Kenya Ranked 2nd in Africa for Cyberattacks: Alarming Interpol Report Exposes Growing Digital Threat
Kenya ranks 2nd in Africa for cyberattacks, an Interpol report warns, as DDoS, SIM swap fraud, and phishing surge nationwide.

Kenya cyberattacks have reached a level that international police can no longer ignore. A new report from Interpol has placed Kenya as the second-most vulnerable country in Africa to cyberattacks, behind only South Africa and ahead of Nigeria. The findings come from the Interpol African Cyberthreat Assessment Report 2026, which paints a troubling picture of a nation whose digital growth has outpaced its ability to protect itself.
According to the report, Kenya accounted for nearly 12 percent of all exploitable digital vulnerabilities detected across the continent in 2025. That figure alone tells a story, but the details behind it are even more concerning. Outdated router firmware, unsecured VPNs, poor patching habits, and weak authentication controls have turned government systems, telecom networks, and mobile money platforms into easy targets. The consequences are already visible: a defaced presidential website, a major airline data breach, and hundreds of thousands of fraudulent SIM cards issued in a single year.
This article breaks down what the Interpol report actually found, why Kenya has become such an attractive target for hackers, which sectors are most exposed, and what needs to change if the country wants to shake off its reputation as East Africa’s cybercrime hotspot.
What the Interpol Report Reveals About Kenya
The Interpol Africa cyberthreat report is one of the most detailed continental assessments of digital risk published to date. It ranks countries based on the share of exploitable vulnerabilities detected within their digital infrastructure, not just the number of attacks recorded.
Kenya’s numbers stand out for several reasons:
- Kenya recorded 11.9 percent of all exploitable digital vulnerabilities identified across Africa in 2025.
- South Africa topped the list at 43.6 percent, while Nigeria followed Kenya at 9.1 percent.
- Regional neighbors trailed far behind: Tanzania sat at 3 percent, Uganda at 0.5 percent, and Burundi at just 0.3 percent.
- Kenya also appeared among global top phishing detections tracked by threat intelligence firm SOCRadar in September 2025.
Interpol was blunt about the cause. The vulnerabilities exploited were not sophisticated zero-day flaws requiring advanced skill. They were well-known, publicly documented weaknesses that should have been patched long ago. This points less to a lack of technical talent in Kenya and more to a systemic failure in cybersecurity investment, governance, and follow-through.
Why Kenya Ranks Second in Africa for Cyberattacks
Several structural factors explain why Kenya cybersecurity gaps have become so pronounced, even as the country markets itself as East Africa’s technology hub.
Outdated Infrastructure and Poor Patch Management
A large share of the vulnerabilities Interpol identified trace back to internet routers running old firmware with known security holes. Many organizations, both public and private, simply don’t update their systems on a regular schedule. The Communications Authority of Kenya has separately flagged legacy systems, weak authentication controls, and internet-connected devices left with default credentials as some of the most common entry points for attackers in the country.
Unsecured VPNs and Remote Access Tools
As more Kenyan institutions adopted remote work and cloud-based tools, many did so without properly securing the virtual private networks meant to protect that access. Hackers have exploited these gaps to slip past perimeter defenses and reach sensitive internal systems.
Weak Document Management Platforms
The report also flagged vulnerabilities in online document management platforms used by government agencies and businesses. These systems often hold sensitive records, making them a high-value target once a breach occurs.
Heavy Reliance on Mobile Money
Kenya’s digital economy runs on mobile money. That strength is also a weakness. The scale of mobile financial transactions gives cybercriminals a massive attack surface, and fraud schemes built around SIM swaps and mobile wallets have scaled accordingly.
Underreporting and Weak Disclosure Requirements
Interpol’s broader survey found that 89 percent of African member countries cited underreporting as a persistent challenge. Kenya is one of only four countries on the continent, alongside Nigeria, South Africa, and Mauritius, that mandates breach disclosure within 72 hours. Even with that requirement, many organizations still lack formal incident reporting mechanisms, and businesses often avoid disclosure out of fear of reputational damage.
Key Cyberattack Trends Targeting Kenya
The Interpol cyberthreat report doesn’t just rank vulnerabilities. It tracks the actual crimes being committed using the access those vulnerabilities create. A few trends define the current threat landscape in Kenya.
1. DDoS Attacks on Telecom Networks
Kenya recorded more than 46,786 Distributed Denial-of-Service (DDoS) attacks in just the first half of 2025, almost all aimed at telecom companies. In a DDoS attack, criminals flood a target’s servers with overwhelming traffic from multiple compromised devices, knocking services offline for ordinary users. Given how much of Kenya’s economy depends on connectivity, an attack on telecom infrastructure has ripple effects across banking, business, and daily communication.
2. SIM Swap Fraud
SIM swap fraud increased by an alarming 327 percent during 2025. More than 123,000 fraudulent SIM cards were issued, and an estimated $3.8 million was stolen directly from mobile wallets. In a SIM swap, a criminal convinces or bribes a telecom employee, or exploits a weak verification process, to transfer a victim’s phone number to a SIM card they control. From there, they can intercept one-time passwords and drain mobile money accounts.
3. Phishing Campaigns
Kenya’s inclusion among global top phishing detections in September 2025 shows that attackers are actively targeting Kenyan users and organizations with deceptive emails, messages, and fake websites designed to steal credentials.
4. Ransomware and Business Email Compromise
While South Africa dominates the continent’s ransomware statistics, accounting for 92 percent of all ransomware detections in Africa, Kenya has not been spared. Criminal groups have also used business email compromise tactics, a scam where attackers impersonate executives or vendors to trick employees into transferring funds or sensitive data.
5. Mobile Money Fraud
Given how central mobile money is to daily life in Kenya, it remains one of the most exploited channels for financial crime, with leaked personal data feeding directly into fraud schemes.
How Kenya Compares to Other African Countries
Understanding Kenya’s position requires looking at the wider regional picture:
| Country | Share of Africa’s Exploitable Vulnerabilities |
|---|---|
| South Africa | 43.6% |
| Kenya | 11.9% |
| Nigeria | 9.1% |
| Tanzania | 3.0% |
| Uganda | 0.5% |
| Burundi | 0.3% |
South Africa’s higher overall share reflects the size and maturity of its digital economy, which simply gives attackers a larger surface to probe. Kenya’s position, however, is notable precisely because its digital economy, while significant, is smaller than South Africa’s. That means Kenya is punching above its weight in the wrong direction, carrying a disproportionate share of continental risk relative to its size.
Cameroon also stands out regionally, recording 40.5 million botnet detections in 2025, the second-highest figure in Africa, while Angola showed similarly elevated levels of compromised device activity. These numbers reinforce a broader theme in the Interpol assessment: cybercrime in Africa is no longer isolated to a handful of countries. It has become a continent-wide, interconnected problem.
The Role of Artificial Intelligence in Africa’s Cybercrime Surge
One of the most striking findings in the Interpol report is how much artificial intelligence now shapes cybercrime. According to the assessment, 55 percent of cybercrimes reported across Africa in 2025 involved AI in some form. Criminal networks are using AI tools to:
- Automate phishing campaigns and make them more convincing
- Generate deepfake content and AI-driven scams that exploit leaked personal data
- Launch attacks faster and at greater scale across multiple countries simultaneously
- Adapt to defenses in real time, making detection harder for security teams
Cybercrime-related financial losses across Africa have more than doubled since 2024, reaching an estimated $484 million. That surge lines up closely with the growing role of AI in attack automation, suggesting the two trends are directly connected.
Real-World Impact: Recent Cyberattacks in Kenya
Statistics only tell part of the story. A few recent incidents show what these vulnerabilities look like in practice.
In July 2026, hackers breached the official website of President William Ruto, defacing the homepage with messages directed at the president and demanding a ransom of five bitcoins, worth roughly Sh41 million at the time. The attackers threatened to leak unspecified data if the ransom went unpaid. Authorities took the site offline immediately, and Information, Communications and the Digital Economy Cabinet Secretary William Kabogo said there was no evidence that sensitive government data had been accessed. The site was restored within two days.
Kenya Airways has also dealt with a passenger data breach linked to a cyberattack, underscoring that the risk extends well beyond government systems into major private-sector institutions that handle large volumes of customer data.
These incidents, combined with the DDoS and SIM swap figures cited above, show a pattern: attackers are probing every layer of Kenya’s digital infrastructure, from state institutions to telecom carriers to commercial airlines.
What Kenya Must Do to Strengthen Its Cybersecurity
Interpol’s findings amount to a warning rather than a verdict. Kenya’s ranking can change, but only with deliberate investment and policy follow-through. Based on the gaps identified in the report, several priorities stand out.
1. Modernize Infrastructure and Patch Management
Government agencies and private companies need routine, enforced patching schedules for routers, servers, and software. Most of the vulnerabilities Interpol identified were already publicly known, meaning they were preventable with basic maintenance.
2. Strengthen VPN and Remote Access Security
Organizations relying on remote access tools should adopt multi-factor authentication, regular security audits, and updated encryption standards rather than treating VPNs as a set-and-forget solution.
3. Improve Telecom-Level Fraud Controls
Given the scale of SIM swap fraud, telecom operators need stronger identity verification processes before transferring a phone number to a new SIM card, along with faster fraud detection systems for mobile money platforms.
4. Build Formal Incident Reporting Systems
Kenya already mandates 72-hour breach disclosure, which puts it ahead of most African nations. The next step is making sure every organization, not just large institutions, has the internal processes to actually meet that requirement without fear of reputational fallout discouraging honest reporting.
5. Invest in Cybersecurity Workforce and Training
Closing the skills gap in both the public and private sectors will reduce reliance on ad hoc security fixes and build long-term institutional resilience.
6. Increase Public-Private Collaboration
Since telecoms, banks, and government agencies are all targeted through overlapping vulnerabilities, coordinated threat intelligence sharing between these sectors would help identify attacks earlier.
Regional and Global Cooperation Against Cybercrime
Interpol has stressed that fragmented national responses allow criminal networks to exploit gaps between countries’ laws and enforcement capacity. Cybercrime rarely respects borders, and a criminal group operating out of one jurisdiction can just as easily target victims in another.
This is part of why coordinated operations matter. Under Operation Red Card 2.0, law enforcement agencies across Africa worked together on cybercrime enforcement, part of a broader continental push that has led to more than 1,600 arrests tied to attacks on critical infrastructure. You can read more about Interpol’s cybercrime operations and continental strategy on its official site, which outlines how the organization coordinates cross-border investigations.
For readers who want the original reporting behind the figures cited in this article, the Interpol Africa cyberthreat findings as reported by Daily Nation provide additional context on how the rankings were calculated.
Conclusion
Kenya’s ranking as Africa’s second most vulnerable country to cyberattacks is a wake-up call rather than a surprise, given how quickly the country’s digital economy has expanded without matching investment in security fundamentals. The Interpol African Cyberthreat Assessment Report 2026 makes clear that the problem isn’t exotic hacking techniques but basic, preventable failures: outdated firmware, unsecured VPNs, weak patch management, and underreporting. With DDoS attacks battering telecom networks, SIM swap fraud rising by 327 percent, and AI now powering more than half of the continent’s cybercrime, the stakes for Kenya’s businesses, government agencies, and everyday mobile money users keep climbing. Addressing this will require sustained investment in infrastructure, stronger telecom-level fraud controls, better incident reporting, and closer regional cooperation, all treated as ongoing priorities rather than a one-time response to a bad headline.











