International Crimes, Felonies, and Legal Implications for Safaricom Group

Share this post:

Did employees of Safaricom and Kenya’s DCI attempt to compromise AWS cloud infrastructure so as to falsely incriminate AWS for illegal possession of privileged Safaricom data? Did they succeed, or did their sloppiness allow for unconcealment of their crimes?

Should Safaricom as a publicly listed company (PLC) be described (or designated) as a criminal that has committed statutory crimes?

Data Leak of 43 Million Safaricom Customer Records, KES 1.432 Billion Lawsuit, and Safaricom-DCI Conspiracy to Fabricate Evidence and Commit Statutory Crimes
Kagirison Research | International Crimes, Felonies, and Legal Implications for Safaricom Group
Snippet from the data leak research.

This is a supplementary post to the data leak research; and its focus is on international crimes and related felonies that occurred after Safaricom had fired the data science specialist it had accused of leaking tens of millions of its customers records. These international crimes and adjunct crimes have never been prosecuted, and Safaricom managers and executives who were involved in them are still employed by Safaricom PLC, which was evident on November 13, 2025, when Nicholas Mulila graced the annual cybersecurity summit held by the company (Safaricom).

Kagirison Research | International Crimes, Felonies, and Legal Implications for Safaricom Group
CREDIT: X Account.

The primary crimes of interest are any felony that attract a maximum penalty of 3 or more years in prison, under either Kenyan or American laws. Among the felonies that are of focus in this post are wire fraud, computer forgery, and identity theft (impersonation).

I will not describe the background of the events that led to these crimes because this has already been done in the aforementioned data leak research. For instance, I will not touch on the directory in the breached Central Development Server (CDS) that Eric Mugo claimed hosted the leaked data as this was explained in the aforementioned research.

In this post, I will focus on the file containing 41,415,410 Safaricom customer records that Patrick Kinoti M’arithi gave Victor Asila Wendo to examine. Eric Mugo, Victor Asila, and Peter Mbatha claimed that these records were leaked. When I reached out to Amazon Web Services (AWS) regarding this set of Safaricom customer data, the guarded answers I received along with the over 6000 pages of documents I was given helped prove that AWS never hosted this data in any of its S3 data buckets. Likewise, there is no evidence that the hacker who contacted Safaricom had hosted this data as per the available records of the contents of the safcomdata S3 data bucket. So, where did Kinoti get this data from, and was it legally handed over to the Directorate of Criminal Investigations (DCI)? If this data was not leaked by the hacker mentioned in the data leak research, who then leaked it and who obtained illegal possession of it?

I will focus on the file containing 41,415,410 Safaricom customer records that Patrick Kinoti M’arithi gave Victor Asila Wendo to examine. Eric Mugo, Victor Asila, and Peter Mbatha claimed that these records were leaked.

The 41,415,410 Safaricom customer records are crucial in establishing the international crimes committed against AWS, including attempts to incriminate AWS by both Safaricom and the DCI, with the Prosecution Counsel and the Office of the Director of Public Prosecutions (ODPP) (tacitly) endorsing these crimes. This is one of the reasons why I previously made the following remarks:

My opinion is that Amazon.com, Incorporated, should sue Safaricom PLC and the Attorney General (of the Government of Kenya) for the illegal use of AWS resources, including AWS infrastructure resources, for commission of statutory crimes.

Data Leak of 43 Million Safaricom Customer Records, KES 1.432 Billion Lawsuit, and Safaricom-DCI Conspiracy to Fabricate Evidence and Commit Statutory Crimes

In my judgement, Eric Kabugo Mugo (of Safaricom) should be convicted, and Nicholas Mulila and Patrick Kinoti (now in Equity Bank Kenya) should be in court to answer to several charges (which are explained later). As expected, Peter Mbatha from DCI would be easily convicted for the crimes he committed. Also exposed to litigation are Peter Ndegwa (as CEO) and Dilip Pal (as CFO) of Safaricom PLC. I will later comment on civil liabilities associated with these international crimes, such as potential lawsuits that can be brought against Safaricom for false representation and/or injurious falsehood against Amazon’s AWS.

In this post, I will not speculate much about how these felonies were executed, but will focus on the on the evidence that Kagirison Research has obtained, and is admissible in a competent court of law. Because this post will not reproduce what was described in the data leak research, then not everyone mentioned in the data leak research will be the focus of this post, though everyone accused of being involved in these felonies of interest have already been mentioned in the aforementioned data leak research. For instance, Huzaira Bashir, George Matuthu, Hillary Murefu Wangila, Martin Stephen Macharia, Matthew Mutiso, Anthony Nyaga Irungu, Samuel Ochieng, and Annette Wanjiru are not the focus of this post, because the evidence at hand do not implicate them in any of the international crimes committed. Likewise, this post will not focus on crimescommitted by both Safaricom PLC and DCI – that do not meet the criteria to be described as international crimes. These crimes are fabricating evidence (which attracts up to 7 years imprisonment), abuse of office (10 years imprisonment), uttering a false document (7 years imprisonment), and conspiracy to defeat justice (5 years imprisonment). These (local) crimes were described in the data leak research.

As mentioned, this post focuses on felonies that have not been prosecuted. These charges must be based on evidence that Kagirison Research has obtained, and is admissible in any competent court of law in Kenya and the United States of America. This explains the need to minimize speculation. On the other hand, it calls for grounding these charges on legal reasoning, which transforms these charges from mere accusations to indictable charges. Equally, legal reasoning allows for examination of claims made by a Safaricom manager that Vodafone Group PLC was involved in the crime of…

To read the full post, subscribe to our private newsletter.

One comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.