Hello

Your subscription is almost coming to an end. Don’t miss out on the great content on Nation.Africa

Ready to continue your informative journey with us?

Hello

Your premium access has ended, but the best of Nation.Africa is still within reach. Renew now to unlock exclusive stories and in-depth features.

Reclaim your full access. Click below to renew.

Money
Caption for the landscape image:

How 'sharp boys' got slice of loot in Sh12bn US student loans scam

Scroll down to read the article

Bundles of Kenyan currency notes.

Photo credit: Pool

For years, Shamir*, a university graduate living in Kasarani, Nairobi, survived on writing brilliant university theses for clients halfway across the world.

He was then part of Nairobi's massive, informal academic writing economy, doing the heavy intellectual lifting while local brokers pocketed the lion's share of the foreign cash.

But the true frustration set in when he noticed the sudden wealth of his peers.

“I used to see people my age drive big cars and flaunt cash and I kept on asking what they were doing that I wasn’t. I wanted to know the secret as well,” said Shamir.

The group was part of cybercriminals, known in urban slang as ‘sharp boys’, who had found a loophole through the digital infrastructure of writing essays for American students.

They were dipping their hands into an educational funding kitty meant for American students that is given through the US Department of Education office of Federal Student Aid, known as the Free Application for Federal Student Aid (FAFSA).

Shamir’s closeness to one of the ‘sharp boys’ opened his eyes to how they were making their money, and he decided to try to invest in the scam, as well.

The US Department of Education in May 2025 announced that the government had lost nearly $90 million (Sh11.6 billion) in the disbursement of student aid to undeserving individuals.

Among the undeserving individuals are dozens of Kenyans, who buy identities of US citizens, then apply for the aid – they get paid without ever having to step into a single lecture hall.

“In this case, one goes into the dark web and for as low as Sh1,000, you can buy personal information of someone in the US, and this is the information you need to apply for the aid. However, you do not buy just one if you want to maximise profit and chances,” says Shamir.

He explains that most would buy about 100 personal details that in the streets is referred to as fullz (full information), which includes the social security number, basic identity, payment data, driver’s license and address. According to him, the whole process of getting the funding is a serious system which requires patience and strategy.

After securing the data, and a proper Virtual Private Network (VPN) the individual pursuing the funding proceeds to apply for FAFSA aid before looking for a school. It is a tactic Shamir said is used to avoid applying for a course at a US-based college, get accepted, only to find out the data package you got cannot apply for FAFSA or has been used to acquire a loan, and it is already indebted.

Cyber café

A man using a computer at a Cyber café in Mulot, Bomet County. 

Photo credit: Francis Nderitu | Nation Media Group

An investor may apply in a group of a hundred so that they get the funding that may range between $2,000 (Sh259,400) and 3,000 (Sh389,100) for each course applied, and will be disbursed as a ‘ghost’ student continues to study.

The criminals in this case have to find means to have the classes done and attended to, so that the disbursement is made in full. The job is given to young individuals in the academic writing game for peanuts.

Most of the time, he says, the US government would release the funds as $1,000 (Sh129,000) first disbursement, $800 (Sh103,600) after some continuous assessment test and the remaining $1,200 (Sh155,400) later if the grant was for $3,000 (Sh388,500) for every semester.

“The impatient individuals, once they get $1,000 (Sh129,000) for 50 courses they are out. The reason you find so many first years joined virtual courses but did not complete them,” said Shamir.

The money is deposited in a digital student wallet that is created for every new student to enable them to access money remaining after the tuition fee is deducted.

He adds that at times, some people get scholarships and waivers that leave their accounts with so much of the funds, which the government assumes is for upkeep while studying. Tuition fees would range between $1200 (Sh155,400) to $2500 (Sh323,750), with cheaper courses guaranteeing higher payouts.

“Getting this money from the digital account is also another syndicate. There are people in the US who help Kenyans withdraw money since moving the money from the digital wallet needs an American bank account to move the excess money from the school account. They charge for it. May take 30 percent of what is in the account,” says Shamir.

It is a costly venture as the classes need to be attended, and Kenyans in the informal academic writing space are subcontracted to keep the classes attended virtually. However, Shamir says the grant is just, but a short-term goal, as the main target is the loans that are granted once a ghost student passes and gets to the second semester.

Getting into the second semester allows an individual to access up to $10,000(Sh1.2 million) as a loan to fund their studies.

“My applications failed because of a leaked VPN. It is a serious issue. If you needed to apply for that FAFSA in California, your VPN cannot be reading Texas, the application will be flagged and you will be asked to go to the commissioner of oaths to confirm your address which at times is difficult,” said Shamir.

Kenyans involved collude with US residents. In rare cases, some give physical addresses that allow them to send friends or family to collect physical cheques from.

What Shamir viewed as a technical hitch is actually part of a massive, multi-agency net tightening around the global student aid pipeline. The National Association of Student Financial Aid Administrators (NASFAA) and federal authorities have been quietly mapping the true scale of the penetration.

According to consolidated federal case logs, the federal investigators are actively tracing an estimated $350 million(Sh45.3 billion) in siphoned funding floating through international networks. The Office of the Inspector General in the US has over 200 active criminal investigations into identity of student aid fraud over the last five years.

The true scope of this invisible conflict was officially laid bare on April 27, 2026, when the US Department of Education launched a nationwide fraud prevention initiative.

In an official agency statement, US Secretary of Education Linda McMahon revealed that a retrospective federal audit had exposed approximately $90 million (Sh11.7 billion) in student aid dollars routinely bleeding out to ineligible recipients over the previous three years.

“American citizens have to present an ID to purchase a ticket to travel or to rent a car – it’s only right that they should present an ID to access tens of thousands of taxpayer dollars to fund their education,” said Ms McMahon while launching the prevention initiative.

Sophisticated transnational fraud

Federal authorities noticed that the system had come under a coordinated siege by highly sophisticated transnational fraud rings utilising automated AI bots to manufacture "ghost students" at scale.

Even more alarming, investigators discovered a massive structural loophole where more than $30 million had been actively siphoned by accounts using stolen social security numbers belonging to deceased US citizens, alongside another $40 million (Sh5.18 billion) drained by automated bot networks designed to mimic real student enrollment behaviours.

The US had already thwarted false applications that would have cost the country about $1 billion (Sh129 billion), had they gone through.

While the US Department of Education scrambles to secure its digital perimeter from Washington, a parallel clampdown has been unfolding across the African continent.

On February 18, 2026, Interpol announced the conclusion of Operation Red Card 2.0, a massive eight-week multinational law enforcement sweep spanning 16 African nations that resulted in 651 arrests and the recovery of more than $4.3 million in stolen assets.

In Kenya alone, local authorities executed 27 targeted arrests focusing heavily on decentralised networks that utilised messaging apps and fictitious digital dashboards to run high-yield investment scams.

While law enforcement officials have not explicitly confirmed whether these specific Interpol actions are directly linked to the FAFSA ghost student syndicate, the timing and mechanics of the crackdowns mirror the exact infrastructure Shamir and his peers were utilising.

This institutional assault on the American student aid program is not an isolated phenomenon, but rather the latest escalation in a sophisticated digital underworld that has placed Kenya at the epicentre of global cybercrime.

According to the March 2026 Interpol Global Financial Fraud Threat Assessment, financial fraud has officially surged into the top five global crime threats alongside illicit drug trafficking and money laundering, inflicting staggering global losses estimated at $442 billion in 2025 alone.

Interpol data reveals that between 2024 and 2025, there was a dramatic 60 per cent spike in fraud-related police Notices and Diffusions published across the African region.

The threat report explicitly warns that regional criminal syndicates have rapidly professionalised, shifting into an industrialised hybrid model that aggressively exploits the continent’s expanding digital infrastructure to target high-value institutions and Western systems.

Security audits from the Communications Authority of Kenya indicate that the country’s highly advanced digital economy has become a prime target and staging ground for transnational syndicates, placing Kenya second only to Nigeria in total continental cyber fraud losses.

Beyond federal benefit schemes, local networks have aggressively scaled into international credit card fraud, advanced identity theft, and account takeovers. Operating out of informal tech corridors, syndicates use sophisticated phishing campaigns and data harvesting pipelines to siphon millions of dollars from unsuspecting cardholders in the West.

A week ago, the Co-Deputy Director of the Federal Bureau of Investigation(FBI), Andrew Bailey, visited the Directorate of Criminal Investigations in Kenya, sparking speculations on the main intent of the visit.

While authorities in the US were yet to respond to our queries by the time of going to press, and law enforcement officials have not explicitly linked this high-level visit to the FAFSA ghost student scam, the closed-door sessions heavily highlighted a unified roadmap against transnational cyber networks.

“Senior officials from both agencies engaged in extensive discussions aimed at strengthening cooperation in various critical areas including fight against terrorism, cybercrime, transnational organised crime, financial fraud, human trafficking, narcotics trafficking, money laundering and crimes against children,” said the DCI.

The bilateral discussions focused on carving out new intelligence sharing pipelines and expanding joint specialised units tasked with dismantling the digital architecture used by international fraud syndicates.

As formal law enforcement arrays its forces from above, a parallel infrastructural squeeze is hitting the sharp boys from within their own operational communication lines.

Woman

Cybercriminals are exploiting online academic writing platforms used to produce essays for American students.

Photo credit: Shutterstock

For years, the primary marketplaces for trading stolen data packages, executing financial cash outs, and brokering identity credentials occurred inside sprawling, invite only WhatsApp groups locally known as KYC (Know Your Customer) networks.

These groups served as the informal digital trading floors for Nairobi’s cybercrime economy, allowing local syndicates to quickly coordinate transactions and share operational tactics.

However, a major enforcement crackdown by WhatsApp has resulted in the abrupt closure and mass purging of these notorious KYC forums.

By severing these vital communication nodes, the tech platform has heavily fractured the immediate peer-to-peer coordination that the sharp boys relied upon to scale their operations.

Between the quiet arrival of top-tier investigators from Washington and the sudden blackout of their underground communication networks, the frictionless digital playground once enjoyed by local operators is rapidly evaporating.

What Shamir and his peers view as a localised game of cat and mouse is inflicting devastating financial and administrative wreckage across the American higher education landscape.

This systemic haemorrhage, according to the US Department of Education, is most visible within the California Community College System, where a massive percentage of recent applications were flagged as entirely fraudulent, costing millions in stolen federal and state aid and forcing the Board of Governors to pass an emergency mandate requiring strict identity verification for all statewide applicants.

Individual districts have found themselves completely overwhelmed, with the Foothill De Anza Community College District intercepting 10,000 suspect profiles out of 26,000 applications before the quarter could even commence.

The ultimate financial toll was laid bare by the College of Southern Nevada, which was forced to completely write off $7.4 million (Sh958 million) in a single semester due to fraudulent ghost student enrollments.

This relentless onslaught of fabricated submissions has placed an unprecedented cybersecurity burden on admissions staff, transforming ordinary campus recruitment registries into high-stress digital battlegrounds.

Follow our WhatsApp channel for breaking news updates and more stories like this.