Stop password theft: Safaricom pushes Kenyans to activate multi-factor authentication
Safaricom PLC has urged users to activate multi-factor authentication (MFA) on their online accounts to protect themselves against password theft and unauthorised access. In a security advisory shared on X on Sunday, October 11, 2026, the telecommunications company warned that passwords could be stolen through phishing attacks, reused across multiple platforms or exposed in data […]
Safaricom PLC, a leading telecommunications company in Kenya, has urged its users to activate multi-factor authentication (MFA) on their online accounts to safeguard against unauthorized access due to stolen passwords. In a security advisory posted on X on October 11, 2026, Safaricom highlighted that passwords could be compromised through phishing attacks, reused across various platforms, or exposed in data breaches.
The company explained that MFA introduces an additional layer of protection, such as an authenticator-app code, security key, or approval prompt, before anyone gains access to an account.
Safaricom recommended enabling this security feature on email accounts, cloud storage services, financial platforms, and workplace systems. The security measure aims to make it harder for unauthorized individuals to access personal and work accounts, even if passwords have been compromised. By requiring an extra verification step beyond passwords, MFA ensures that users provide a second form of verification, such as entering a generated code via an authenticator app, utilizing a physical security key, or approving a login request.
The advisory underlines the growing significance of online security as people increasingly depend on digital platforms for communication, information storage, and financial transactions. Users are advised to avoid reusing passwords across different accounts and to remain vigilant against suspicious links or messages requesting login details.
Safaricom emphasized that enabling MFA can substantially enhance account security, even if a password has been compromised. One additional step can significantly deter unauthorized access, the company stated.
To further protect themselves, users should create strong and unique passwords and exercise caution when responding to suspicious messages or clicking unfamiliar links. Safaricom’s advisory emphasizes the importance of integrating secure password practices with additional verification measures in an era where digital platforms play a crucial role in daily life.
Written by urgent.news from People Daily Kenya's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.