https://new.kenyalaw.org/akn/ke/judgment/kehc/2026/9771
The Court held that the SIM swap was the catalyst, but not a novus actus interveniens breaking the chain of causation. The bank had an independent duty to protect the customer’s account and to interrogate glaringly suspicious, rapid, high-value transfers. The telecom provider also remained liable because the SIM...
Source-derived case information.
- Citation
- [2026] KEHC 9771 (KLR)
- Parties
- Appellant: Diamond Trust Bank Kenya Ltd; 1st Respondent: Mercy Wairimu Kariuki; 2nd Respondent: Safaricom Plc
- Court
- High Court
- Jurisdiction
- Kenya
- Case Number
- Civil Appeal E121 of 2024
- Procedural Posture
- Civil Appeal / Judgment on Appeal and Cross Appeal From Chief Magistrate’s Court Judgment
- Outcome
- Appeal dismissed; cross-appeal dismissed; trial court judgment affirmed
- Judges
- ["AN Ongeri"]
- Legal Topics
- Negligence, Duty of Care, Causation, Novus Actus Interveniens, SIM Swap Fraud, Unauthorized Banking Transactions, Apportionment of Liability, Concurrent Liability, Appeal Review Standard, Daily Transaction Limits, Confidentiality and Data Breach
- Source Language
- en
Source-derived case record
Summary, issues, holding and outcome
More case intelligence is available
Unlock the full research layer for this judgment.
Parties
Diamond Trust Bank Kenya Ltd
Appellant
Mercy Wairimu Kariuki
1st Respondent
Safaricom Plc
2nd Respondent
Procedural Posture
Civil Appeal / Judgment on Appeal and Cross Appeal From Chief Magistrate’s Court Judgment
Legal Issues
- 1 Whether the Appellant breached its duty of care to the 1st Respondent
- 2 Whether the trial court erred in apportioning liability between the Appellant and the 2nd Respondent
- 3 Whether the non-business day processing and daily limit arguments displaced liability
Ratio Decidendi
The Court held that the SIM swap was the catalyst, but not a novus actus interveniens breaking the chain of causation. The bank had an independent duty to protect the customer’s account and to interrogate glaringly suspicious, rapid, high-value transfers. The telecom provider also remained liable because the SIM swap was a direct breach within its own sphere of duty. The apportionment adopted by the trial court was therefore reasonable and just, and no ground for appellate interference was established.
Court Disposition
Appeal dismissed; cross-appeal dismissed; trial court judgment affirmed
Orders
- The Appellant’s appeal is dismissed with costs to the 1st Respondent.
- The 2nd Respondent’s cross-appeal is dismissed with costs to the 1st Respondent.
Full Case Text
Judgment text and source record
1 paragraphs
Diamond Trust Bank Kenya Ltd v Kariuki & another (Civil Appeal E121 of 2024) [2026] KEHC 9771 (KLR) (18 June 2026) (Judgment) Neutral citation: [2026] KEHC 9771 (KLR) Republic of Kenya In the High Court at Machakos Civil Appeal E121 of 2024 AN Ongeri, J June 18, 2026 Between Diamond Trust Bank Kenya Ltd Appellant and Mercy Wairimu Kariuki 1st Respondent Safaricom Plc 2nd Respondent (Being an appeal from the Judgment of HON. R.W GITAU (SRM) in MAVOKO CMCC NO. E182 of 2022 delivered on 26/03/2024) Judgment 1.The cause of action in this case accrued on or about 8th February 2022, when the 1st Respondent received several message alerts from the Appellant at around 5:23 AM informing her of multiple withdrawals from her bank account, which she had not authorized. 2.This followed a SIM swap incident on her Safaricom line on 6th February 2022, which she had immediately reported to the 2nd Respondent. 3.The 1st Respondent argued that she had held a bank account with the Appellant for years, entrusting it with her hard-earned money for safe-keeping. 4.She testified that after the SIM swap alert, she promptly called Safaricom’s customer care, was told her line had been swapped through an M-Pesa agent, and was advised to visit a Safaricom shop. 5.She did so on 7th February 2022 and her line was reinstated. However, the next morning, she woke up to alerts showing that a total of Kshs. 4,418,601 had been withdrawn from her account via the Appellant’s mobile banking platform and Pesalink. 6.She contended that the Appellant had acted illegally, negligently, and in breach of its fiduciary duty by permitting these unauthorized transfers, ignoring glaring red flags such as the withdrawal of large sums in quick succession to several other banks and mobile phone numbers, and allowing transactions that exceeded daily allowable limits. 7.She maintained that she had never shared her Personal Identification Number (PIN) with anyone. 8.The Appellant, Diamond Trust Bank Kenya Limited, denied liability and argued that it had strictly acted within its duty under the General Terms and Conditions agreed upon with the 1st Respondent. 9.The Appellant contended that all the disputed transactions were initiated using the 1st Respondent’s mobile banking application upon successful input of her secret PIN, and that the Bank was entitled to deem that successful input as sufficient proof of identity without making further checks. 10.The Appellant also argued that the transactions were initiated over three separate days and did not surpass the daily allowable limit of Kshs. 2,000,000. 11.The Appellant further submitted that the 1st Respondent had fully blamed the 2nd Respondent for the compromise of her mobile banking application, and therefore the Appellant should not be held liable. 12.The Appellant also raised a jurisdictional challenge, arguing that the matter ought to have been litigated under the Data Protection Act or the Kenya Information and Communications Act. 13.The Trial Court held that the Appellant breached its duty of care owed to the 1st Respondent. 14.The court rejected the Appellant’s argument that it was not liable simply because the correct PIN was entered, finding that the bank had ignored significant red flags, including the rapid succession of large transactions and transfers to multiple unrelated accounts and mobile numbers, which should have prompted further verification. 15.The trial court apportioned liability, finding that the 2nd Respondent was primarily responsible for the SIM swap, but that the Appellant was also negligent in processing the transactions. 16.Consequently, the Trial Court entered judgment in favor of the 1st Respondent against the Appellant for the sum of Kshs. 1,788,601, awarded general damages for negligence and breach of confidentiality, and granted costs of the suit and interest at court rates. 17.The Appellant being dissatisfied with that judgment and decree filed the present appeal on the following grounds;i.That the Learned Magistrate erred in law and in fact by finding the Appellant breached its duty of care owed to the 1st Respondent yet the Appellant strictly acted within its duty under the General Terms and Conditions.ii.That the Learned Magistrate erred in law and in fact in failing to appreciate the generally recognized accounting principles and practices with regards to mobile banking transactions initiated over non-business days being processed and subsequently dated and recorded on account statements of the next business day.iii.That the Learned Magistrate erred in law and in fact in failing to appreciate the fact that the transactions on the 1st Respondent's mobile banking application were initiated on three separate days, and as such the transactions did not surpass the daily allowable limit of Kshs. 2,000,000.00.iv.That the Learned Magistrate erred in law and in fact in failing to appreciate the principle of causation, by apportioning full liability upon the 2nd Respondent, yet entering judgment and awarding quantum payable against the Appellant.v.That the Learned Magistrate erred in law and in fact in failing to appreciate the fact that the 1st Respondent fully blamed the 2nd Respondent for the compromise of her mobile banking application and subsequent loss of funds yet entering judgment in the sum of Kshs. 1,788,601 against the Appellant.vi.That the Learned Magistrate erred in failing to consider the Appellants' submissions and the numerous binding authorities cited by the Appellant and in doing so, arrived at an erroneous conclusion 18.The 2nd respondent filed a cross appeal challenging the 60% liability apportionment, arguing that the trial court erred in law and fact by holding it responsible for financial losses that occurred exclusively on the bank's independent platform. 19.The 2nd respondent maintained that its operational mandate is strictly limited to providing telecommunications infrastructure and that it exercises no control or visibility over transactions executed within the bank's mobile banking system. 20.Further, that timeline undermines the negligence claim against the 2nd respondent in that the 1st Respondent's SIM card was swapped on February 6, 2022, but she visited Safaricom's offices and regained full control of her mobile line on February 7, 2022. 21.The 1st Respondent's bank statements and witness testimonies confirmed that the disputed fraudulent withdrawals took place on February 7 and 8, 2022, after she had already resumed full possession and use of her SIM card. 22.The parties filed written submissins as follows; The appellant, Diamond Trust Bank Kenya Limited, submitted that they are challengong the judgment of the Chief Magistrate's Court at Mavoko, which held the second respondent, Safaricom Plc, 100% liable for a data breach that enabled an illegal SIM swap and fraudulent access to the first respondent's bank account, yet directed the appellant to compensate the first respondent for losses of Kshs. 1,788,601.00. 23.The appellant argues that the learned magistrate misapplied the principles of causation, contractual duty, and industry-standard banking practices. 24.The appellant submits that the undisputed facts show the first respondent held a bank account with the appellant and a SIM card issued by the second respondent, linked to the appellant's mobile banking application. 25.On 6th February 2022, the first respondent received suspicious airtime and SIM swap alerts, promptly contacted the second respondent's customer care, but despite her notifications, the second respondent completed the unauthorized SIM swap. 26.The first respondent's SIM was reinstated the next day, but on 8th February 2022, she received debit alerts showing that Kshs. 4,418,601.00 had been withdrawn via the mobile banking application. 27.The trial court found that the second respondent's actions were the direct cause of the compromise and absolved the appellant of any role in the initial data breach, yet still imposed partial liability on the appellant. 28.The appellant contends that this is an error in the application of causation, relying on the two-part test requiring proof that the loss would not have occurred "but for" the defendant's negligent act, and that the damage was not too remote. 29.The appellant cites the case of Jamu Imaging Centre v Roberto Macri (Civil Appeal No. E1 of 2020), where the court emphasized that causation must be established on a balance of probabilities and that the evidence must be carefully analyzed to determine the exact nature of the fault or breach of duty and its consequences. 30.The appellant also refers to Clerk & Lindsell on Torts (23rd Ed, 2020) for the ingredients of negligence: a duty of care, breach, causal connection between the breach and the damage, and damage that is not too remote. 31.The appellant argues that the proximate cause of the loss was the second respondent's unauthorized SIM swap, which compromised the account's security and enabled fraudsters to bypass two-factor authentication. 32.The appellant's alleged failure to detect daily limit breaches was a secondary, subsequent event that did not cause the loss but merely failed to mitigate it after the second respondent's negligence had already set the loss in motion. 33.The second respondent's act, the appellant submits, constitutes a novus actus interveniens breaking the chain of causation. 34.The appellant further contends that the trial court ignored the chronology of events: the SIM swap occurred on a Sunday (6th February 2022), a non-business day, when the appellant's automated banking system processed transactions without human intervention. 35.The system has a hard daily limit of Kshs. 2,000,000, and the fact that over Kshs. 2 million was moved proves that the fraud was initiated across two different system days, partly on Sunday and concluded on Monday after the daily limit reset. 36.The appellant argues that the trial court erroneously treated the automated transaction posting date (7th February) as the initiation date and imposed an unrealistic standard of care requiring manual monitoring outside business hours. 37.The appellant concludes that the sole, proximate cause of the loss was the second respondent's negligence, and therefore the judgment against the appellant should be set aside, the first respondent's suit against the appellant dismissed, and costs awarded to the appellant. 38.The first respondent submitted in response to the appeal by Diamond Trust Bank Kenya Limited and a cross-appeal by Safaricom PLC. 39.The 1st respondent stated that this matter originates from a judgment delivered on March 26, 2024 in Mavoko Chief Magistrate's Court Civil Suit No. 182 of 2020, wherein the first respondent sought declarations of data breach and negligence, financial liability for resulting losses, a refund of Kshs. 4,418,601.00, costs, and interest. 40.Regarding the appellate court's duty, the first respondent guides the court using the precedent established in Selle & another v. Associated Motor Boat Co. Ltd. & others (1968) EA 123, which dictates that a first appeal acts as a retrial where the court must independently evaluate the evidence and draw its own conclusions while acknowledging that it did not hear the witnesses firsthand. 41.This principle is reinforced by Abdul Hammed Saif v. Ali Mohamed Sholan (1955), 22 E.A.C.A. 270, clarifying that findings of fact may be overturned if the trial judge ignored material circumstances or if witness demeanor contradicts the general evidence. 42.Furthermore, the first respondent cites Peters v. Sunday Post Limited [1958] EA 424, which incorporates the House of Lords decision in Watt v. Thomas [1947] A.C. 484, to emphasize that while an appellate court has jurisdiction to review evidence, it must exercise caution and should not alter findings of fact simply because it might have reached a different conclusion. 43.The factual matrix of the dispute involves the first respondent's bank account held with the appellant and her mobile subscriber line operated by the second respondent. 44.On February 6, 2022, the first respondent received a SIM swap notification from the second respondent and immediately called customer care to state she had not initiated the request. 45.Despite being persistently called by unknown numbers during this time, she successfully engaged customer care, who confirmed the unauthorized SIM swap via an agent and promised to block the line. 46.Although her line was restored the next day at a dealer shop, she received numerous debit transaction alerts early on February 8, 2022, revealing that Kshs. 4,418,601.00 had been fraudulently withdrawn from her bank account across multiple transactions. 47.The appellant's witness, Peter Kiome, maintained that mobile banking is PIN-protected and managed exclusively by the bank's security protocols. 48.The second respondent's witness, Gideon Mwaliga, testified that the SIM swap followed proper procedures because the requester answered personalized security questions within the agent's geographic proximity criteria, adding that no money was lost via the mobile money platform and that the telecom provider has no control over banking applications. 49.In addressing the legal issues, the first respondent argues that both the appellant and the second respondent breached their contractual and statutory duties of care. 50.The appellant is accused of negligence for permitting fraudulent transfers, ignoring immediate red flags from rapid sequential withdrawals, allowing single-day transaction volumes to exceed reasonable individual limits, and permitting unauthorized access to personal data. 51.Conversely, the second respondent is asserted to have breached its duty by failing to successfully block the line on the night of February 6, allowing an irregular SIM swap and cloning by fraudsters, and subsequently executing a premature reactivation before ensuring the line was secure. 52.On the principle of causation, the first respondent contends that the second respondent's negligence was the proximate cause of the financial injury. 53.To ground this, the first respondent cites Timsales Limited v. Stanley Njihia Macharia [2016] eKLR, which approved the holdings in South Nyanza Sugar Co. Ltd v. Wilson Ongumo Nyalwemba [2008] eKLR and Statpack Industries Limited v. James Mbithi Munyao HCCA No. 157 of 2003 (UR), noting that while the burden of proof rests on the plaintiff to establish a balance-of-probabilities connection between negligence and injury, SIM-swap attacks inherently establish close temporal and causal links to tangible financial loss because the unauthorized control of a phone line is immediately exploited for password resets and banking access. 54.Statutory liability is invoked through Section 65(1) and (2) of the Data Protection Act, which mandates compensation for individuals suffering damage due to a data controller or processor's contravention of the Act. 55.The first respondent submits that the second respondent failed to implement proper technical and organizational safeguards under Section 43(5)(c) of the Data Protection Act, neglecting to protect her data or warn her of potential injury following the initial breach. 56.Because the second respondent's witness admitted to past disciplinary actions resulting from internal staff connivance in fraudulent SIM swaps, it is argued the telecom provider possessed full knowledge of the foreseeable risks of financial fraud linked to data breaches. 57.Consequently, the first respondent maintains that the bank account would never have been compromised without the second respondent's initial negligence and asks the High Court to uphold the lower court's judgment or assign full liability to the second respondent. 58.The 2nd Respondent, Safaricom PLC, filed submissions in support of thiir cross-appeal and they opposed the appellant’s appeal judgment delivered on March 26, 2024, by Hon. R.W. Gitau at the Mavoko Chief Magistrate's Court. 59.In the original suit, the 1st Respondent, Mercy Wairimu Kariuki, sought a refund of Kshs. 4,418,601, general damages, costs, and interest after her mobile banking application was compromised and funds were fraudulently withdrawn. 60.The trial court found both Diamond Trust Bank Kenya Limited (the Appellant) and Safaricom liable for a breach of duty of care, apportioning liability at 60% against Safaricom (ordered to pay Kshs. 2,630,000) and 40% against the bank (ordered to pay Kshs. 1,788,601). 61.Safaricom filed a Cross-Appeal to challenge this 60% liability apportionment, arguing that the trial court erred in law and fact by holding it responsible for financial losses that occurred exclusively on the bank's independent platform. 62.Safaricom establishes that its operational mandate is strictly limited to providing telecommunications infrastructure and that it exercises no control or visibility over transactions executed within the bank's mobile banking system. 63.A critical factual timeline undermines the negligence claim against Safaricom: the 1st Respondent's SIM card was swapped on February 6, 2022, but she visited Safaricom's offices and regained full control of her mobile line on February 7, 2022. 64.The 1st Respondent's bank statements and witness testimonies confirmed that the disputed fraudulent withdrawals took place on February 7 and 8, 2022, after she had already resumed full possession and use of her SIM card. 65.Safaricom’s witness, Gideon Mwaliga, proved that the SIM swaps were executed lawfully and procedurally because the requester successfully satisfied vetting criteria, including geo-location checks and personalized security questions unique to the subscriber. 66.The 1st Respondent conceded during trial that she did not lose any funds from her M-Pesa account, which is the only financial platform under Safaricom's direct control. 67.Invoking Sections 107–109 of the Evidence Act, Safaricom argues that the legal burden of proof rests firmly on the claimant and never shifts throughout the trial, meaning a claim must fail if the claimant does not prove the defendant caused the loss. 68.To support this principle regarding the burden of proof, Safaricom relies on the decisions in Alice Wanjiru Ruhiu v Messiac Assembly of Yahweh [2021] eKLR and Treadsetters Tyres Ltd v John Wekesa Wepukhulu [2010] KEHC 341 (KLR). 69.Safaricom asserts that the proximate and operative cause of the damage was either a security failure within the bank's platform or the 1st Respondent’s failure to safeguard her confidential PIN, rather than Safaricom's remote telecom services. 70.To establish that liability only attaches when a defendant's actions are the direct and proximate cause of the loss, Safaricom cites Elijah Ole Kool v George Ikonya Thuo [2001] KEHC 648 (KLR) and Edward Mzamili Katana v CMC Motors Group Ltd [2006] KEHC 2264 (KLR). 71.Safaricom notes that the 1st Respondent bears contributory responsibility because her banking application was PIN-protected; under the precedent of Kenya Commercial Bank Limited v Fredrick Mallya [2017] KEHC 1326 (KLR), a customer who negligently exposes their PIN cannot shift liability to a third party. 72.Safaricom further raises the equitable maxim that "no man can benefit from his own wrong," citing the case of Alghussein v Eton College [1988] 1 WLR 587. 73.The bank's defence that it could not produce contemporaneous transaction records because "statements are not recorded over weekends" is dismissed by Safaricom as completely implausible given that automated, modern banking systems capture customer transactions on a real-time, 24/7 basis. 74.Safaricom contends that the bank breached its duty to deploy reasonable skill and care because large, suspicious withdrawals were processed in rapid succession beyond transactional limits without the bank flagging them or contacting the customer. 75.To demonstrate that financial institutions have a legal obligation to investigate transactions that are glaringly out of the ordinary, Safaricom relies on Joe Owaka Ager v Barclays Bank of Kenya Limited [2019] KEHC 12159 (KLR) eKLR and Shalimar Flowers Self Help Group v Kenya Commercial Bank [2016] KEHC 6238 (KLR). 76.Safaricom also points to Kingdom Bank Limited v Wanjohi [2024] KEHC 2677 (KLR) to emphasize that banks cannot merely rely on transaction statements but must demonstrate that they took active, reasonable steps to recall or recover funds lost through fraud. 77.Finally, Safaricom relies on the distinct roles of telecommunications providers and financial institutions established in Wachira v Safaricom Company Limited [2024] KEHC 16425 (KLR), which rules that telecoms provide the communication infrastructure while banks operate as separate entities with independent security and Know Your Customer (KYC) duties. 78.Safaricom concludes that expanding transaction liability to telecom operators would blur essential regulatory boundaries and impose impractical obligations, and therefore prays that the High Court allows its Cross-Appeal and dismisses the bank's appeal with costs. 79.The following are the issues for determination in this appeal;i.Whether the Appellant (Diamond Trust Bank Kenya Limited) breached its duty of care owed to the 1st Respondent.ii.Whether the trial court erred in its apportionment of liability between the Appellant and the 2nd Respondent (Safaricom PLC).iii.Whether the trial court erred by not fully appreciating the nature of the banking and mobile telecommunication transactions and the standard of care required, particularly concerning non-business days and daily transaction limits.iv.Whether the 1st Respondent proved her case on a balance of probabilities against the Appellant, and whether the quantum of damages awarded was appropriate. 80.This appeal arises from the judgment of the Chief Magistrate's Court at Mavoko delivered on March 26, 2024, in Civil Suit No. 182 of 2020. 81.The trial court found the Appellant, Diamond Trust Bank Kenya Limited, liable for breach of its duty of care to the 1st Respondent and apportioned liability at 40% against the bank, leading to an award of Kshs. 1,788,601. 82.The 2nd Respondent, Safaricom PLC, was held 60% liable. Both the Appellant and the 2nd Respondent have challenged this decision through an appeal and a cross-appeal, respectively. 83.This court, acting as a first appellate court, has a duty to re-evaluate the evidence on record and draw its own conclusions, while bearing in mind that it did not have the advantage of hearing the witnesses and observing their demeanor. 84.This duty was aptly stated in the case of Selle & another v. Associated Motor Boat Co. Ltd. & others (1968) EA 123. 85.The main question in this matter is whether the trial court's apportionment of liability was correct in law. 86.The Appellant contends that the sole proximate cause of the loss was the SIM swap conducted by the 2nd Respondent, and that its own actions were a secondary, subsequent event that did not cause the loss but merely failed to mitigate it. 87.This argument, however, overlooks the independent and concurrent duties of care owed by both a bank and a telecommunications provider to their respective customers. 88.The law is clear that a bank owes a fiduciary duty to its customer to exercise reasonable skill and care in handling the customer's account. 89.As was stated in Fidelity Commercial Bank Limited v Italian Market Kenya Limited (Civil Appeal No. 248 of 2015) [2017] eKLR, a bank is under an obligation to exercise reasonable skill and care, and this duty applies to interpreting, ascertaining, and acting in accordance with the instructions of the customer. 90.While the SIM swap was the enabling event that gave the fraudsters control of the 1st Respondent's phone line, the financial loss occurred when the Appellant's banking system permitted the fraudulent withdrawals. 91.The Appellant's reliance on the principle of novus actus interveniens to break the chain of causation is not persuasive. 92.The fraud was a continuous sequence of events: the SIM swap compromised the 1st Respondent's line, which was then used to access her bank account and transfer funds. 93.The bank's failure to act on the red flags of rapid, sequential, and large transactions was not a new and independent cause that superseded the SIM swap; it was a failure to discharge its own duty to safeguard the customer's funds. 94.The trial court correctly rejected the Appellant's argument that it was not liable simply because the correct PIN was entered. 95.A bank cannot hide behind a customer's PIN when it is presented with a series of transactions that are so glaringly out of the ordinary that a reasonable banker would have been put on inquiry. 96.A bank is expected to flag suspicious transactions. In this case, the withdrawals from multiple unrelated accounts and mobile numbers in quick succession constituted significant red flags that the Appellant ought to have heeded. 97.The Appellant's argument regarding the transactions being processed over non-business days does not absolve it of liability. 98.The banking system operates on an automated 24/7 basis. The Appellant cannot use the defence that it was a "non-business day" to avoid its duty to monitor and flag suspicious activity. 99.While it is true that the system may have a daily limit, the fraudsters exploited the reset of this limit to make multiple withdrawals. 100.This demonstrates the very nature of the system's vulnerability that the bank was obliged to safeguard against. 101.A simple technical compliance with a daily limit does not satisfy the broader duty of care to protect a customer from loss. 102.A bank is expected to exercise reasonable care and cannot simply rely on the fact that a transaction was initiated using the correct PIN if there are other suspicious circumstances. The fraud originated from its actions. 103.The unauthorized SIM swap was a direct breach of its duty to protect the 1st Respondent's personal data and telecommunications line. 104.The 1st Respondent promptly reported the suspicious activity on the day of the swap, yet the fraud was still executed, and her line was only reinstated the following day. 105.This constitutes a breach of its duty of care and a failure to protect her data. The jurisdiction of the court was properly invoked for a claim of negligence and breach of a duty of care, and the trial court was correct to entertain it. 106.This court finds that the trial court's apportionment of liability was neither perverse nor erroneous in law. 107.Both the bank and the mobile service provider had concurrent duties of care to the 1st Respondent. 108.The SIM swap was the catalyst, but the bank's failure to protect the account was equally an operative cause of the loss. 109.The trial court correctly identified that both parties were negligent and that their actions jointly led to the 1st Respondent's loss. 110.The finding that the Appellant was 40% liable for the sum of Kshs. 1,788,601 is a reasonable and just apportionment of liability. 111.The Appellant's appeal lacks merit. The 2nd Respondent's cross-appeal also fails, as the evidence shows its actions were a direct and proximate cause of the loss. 112.The trial court's judgment is therefore upheld in its entirety. 113.The Appellant's appeal is dismissed with costs to the 1st Respondent. 114.The 2nd Respondent's cross-appeal is also dismissed with costs to the 1st Respondent. 115.The judgment and decree of the Chief Magistrate's Court at Mavoko in Civil Suit No. 182 of 2020 is hereby affirmed in all respects. 116.Orders to issue accordingly. DATED, SIGNED AND DELIVERED AT NAIROBI THIS 18TH DAY OF JUNE 2026.ASENATH ONGERIJUDGEIn the presence ofMr Mulyungi holding brief for Mr Ludenyo for the AppellantMr Ongwen for the 2nd RespondentMr Mwangi for the 1st RespondentChrispin - Court Assistant