STK is used in Kenya to facilitate SMS Banking using primarily GSM phones for transmission of the SMS messages. While providing a valuable banking solution it is not without security risk, some of which has been exploited. This paper will describe the underlying architecture of Kenyan STK based M-Pesa banking, various vulnerabilities will be discussed and methods suggested to overcome them.