NAIROBI, Kenya -A Nairobi court has found Stanbic Bank Kenya Limited liable for breach of duty of care after a customer who was robbed of his ID and phone lost Sh1,001,000 in under an hour through the bank’s self-registration digital banking platform.
In a landmark judgment delivered at the Milimani Small Claims Court, Case Number SCCCOMM/E6743/2026 – James Njoroge vs Stanbic Bank Kenya Limited, the court ruled that the bank’s Know Your Customer (KYC) and digital onboarding process was “inherently insecure” and designed in a way that allowed a thief to easily pick the lock.
The case is set to send shockwaves through Kenya’s banking sector as lenders aggressively push customers to digital channels.
How the theft happened
According to court documents seen by this publication, Mr. James Njoroge had been a customer of Stanbic Bank for over 10 years and had never used or registered for mobile or digital banking.

On the morning of 13th July 2025, he was robbed and his physical wallet containing his National ID card, ATM cards, and his mobile phone linked to his bank account was stolen.
At 14:48 hours on the same day, a new digital banking profile – Stanbic’s OMNI platform – was self-registered on his account.
Shortly thereafter, between 15:09 and 15:25 hours – less than 40 minutes later – three unauthorized transactions totaling Sh1,001,000 were processed and his account drained.
Mr. Njoroge filed suit on 6th May, 2026, seeking compensation of Sh851,000, general damages for breach of duty of care, interest and costs.
Bank’s gate left open
The core of the dispute was whether Stanbic breached its fiduciary duty as custodian of customer funds.
The court cited the classic banking law principle from Karak Brothers Company Ltd v Burden (1972) that “a bank has a duty under its contract with its customer to exercise reasonable care and skill in carrying out its part with regard to operations within its contract.”
The court said this duty “is not merely passive; it requires the bank to act as a vigilant guardian of the customer’s funds.”
Stanbic had argued that it uses multi-factor authentication and that it exercised reasonable care. The bank said its self-registration process relies on knowledge-based information – ID number, date of birth, account number – plus an OTP sent to the registered mobile number.
The court rejected that argument.
“The Claimant testified, and it is not disputed, that he had never used or registered for mobile banking in his 10 years of banking with the Respondent. The evidence shows that on 13th July 2025, a complete stranger to the bank, using only the items stolen in a robbery (ID card, mobile phone), was able to create a full digital banking profile and drain a significant sum of money in less than an hour,” the judgment reads in part.
Justice noted that the system relied on an OTP sent to a stolen mobile phone.
Quoting a recent High Court decision – Commercial Appeal E078 of 2026 KEHC 9414 (KLR), Family Bank Limited v Kiarie – the magistrate said:[2026]
“A bank is the keeper of the gate through which its customer’s money passes; where it is warned that the gate stands open and does not close it, it cannot afterwards be heard to say that the thief carried the right key.”
The court found that principle applies with even greater force in Njoroge’s case.
“The Respondent did not just fail to close the gate after being warned; its gate was designed in a way that allowed a thief to easily pick the lock,” the judgment states.
KYC failure
The court found that the bank’s argument that the customer provides ID details during initial account opening is circular and insufficient.
“The information provided 10 years ago to open a physical account is the same information that the fraudster now possesses. It does not serve as a robust verification for a new and powerful channel,” the court said.
The court held that a bank’s duty of care must extend to ensuring that a significant change to an account, such as the activation of digital banking on a long-standing, entirely offline account, is verified with a high degree of certainty – for example through branch verification, biometric confirmation, or a cooling period.
By allowing instant self-registration using only data contained in a stolen wallet and phone, the bank failed that test.
While the full quantum of damages is in the final pages of the 9-page judgment, the court found for the claimant on liability and awarded compensation for the loss, plus interest at court rates from the date of filing until full payment, and costs of the claim.
The ruling is a warning to all Tier 1 banks. As banks digitize, the court is saying convenience cannot trump security. If a customer has been offline for a decade, a sudden digital registration from a new device followed by large transfers should trigger enhanced due diligence, not automatic approval.
Stanbic Bank had not commented by press time.