
Cybersecurity
Kenya Orders Telcos to Push Emergency SMS Past Every DND Setting, and Phishers Are Watching
October 4, 2026GashoTech Team
The one inbox Kenyans cannot mute
Most of us spent the last few years teaching our phones some discipline. We opted out of promotional bulk SMS, switched on Do-Not-Disturb, and reclaimed our inboxes from the endless stream of betting tips, loan offers and fake prizes.
On 1 October 2026, the Communications Authority of Kenya (CA) ordered the country's four mobile network operators to undo that - selectively, temporarily, and for one specific reason.
In a letter addressed to the chief executives of Safaricom, Airtel Kenya, Telkom Kenya and Jamii Telecommunications, the CA directed all operators to exempt government-authorised emergency bulk SMS from the opt-in and opt-out requirements that apply to commercial messaging services. The directive covers the national early warning system simulation exercise, which ran on 2 October, and the entire El Nino preparedness and response period.
In plain language: when the government sends an approved flood warning, it will reach every active line in Kenya - including yours, even if you long ago told your telco you never want to hear from a bulk sender again.
What the directive actually says
The letter, dated 1 October 2026, contains several directives that operators must implement with immediate effect. Compliance, the CA stated, is mandatory.
Deliver to all active subscribers. Approved emergency preparedness and public safety messages must reach every active subscriber, regardless of promotional messaging preferences, DND settings or previous opt-out arrangements.
No opt-out mechanisms on emergency alerts. Operators are directed not to apply opt-out mechanisms to emergency alerts and disaster preparedness messages issued under the framework.
Prioritise emergency traffic. Operators must ensure timely delivery of emergency communications across their networks and give them priority over ordinary commercial traffic.
Support the simulation and the real thing. Telcos must provide the technical support required for the 2 October simulation exercises and for actual emergency response operations that follow.
Designated platforms only. The emergency messages are disseminated through government-designated platforms, including short code 1590.
The CA anchored the directive in law rather than convenience. It cited constitutional provisions requiring the State to publish and publicise important information affecting the nation, Article 33 on the freedom to receive and impart information, Article 46 on consumers' right to information necessary for their safety and welfare, and the Access to Information Act 2016. It also invoked telecommunications licence conditions - specifically Condition 6 - which require operators to facilitate public information during major disasters, emergencies or crises, and to coordinate with the Authority.
Why now: El Nino is the deadline
The timing is not accidental. Kenya is entering the October-to-December rainfall season, and the seasonal forecast points to above-normal rainfall across large parts of the country, with the risk of flooding, landslides, infrastructure damage and displacement. The Kenya Meteorological Department has cautioned that the first showers are not automatically the official onset of El Nino rains - the technical definition requires at least 20mm of rainfall over three consecutive days - but the preparedness clock has already started.
The Red Cross has reportedly warned that millions of people could be affected if the season turns severe. That projection is a planning figure, not a forecast of certainty - but it explains why the government wants the emergency channel unlocked before the first major flood event, not after it.
The 2 October simulation was the proof of concept: a full national early warning drill, with live test alerts flowing through short code 1590, testing whether the operators' systems can actually push a message to every active line when the opt-out filters are lifted.
The security angle: what phishers learned this week
This is where the story stops being purely a telecoms story and becomes a cybersecurity one.
Every time a government normalises a new messaging channel, criminals get a template. We have seen it with M-PESA reversal scams, with fake NHIF and HELB messages, and with COVID-era "relief payment" SMS. The pattern is always the same: legitimate government communication arrives first, and imitations follow within days.
Kenya's experience with mobile money fraud makes this concrete. When Safaricom deployed AI-powered fraud detection, mobile money scams on its network dropped by more than half - which tells you how large the scam volume was to begin with. An unlocked, prioritised, government-authorised emergency SMS channel is now the single most valuable phishing disguise in the country.
So the rules for this season are simple:
- Real emergency alerts inform. They tell you about weather, evacuations, road closures and health precautions.
- Real emergency alerts never ask for money, PINs, passwords or M-PESA codes. No government flood warning will ever ask you to "confirm your details" via a link.
- Check the sender. Approved alerts come through designated platforms including short code 1590 - not through random 11-digit numbers or lookalike codes.
- Report the fakes. Forward suspicious messages to your operator's fraud reporting channel. Every report makes the next scam harder to land.
The bigger picture: SMS is the bridge, cell broadcast is the destination
There is a second, quieter story inside this directive: Kenya's emergency alert infrastructure is being rebuilt, and SMS is only the interim layer.
The CA's own roadmap, published on its site, describes a national Cell Broadcast Service (CBS) - an advanced emergency communication platform that enables the government to send instant, location-based alerts directly to every mobile phone connected to specific cell towers in an affected area.
The difference matters more than it sounds. SMS can suffer congestion and delay; when a flood is coming and millions of messages are queuing, minutes cost lives. Cell Broadcast delivers simultaneously to every phone in a tower's footprint without needing a subscriber list, without prior registration, and without being slowed by network overload. It is the same technology that powers earthquake and amber alerts in other countries.
In March 2026, the CA hosted a validation workshop on an Early Warning System Assessment Tool to gauge Kenya's readiness to roll out CBS, with the stated aim of aligning with the global Early Warning for All initiative's December 2027 target - universal access to effective early warning systems.
This week's DND override is the bridge between the SMS era and that destination. It squeezes maximum reach out of existing infrastructure while the more capable system is being built.
What to expect this season
For ordinary Kenyans, three practical things follow from the directive.
First, if you opted out of bulk SMS or enabled DND, expect emergency alerts anyway. That is not your telco breaking your trust; it is a lawful, temporary, government-authorised exemption with a defined scope - the simulations and the El Nino response period - and it does not reopen the door to commercial spam.
Second, the same alert you receive will be received by criminals targeting your locality. Treat every "emergency" message that asks you to act on money or credentials as fraud, full stop.
Third, watch the 1590 channel. If this El Nino season proves the value of prioritised emergency SMS, it strengthens the case for the Cell Broadcast rollout - and Kenya gets closer to a system where a flood warning finds you before the flood does.
The mute button was a good idea for spam. For disasters, Kenya has decided, silence is a liability.
Want to learn more?
Contact GashoTech for personalized consultations on AI, automation, and cybersecurity solutions.
Get in Touch