TECHNOLOGY

Kenya Faces Sharp Rise in Website Attacks

1 Mins read
Kenya Faces Sharp Rise in Website Attacks

Kenyan businesses and public institutions are facing a growing digital security threat after distributed denial-of-service (DDoS) attacks against websites, servers and networks increased by 114.3 per cent in the year to June 2026.

Data from the Communications Authority of Kenya (CA) shows that DDoS attacks rose from 33.68 million recorded in the previous year to 72.16 million by June 2026. The sharp increase was the highest growth recorded among the cyber threats monitored by the regulator.

A DDoS attack happens when criminals send huge amounts of malicious internet traffic to a website, server or network at the same time. The heavy traffic can overwhelm the system, making it slow or completely unavailable to genuine users.

Cybercriminals commonly use groups of infected computers and other connected devices, known as botnets, to generate the large volumes of traffic. The attacks can consume a system’s bandwidth, processing power and memory without necessarily gaining access to the information stored inside it.

For businesses, such disruptions can mean lost sales and customers being unable to access online services, make purchases or log into their accounts. Government agencies can also face interruptions when citizens are unable to use essential digital services.

DDoS attacks can sometimes be used to distract organisations while criminals attempt other activities, including stealing information or installing malware.

Kenya has experienced major DDoS incidents before. In July 2023, the eCitizen platform was hit by a cyberattack that temporarily disrupted access to several government services. Systems linked to Kenya Power, Kenya Railways and the National Transport and Safety Authority were also reported to have been affected. The government said no data was accessed or lost, while the hacktivist group Anonymous Sudan claimed responsibility.

Other forms of cyberattacks also increased during the year. Web application attacks rose by 99 per cent to 51.51 million from 25.89 million, while malware attacks increased by 64.8 per cent to 230.31 million from 139.76 million.

Overall, the CA detected 11.1 billion cyber-threat incidents during the 2025/2026 financial year, up 29 per cent from 8.6 billion the previous year.

System vulnerabilities remained the largest category, accounting for 10.6 billion incidents, or 95.4 per cent of all threats detected. The CA has linked the continuing threats to weak system patching, limited awareness of phishing and social engineering, and the growing use of artificial intelligence and machine-learning tools by cybercriminals.