The Gambling Regulatory Authority has confirmed it is actively investigating three licensed betting operators Betika, Odibets and Kwikbet over claims that they unlawfully benefited from vast quantities of Safaricom subscriber data allegedly harvested by former telco employees and sold for commercial gain.
The confirmation, contained in official correspondence to complainant Benedict Kabugi Ndungu, marks the first clear public acknowledgement that the regulator is examining the firms after a formal complaint lodged with both the Director of Criminal Investigations and the GRA Director General.
In that May 19, 2026 complaint, Kabugi asked the two agencies to investigate the three operators for alleged unlawful acquisition and use of subscriber information and sought the suspension of their operating licences pending the outcome.
He alleged the data had been accessed by former employees of a major telecommunications company, shared for financial gain, and systematically fed to betting firms.
According to the complaint and supporting material, the information enabled the operators to improve customer acquisition, increase sales and enhance profits through precision targeting that ordinary marketing could never achieve.
The High Court had already made findings that undercut any claim of isolated or accidental leakage. In Constitutional Petition E095 of 2026, delivered on May 13, 2026 by Justice Bahati Mwamuye, the court held there had been “a sustained and systematic compromise of subscriber data.” Eleven petitioners each received Sh900,000 in general damages after the court found their rights to privacy, dignity and consumer protection had been infringed.
The judgment recorded that between 2018 and 2019 former employees had accessed and transmitted sensitive subscriber information — including financial transaction data, betting activity, device identifiers and geolocation information to third parties, among them betting companies, without consent or lawful authority. Weaknesses in internal controls allegedly allowed unrestricted access.
Sources familiar with the current probes say the DCI has formally requested extensive records from the GRA covering the licence holders: licensing information, past complaints, due diligence files and statutory returns going back to 2018.
Forensic material already before the courts, drawn from WhatsApp communications and system logs, has placed specific individuals and platforms in the chain. DCI analysis of those communications has been cited as naming “Andrew,” “Odibet,” “the Mburus” and “Betika” among the recipients or intermediaries handling the data.
Andrew Akwesera Aligula sits at the centre of the Odibets side of the record. Public reporting and court-linked material identify him as co-owner and operational figure behind Odibets. He has been arrested and held at Gigiri Police Station in connection with the data transactions.
On the day of one reported detention the Odibets application experienced a multi-hour outage. Separate proceedings have also linked him to unsolicited messaging of Safaricom subscribers and other disputes over property and data handling. Forensic references to “Andrew” and “Odibet” in the WhatsApp trails have placed the platform and its senior figure inside the evidentiary file examining how large datasets of identity details, mobile-money histories, betting behaviour and location data were segmented, moved and allegedly integrated into customer profiling and acquisition systems during periods of rapid expansion.
Betika, operated by Shop and Deliver Limited, appears with equal frequency in the same forensic chains. Public corporate records and industry reporting identify Chris Mwirigi Kaumbuthu as a key director and shareholder of Shop and Deliver, with Roamtech Solutions Limited also linked as shareholder and director.
George Mburu, co-founder of Roamtech and associated with Betika, has been named in reporting on the “Mburus” references in the data-transaction messages. Betika has been described in investigative accounts as one of the more frequent alleged buyers across multiple tranches of the stolen data.
The commercial logic is straightforward: access to real-time or near-real-time insight into who was already betting, how much, on which platforms, and from where, allowed hyper-targeted offers that converted ordinary users into high-frequency customers far more efficiently than cold marketing.
Kwikbet, operated by Solami Limited under licence, is the third firm named in Kabugi’s formal complaint to the GRA and DCI. Its ownership structure remains notably opaque. Public filings and the company’s own materials do not readily disclose directors or controlling shareholders in the same detail available for the other two operators.
That opacity itself becomes part of the accountability question now before the regulator: how a licensed operator whose beneficial ownership is hard to map sits inside a complaint alleging industrial use of compromised national subscriber data.
The modus operandi described across the complaint, the High Court record and forensic summaries is consistent. Former Safaricom employees allegedly extracted records covering tens of millions of subscribers names, national identity details, M-Pesa transaction histories, device identifiers, location data and detailed betting patterns.
The material was moved in batches, paid for through intermediaries designed to obscure the ultimate buyers, and then used to build behavioural profiles of gamblers.
Those profiles powered targeted marketing that identified high-value or already-engaged punters and locked them into continuous engagement. Ordinary Kenyans’ private financial and location data became a commercial product sold into the betting ecosystem.
While the GRA has told Kabugi that investigations remain active and that he will be informed of the outcome, parallel activity at the Office of the Data Protection Commissioner has seen requests for Alternative Dispute Resolution on related complaints.
Correspondence marked “without prejudice” has proposed settlement discussions that would not constitute admission of liability and could not be used in later proceedings.
One such track involves an ODPC complaint numbered against DG Loan; others sit in the same broader data-protection file. The contrast is stark: quiet settlement talks on one side, an open regulatory investigation into the three betting licences on the other.
The same data pipeline that allegedly fed these platforms also produced criminal cases against the former Safaricom staff who extracted it and civil awards against the telco that failed to prevent the compromise.
What has been slower is decisive action against the alleged downstream commercial beneficiaries. The GRA’s confirmation that it is now examining Betika, Odibets and Kwikbet therefore represents more than a routine status update.
It is the first formal signal that the regulator is prepared to look at whether licences were used to monetise data that the High Court has already described as systematically compromised.
Kenya’s betting industry has long operated at the intersection of aggressive customer acquisition, mobile-money convenience and thin regulatory oversight.
The question now before the GRA, the DCI and the public is whether three of its most visible licensed operators built part of that growth on a foundation of stolen personal data and whether the individuals who controlled those platforms will finally be required to answer for it.
The forensic trails, the court findings and the formal complaints are already on record. The only remaining variable is how far the regulator is prepared to go.
There's no story that cannot be told. We cover the stories that others don't want to be told, we bring you all the news you need. If you have tips, exposes or any story you need to be told bluntly and all queries write to us [email protected] also find us on Telegram
