCI stated that they did not have custody of the server image. So, if DCI cannot prove custody of the server image, how did they obtain contents of the aforementioned directory? Likewise, if this directory was not imaged, then which investigation did DCI do (on this directory) and then present in court?
The number of leaked customer records is not certain because Safaricom PLC never made a timely report of this data leak to the Office of the Data Protection Commissioner (ODPC) as mandated by the Data Protection Act 2019, particularly Section 43 of this act.
Antony Kagirison
In his report, Mugo stated that he heads a team that includes 3 police officers, all with the rank of Inspector of Police, and that they have been seconded by NPS to Safaricom PLC so that they can easily aid in criminal investigations. Did Mugo image the server? If yes, it was not difficult to ask any of the police officers in his team to liaise with DCI to ensure that DCI had obtained the server image for investigation. This way, a key hardware in Safaricom’s cloud infrastructure could be offline for minimal time, while allowing for investigations into the data leak to occur.
Away from the server image for now, how did the ODPP participate in the criminal case?
Mutual Legal Assistance
Seven (7) months into the case, the ODPP – through a request made by C.M.Mwaniki – sought a mutual legal assistance from Swiss and American authorities with the goal of getting two foreign companies to aid their investigation. These companies were Proton AG and Amazon Web Services, Incorporated (AWS Inc.). About six weeks earlier, DCI had issued a consubstantial request of mutual legal assistance via the International Criminal Police Organization (INTERPOL).
Interestingly, despite Proton AG and Amazon Web Services, Incorporated (AWS) showing readiness to procedurally and legally cooperate with the investigation into this data leak, the ODPP did not pursue this path, instead choosing to rely on DCI and internal Safaricom investigations. Already, these foreign companies were cooperating to mitigate the adverse effects of the data leak.
Proton AG through Shayn had informed Annette Wanjiru (of Safaricom PLC) on the steps they had taken after receiving a report of the abuse of their email service by the hacker(s). This is despite Annette Wanjiru making a crude request to ProtonMail. “Kindly share with us any information identifying the user to aid in our investigation”, wrote Annette Wanjiru in her unprocedural request to ProtonMail, a subsidiary of Proton AG. Annette used the official Safaricom Abuse email account of [email protected] to make the aforementioned unconventional request. Basically, this amounts to abusing the official email account used to report abuses to Safaricom.
Refusal to pursue assistance from AWS left the ODPP and DCI with only the exhibits obtained from Safaricom PLC and the gadgets of the plaintiff. As is explained later, this undermined the investigations.
The question of whether DCI got the server image raises another question, what if the server in question – i.e CDS – did not exist. How do we know it existed? Before answering this question, let us consider the magnitude of the leak. How large was it?
How Large was the Data Leak: Was it 35 million Customer Records, 41 million Customer Records, or 43 Million Customer Records?
The number of leaked customer records is not certain because Safaricom PLC never made a timely report of this data leak to the Office of the Data Protection Commissioner (ODPC) as mandated by the Data Protection Act 2019, particularly Section 43 of this act. So, it is not clear if it was 35 million customer records that were leaked (as derived from the deponement of Samuel Ochieng), or was it 41 million customer records (as can be derived from the deponement of Victor Asila Wendo)? My take is that 43 million customer records leaked in this data breach, and I derive this from the investigation report written by Eric Kabugo for the Ethics and Compliance department, then headed by Patrick Kinoti (now the Group Director Non-Financial Risks in Equity Bank Limited).
I derive the 43 million value from the correspondence between the hacker(s) and Safaricom PLC, with this correspondence running into 8 emails sent by the hacker(s) with the eighth email titled “Final breach completed – let’s talk”. Interestingly, the hacker sent the eighth email 48 hours 34 minutes after he sent the first email titled “35 million customers data breach – very soon on
dark web”. The ad hoc meeting mentioned above was held on the same day that Safaricom received the first email notifying them of the breach. As mentioned, the attendants in this meeting were Kennedy Kaberia, Samuel Ochieng, Patrick Kinoti, Titus Mwenda, David Nyamai, Eric Mugo, James Yogo, and Odhiambo Ooko among others.
The hacker(s) in their second email confirmed that they had uploaded 9 files containing Safaricom customer data. This data was in plain-text, row-based file format. This email was sent to Samuel Ochieng, Johnbosco Mulei (now the Senior Manager, Group Cybersecurity – Technical Security in KCB Bank Group) and James Yogo (now the Head of Cyber Security (CISO) in the Central Bank of Kenya) – and copied to the Data Protection Office (of Safaricom) and Safaricom Integrity Team. It is important to mention (for the reason that will be obvious shortly) that the hacker(s) sent leaked data samples organized in row-based file format.
Months into investigations and ongoing court case, Patrick Kinoti M’arithi handed Victor Asila a flash drive containing files and datasets that he was to analyze. These datasets were similar to the datasets that were contemporaneously subject to investigation by the DCI.
In his deponement, Asila stated that one of the dataset contained 41,415,410 unique customer records organized in parquet format. “When I looked at the file it contained 41,415,410 unique customer records”, deponed Asila. He also stated that the flash drive also contained a folder with programming code that was used to generate datasets. He then stated that the code was executed on the purported date of the data breach. Asila also deponed that he made a data analysis report. It is from Asila’s statement that I got the record that 41 million customer records leaked from Safaricom’s CDS. So, who created the aforementioned folder and the programming code it contained?
It is not wise to take Asila word for it that he does not know the origin of the data he analyzed, even though he deponed that he received the flash drive from Kinoti. So, where did Kinoti get the data contained in the flash drive? Also, why did Mugo describe the same datasets as leaked in his report into the data leak? Interestingly, the filename of the datasets do not match the file names that the hacker(s) showed Safaricom in their 8 email correspondences. However, these datasets could have been part of the 60 files that the hacker(s) said they had uploaded in the phonedata directory in the S3 bucket mentioned earlier.
My opionion is that Amazon.com, Incorporated, should sue Safaricom PLC and the Attorney General (of the Government of Kenya[GoK]) for the illegal use of AWS resources, including AWS infrastructure resources, for commission of statutory crimes. I do not buy the unsubstantiated claim that Vodafone Group PLC set up Safaricom PLC and DCI, and led them to institute a criminal case using fabricated evidence, which illicitly used AWS resources. It can be argued that the ODPP discouraged bringing AWS onboard to aid the criminal investigations into the data leak because it would then have been possible to reveal that fabricated evidence was being used to prosecute the case.
Antony Kagirison
Relatedly, the data format is interesting because parquet format cannot directly add data into tables created by data organized in row-based file format. I will explain later why the data examined by Asila raises the question of whether the data of 41,415,410 unique Safaricom customers leaked.
As stated previously, Mugo deponed that the leaked data originated from the CDS in the Big Data environment. Now, our focus is on whether this CDS existed. To do this, we need to show that it (CDS) was set up and that it operated, as well as mention the people who set it up and used it.
Central Development Server (CDS)
How do we know that CDS was created and operated by the finance department of Safaricom PLC?
In the statement that David Nyamai Kasuki recorded at DCI headquarters, he stated that there exists a Big Data and Business Analytics department that he had led before handing it over to Charlotte Kepadisa. Also, he stated that this department reports to the Chief Financial Officer (CFO), Dilip Pal.
Nyamai affirmed that he headed this department during the purported time of the data leak, and he had a team made up of 17 scientists, with 4 of them being contractors from Vodafone Group PLC. This means that the data leak happened in his department during his leadership. This also places him as a good source of information about how the central development server (CDS) came into operation and who operated it.
Nyamai stated that his data science team needed to work with the data engineering team to optimally serve the finance department, especially following an assessment report by McKinsey Consulting that recommended scaling of the data science team. The data engineering team was then headed by Kamau Maina, and his superior was George Njuguna. The data engineering team that collaborated with the data science team was dubbed the big data engineering team, and was headed by George Kanja Matuthu. Matuthu reported to Kamau Maina.
Nyamai stated that it is the data engineering team that sets up servers that are used by the data science team, especially the big data lake servers. The data engineering team also install tools required by the data science teams in these servers. Likewise, the data engineering team maintains the big data environment and creates the data pipelines that are needed by the data science team.
According to Nyamai, his team needed a centralized data science environment that would allow on-site and remote data scientists to work together, as well as allow Safaricom and Vodafone scientists to collaborate easily on data projects. It is for this reason that the central development server was setup.
The central development server (CDS) was setup by Matthew Mutiso – a member of the data engineering team under George Matuthu. The list of data scientists that could access and use the CDS was approved by the data engineering team, with Huzair Bashir confirming this approved list. Now, we know that CDS was set up by the data engineering team for use by the data science team. The data scientists were using this CDS during the time of the data leak.
The Safaricom data science team members who had access and used the CDS before and during the period it was breached (hacked) were the plaintiff, Victor Asila, Hillary Wangila, Martin Macharia, Billy Lugado, Benson Olugo, Seaman Kinyua, Jeff Ogucha, Kevin Mbugua, Roselyn Kinuthia, Anthony Irungu, David Gitahi, and Robert Ayub Odhiambo; while the Vodafone scientists who had contemporaneous access and usage rights were Riyaj Azad Shaikh, Udbhav Pangotra, Sourav Mahajan, and Gaurav Srivastava. The line managers for this team were David Nyamai, the plaintiff, and Victor Asila.
The data science team repeatedly requested help from George Matuthu when running the CDS. Let me mention an appropriate incident here.
According to an email sent to the plaintiff, Huzaira Bashir, Shaiykh Riyaj, and Victor Asila (and copied to Matthew Mutiso), George Kanja Matuthu noted that the Central Development Server (CDS) had been granted a proxy bypass for 2 weeks, and that he had sought a permanent exception to the existing tailored access restriction. In his email message, Matuthu noted, “we had a proxy bypass to allow us to access the packages, and we were given a 2 week grace period by security team. We are seeking a permanent exception to this, to allow us to be upgrading them as time goes”. The packages Matuthu is describing are pre-written programming codes that were required by the data science team in their operations of the CDS. Huzaira Bashir had earlier warned the aforenamed (data science) team members as follows: “DO NOT try and upgrade any python or pip installation”. Now, the questions are: Was Matuthu able to get the permanent exception he had sought? If yes, would this exception modify the scope of internet restriction granted to this CDS? If there was internet connection, who was authorized to connect the CDS server to it (the internet)? Unfortunately, we cannot know the answers to these and other related questions because Matuthu was never called to testify in the case. This omission was noted in the judgment that acquitted the plaintiff in the criminal case filed by the ODPP. On October 16, 2024, Muriu Mungai & Company Advocates LLP noted that this acquittal had been subjected to an (ongoing) appeal (at Milimani High Court).
On the purported date of the data leak, Mugo states that the CDS was accessed by 4 members of the data science team, namely Saikumar Allaka (the plaintiff), Hillary Murefu Wangila, Martin Stephen Macharia, and Anthony Nyaga Irungu. Mugo was comport enough to state the number of times each of these 4 scientists accessed the CDS. According to his investigative report, Wangila accessed the CDS 3 times, Irungu accessed the CDS 4 times, and Macharia accessed the CDS 5 times, while the plaintiff accessed this server only once.
It is interesting that Mugo cleared Irungu, Wangila, and Macharia of culpability and involvement in the data leak. What is more concerning is that DCI and the prosecutor did not call Irungu, Wangila, and Macharia to testify (or even record statements).
At this point, a pressing question can be raised. Who created the purported directory in CDS that contained the Safaricom customer data that was leaked? Also, when was this directory created? Was it created when CDS was granted unrestricted internet access pursuant to approval of request contained in correspondence referenced as CRQ000007564223? Which of the Safaricom and Vodafone employees were granted this unrestricted access? Were they called to testify or were they investigated by Eric Mugo who generated the report on this data leak on behalf of the corporate security division (headed by Nicholas Mulila)?
On the purported date of the data leak, Mugo states that the CDS was accessed by 4 members of the data science team, namely the plaintiff, Hillary Murefu Wangila, Martin Stephen Macharia, and Anthony Nyaga Irungu…Wangila accessed the CDS 3 times, Irungu accessed the CDS 4 times, and Macharia accessed the CDS 5 times, while the plaintiff accessed the server (CDS) only once.
Mugo and Mulila are best positioned to answer questions about this directory, because it is this directory that is considered to be one of the primary fabricated evidence that was presented in court by the corporate security division (of Safaricom) and DCI. If Mulila claims ignorance of Mugo’s investigation report, then why did he allow the report to be issued as an authoritative internal report? Also, was this report given to DCI? Did DCI claim ownership of this report when they submitted it (or parts of it) as an exhibit in the trial court?
How I Confirmed that Fabricated Evidence was Presented in the Trial Court
During his testimony in the trial court presided over by Senior Principal Magistrate R.K. Ondieki, Mbatha stated that the leaked data had been uploaded from a Safaricom server to AWS cloud. I reached out to AWS about this, and this is how I found out that DCI presented fabricated evidence in court. I was also able to trace the origin of this evidence fabrication to Eric Mugo.
This is the AWS response to the exhibit I provided to it…





Can you educate all Kenyans on the dangers of this leak.
How can someone be enjoined in this lawsuit coz all Kenyans
so should be part and parcel of this suit.
First and foremost thank you Mr. Anthony for the publication. Approaching this as a problem-solver, I find the campaign’s thesis to be both sound and necessary. It correctly identifies a key pressure point. My skills as a lawyer and tech enthusiast are directly relevant, and I am eager to explore how I can contribute to this principled cause.