Free cookie consent management tool by TermsFeed Skip to content
Blog The State of Cybersecurity in Kenya in 2026
Cybersecurity August 17, 2026 9 min read

The State of Cybersecurity in Kenya in 2026

Kenya's digital economy has grown faster than almost any other in the region, and that growth has come with a cost. In 2026 the country has recorded some of the highest volumes of cyber threat activity ever logged by its national monitoring agencies, alongside a string of visible incidents that have

J

Justus A. Amito

Intellinks East Africa

Kenya's digital economy has grown faster than almost any other in the region, and that growth has come with a cost. In 2026 the country has recorded some of the highest volumes of cyber threat activity ever logged by its national monitoring agencies, alongside a string of visible incidents that have put government systems, telecoms, and financial platforms under uncomfortable scrutiny. This is a look at where things stand, based on figures from the Communications Authority of Kenya, the National KE CIRT CC, INTERPOL, and independent threat intelligence researchers.

The numbers behind the noise

The Communications Authority of Kenya, through the National Kenya Computer Incident Response Team Coordination Centre (KE CIRT CC), publishes a quarterly cybersecurity report, and the figures for 2026 are staggering even by past standards.

Between January and March 2026, the KE CIRT CC detected over 3.37 billion cyber threat events, a 26.15 percent decline from the previous quarter but still an enormous number by any measure. Roughly 96 percent of these, about 3.23 billion incidents, were classified as system attacks, meaning attempts to exploit vulnerabilities in network devices, operating systems, databases, and other critical infrastructure. The remainder was split across malware (68.7 million), brute force attacks (46.4 million), web application attacks (12.1 million), DDoS attacks (8.2 million), and mobile application attacks (219,549). During the same quarter the Authority issued 20.58 million cyber threat advisories to organisations and internet users.

The trend continued into the second quarter. Between April and June 2026, Kenya recorded more than 2.3 billion cyber threat events, a further 30.03 percent decline from the previous quarter. System attacks again dominated, accounting for more than 2.25 billion incidents. Malware attacks reached nearly 59 million and brute force attempts topped 24 million, while web application attacks totalled over 17.4 million.

The Authority attributes the persistence of this threat environment to a familiar set of weaknesses: inadequate system patching, low public awareness of phishing and social engineering, and the increasing use of artificial intelligence by cybercriminals to automate and scale attacks.

Kenya named the region's top target

INTERPOL's 2026 African Cyberthreat Assessment placed Kenya at the top of the list as East Africa's most vulnerable nation to cybercriminal activity, pointing to a 327 percent increase in SIM swap fraud and mobile money attacks. The report argues that Kenya's digital economy has expanded faster than its capacity to secure the systems underpinning it, with mobile financial services, telecom networks, and government platforms singled out as the weakest points. Kenya's heavy dependence on mobile money and mobile connectivity, while a genuine development success story, has also become one of its biggest points of exposure.

The telecom sector alone recorded more than 46,786 DDoS incidents in the first half of 2025, a figure INTERPOL cites as evidence of how much pressure critical infrastructure is already under. In response, Kenya has introduced the Computer Misuse and Cybercrimes Amendment Bill 2024 to address SIM swap fraud and scam calls, though INTERPOL cautions that legislation on its own will not be enough against threats that are increasingly cross-border and fast evolving.

The presidency website breach

The most visible incident of the year so far took place on Saturday, 18 July 2026, when hackers defaced the official website of the presidency, president.go.ke. The homepage was replaced with messages targeting President William Ruto and a ransom note demanding five bitcoin, worth roughly 320,000 US dollars or about 41.3 million Kenyan shillings, along with a threat to leak sensitive government data if the demand went unmet by a set deadline.

Cabinet Secretary for Information, Communications and the Digital Economy William Kabogo confirmed the breach and said the ICT Authority had detected the incident and activated its cybersecurity response protocols. Access to the site was temporarily restricted while forensic teams investigated, and the government maintained that no evidence of unauthorised access to sensitive data or data exfiltration had been found, and that no core state databases were compromised. Reports indicate the site was restored within a couple of days.

As of the most recent reporting, no hacker group has publicly claimed responsibility, and the government has not attributed the attack to a specific actor or country. It is currently treated as a financially motivated extortion attempt rather than a confirmed politically or state linked operation, though the forensic investigation is ongoing.

This was not an isolated event. It follows a pattern of high profile hits on Kenyan public sector systems. In July 2023, the hacktivist collective Anonymous Sudan disrupted the eCitizen platform with a DDoS attack that affected more than 5,000 government services, including systems used by the National Transport and Safety Authority and Kenya Power. Then on 17 November 2025, a group calling itself PCP@Kenya carried out a coordinated attack on several government websites, defacing them with extremist propaganda and knocking some offline, affecting ministries including Interior, Health, Education, ICT, Labour, Environment, and Tourism. The government maintained at the time that no sensitive data had been leaked.

Taken together, the presidency defacement is the third major public sector cyber incident Kenya has experienced within three years, a pattern that has intensified rather than eased.

Beyond the presidency: other flagged incidents

The Kenya National Highways Authority (KeNHA) was listed on the leak site of the Deadlock ransomware group on 25 July 2026. As with most ransomware leak site listings, this represents the attacker's own claim rather than an independently confirmed breach, and KeNHA has not publicly confirmed the extent of any compromise. Threat intelligence researchers note that if such a listing is genuine, the exposure could extend well beyond the agency itself, potentially touching contractors, consultants, landowners, and citizens whose identification documents, banking details, or project-related personal information may sit in internal systems.

Independent threat intelligence firm CYFIRMA, tracking the period between January 2025 and February 2026, identified 11 separate ransomware or data exposure claims against organisations in Kenya and Tanzania, attributed to seven different threat groups including Qilin, TheGentlemen, and Incra. Separately, on 5 March 2026, a threat actor advertised a Kenya based credential database on a cybercrime forum, described as containing more than 20,000 email and password pairs. CYFIRMA notes that a number of these claims, including one tied to the RansomHub leak portal, could not be independently verified because the portal itself was inaccessible at the time of review, so some of this activity should be read as reconnaissance or unverified extortion attempts rather than confirmed breaches.

The same research flagged 2026 as a year of heightened exposure given several large technology and cybersecurity conferences scheduled in Nairobi and Mombasa, events that concentrate government officials, financial institutions, and infrastructure operators in one place and, in doing so, create attractive targets for espionage and disruption.

Where the weaknesses lie

A recurring theme across these reports, and one raised pointedly by Kenyan civil society, is that many of these incidents were foreseeable. Auditor General Nancy Gathungu's report for the financial year ending June 2023 had already flagged that the eCitizen platform was operating without an approved ICT policy, without an ICT steering committee, without an approved business continuity plan, and without a secondary backup site. That warning was tabled in Parliament before the platform was breached days into the following financial year. In the last week of July 2026, the National Assembly's Public Accounts Committee, chaired by Butere MP Tindi Mwale, took evidence from Energy Principal Secretary Alex Wachira on related failings.

This points to a gap that goes beyond technical vulnerabilities. It is a governance gap, where known risks are documented but not resourced or acted on until after something breaks.

What is driving the surge

A few factors run through nearly every report published this year.

Kenya's rapid digital transformation, spanning cloud adoption, mobile payments, e government services, and a growing number of internet connected devices, has expanded the attack surface faster than defensive capacity has kept pace. The Communications Authority has flagged cryptocurrency exchanges, foreign exchange trading platforms, and online gambling websites as emerging high risk sectors as digital services keep multiplying.

Artificial intelligence is showing up on both sides of the fight. Threat actors are increasingly using AI generated phishing emails, spoofed domains, deepfakes, and automated attack tooling, while system misconfiguration, especially in cloud environments and databases with weak access controls, continues to be exploited for privilege escalation and lateral movement.

Human factors remain just as significant as technical ones. Low public awareness of phishing and social engineering, combined with inadequate patching cycles across both government and private sector systems, keeps giving attackers an easy way in even when the underlying vulnerabilities are well known.

The response so far

On the policy side, Kenya has moved to introduce the Computer Misuse and Cybercrimes Amendment Bill 2024, targeting SIM swap fraud and scam calls specifically. On the capacity building side, the KE CIRT CC partnered with the United Kingdom's Foreign, Commonwealth and Development Office to run a five day training programme in Nairobi in early March 2026, bringing together 85 participants from 25 organisations, including government agencies, critical infrastructure operators, and academic institutions. The training focused on threat intelligence sharing platforms such as MISP and the PinPoint analytical tool, aimed at helping organisations exchange threat data quickly without running into legal or trust barriers. This was delivered under the final phase of the UK funded Africa Cyber Programme.

The Communications Authority has continued to urge organisations across sectors to prioritise regular system updates, strengthen employee awareness training, implement stronger access controls, and adopt proactive threat monitoring rather than reactive incident response.

The bigger picture

None of this suggests Kenya is uniquely under siege compared to peer economies going through similar digital growth. What it does suggest is that the country's ambition to digitise government services, financial systems, and public infrastructure has, for now, outpaced its investment in the people, policy, and technical controls needed to protect those systems. INTERPOL's own assessment makes that point directly: legal reform alone will not be enough against threats that are cross-border, fast-moving, and increasingly automated.

For a country that has built much of its recent economic story on mobile money, digital government, and a fast-growing tech sector, closing that gap is not optional. The billions of threat events logged every quarter are mostly automated noise that gets filtered out before doing damage. But incidents like the presidency website breach, the KeNHA ransomware listing, and the string of credential leaks show that when the noise does get through, it reaches systems that ordinary Kenyans depend on every day.

J

Written by

Justus A. Amito

Technical insights from the Intellinks East Africa team on IT security, backup, cloud and operations.

More articles

Share this article

Explore more insights

Practical thinking on IT security, backup, cloud and operations for East Africa.