Kenya cyber threats reached 11.12 billion in the year to June 2026, according to the country’s communications regulator. That is 29% more than the 8.62 billion events recorded a year earlier. The sharpest jump came from DDoS attacks, which rose 114.3%.
The figures come from the Communications Authority of Kenya’s (CA) fourth-quarter Sector Statistics Report, published this month. Mobile money, online banking and eCitizen are now part of daily life, so the numbers matter well beyond IT departments. Below, we look at what drove the rise and what it really means.
How Many Cyber Threats Did Kenya Record in 2025/26?
Between July 2025 and June 2026, the National KE-CIRT/CC detected 11.12 billion threat events. The centre sits within the CA and coordinates Kenya’s response to cyber incidents. Its total compares with 8.62 billion events in 2024/25, a rise of 29%.
Activity was far from steady. Detections peaked between October and December 2025, when they reached 4.56 billion. System vulnerability exploits alone made up 4.37 billion of that quarter’s total. The final quarter brought relief, with detections falling 30% to 2.36 billion.
The table below shows each quarter of Kenya’s July-to-June financial year. Full breakdowns appear in the CA’s quarterly <a href="https://www.ca.go.ke/sites/default/files/2026-04/Cyber%20Security%20Report%20Q3%202025-2026_0.pdf” rel=”nofollow noopener” target=”_blank”>cyber security reports.
The first two quarters alone account for about 5.4 billion events, just under half the annual total.
When Did DDoS Attacks in Kenya More Than Double?
Most of Kenya’s DDoS activity in 2025/26 landed between July and December 2025. Over the full year, detections climbed 114.3%, from 33.7 million to around 72 million. A distributed denial-of-service (DDoS) attack floods a website or network with junk traffic until real users are locked out.
The later quarters show how fast the wave faded. The CA counted 8.2 million DDoS events from January to March 2026. That figure then fell 90% to just 819,325 between April and June. Together, those two quarters come to about 9 million, which leaves more than 60 million for July to December.
The CA has not named one cause for the annual jump. Earlier KE-CIRT reports, however, describe attackers abusing insecure protocols and remote desktop services to amplify traffic. Government and health sector systems were the main targets. Kenyans felt the impact in July 2023, when a DDoS campaign disrupted the eCitizen portal.
Which Other Cyber Attacks Grew Fastest in Kenya?
Second place for growth went to web application attacks, which almost doubled in Kenya’s 2025/26 figures. Several other categories also moved sharply:
- Web application attacks: up 99% to 51.5 million, often aimed at login pages and online forms.
- Malware detections climbed 64.8% to 230.3 million over the year.
- Mobile apps saw attacks grow 54% to 789,826, a small base with fast growth.
- Brute force attacks, automated attempts to guess passwords, barely moved at 3.6% growth to 132.2 million.
Growth and volume tell different stories, though. DDoS led growth at 114.3%, yet its 72 million events made up less than 1% of detections. System vulnerability exploits still dominate, as attackers probe unpatched devices, software and databases. From January to March 2026, they accounted for 3.23 billion of 3.37 billion events, about 96%.
Do 11 Billion Cyber Threats Mean 11 Billion Successful Attacks?
Not at all, because each detection records an attempt or a suspicious signal, not a confirmed breach. The count includes automated scans, exploit attempts and malicious traffic, whether or not they succeed. Picture a tally of knocks on the door: only some of them turn into break-ins.
The CA’s warnings to users also grew faster than the threats. The authority issued 83.1 million cyber advisories, up 60.8% from 51.7 million. Brute force advisories jumped 365.5% to 25.5 million, while brute force attacks rose only 3.6%. The CA has given no explanation for that gap, but it may reflect wider detection and notification efforts.
What the Communications Authority Wants Organisations to Do
Patch systems regularly, train staff and tighten access controls: that is the core of the CA’s advice. Its reports blame weak patching and low awareness for much of the volume. Phishing and criminals’ growing use of AI add to the pressure. The authority also urges proactive threat monitoring, so suspicious activity is caught early.
Better cooperation is the other priority. For April to June 2026, KE-CIRT/CC planned training with Expertise France on a Threat Intelligence Sharing Platform. The goal is for sector response teams to share threat data through standard platforms instead of ad hoc messages.
Households and small businesses can apply the same lessons. Install phone and router updates promptly, and treat unexpected links or payment requests with suspicion. You can report an incident to the National KE-CIRT/CC on +254 703 042 700. For a wider view of how attackers choose targets, read our piece on how advertising data is weaponised.
Conclusion: What Kenya’s Cyber Threat Figures Really Show
The headline number is huge, but the mix matters more. Billions of detections reflect background probing of unpatched systems. The fastest growth came in DDoS and web application attacks, which hit public services and online platforms directly. The global trend points the same way, with ransomware attacks doubling year over year. Watch the CA’s next report, covering July to September 2026, to see whether the DDoS lull holds.
