• Home
  • Technology
  • Kenyan websites hit by 72 million DDoS attacks as cyber...

Kenyan websites hit by 72 million DDoS attacks as cyber threats surge 114%

26, Sep 2026 / 3 min read / By Livenow Africa

Kenyan websites, servers and online services faced more than 72 million distributed denial-of-service attacks in the year to June 2026, exposing the growing cybersecurity risks facing a country increasingly dependent on digital infrastructure.

Data from the Communications Authority of Kenya shows that detected distributed denial-of-service, or DDoS, attacks increased by 114.3 per cent to 72.16 million during the 2025/26 financial year, from 33.68 million a year earlier.

The increase was the fastest among major categories of cyber threats tracked by the regulator.

A DDoS attack works by overwhelming a website, server or online service with enormous volumes of traffic, making it slow or completely inaccessible to legitimate users.

More on this story

Kenyan websites hit by 72 million DDoS attacks as cyber threats surge...

Veloura

Attackers frequently achieve this using botnets — networks containing large numbers of compromised computers, phones, routers and other internet-connected devices.

The surge matters because more Kenyan economic and government activity now depends on continuous internet connectivity.

Banks, hospitals, government portals, telecommunications companies, e-commerce platforms, media organisations and other businesses can suffer significant disruption when critical online systems become unavailable.

11.1 billion cyber threats detected

DDoS attacks represent only one part of Kenya's rapidly expanding cyber threat environment.

The Communications Authority recorded about 11.1 billion cyber-threat events during the financial year to June, compared with 8.6 billion the previous year — an increase of about 29 per cent.

Web application attacks almost doubled from 25.89 million to 51.51 million.

Malware incidents increased by 64.8 per cent to 230.31 million from 139.76 million.

System vulnerabilities remained by far the largest category, accounting for about 10.6 billion detected threats.

Official Communications Authority reports have also demonstrated how quickly attack volumes can fluctuate.

During October to December 2025 alone, the National Kenya Computer Incident Response Team Coordination Centre detected more than 58 million DDoS threats. The authority said many involved compromised mobile devices and Android television sets, with attackers exploiting poor credential management.

Between January and March 2026, detected DDoS threats fell sharply to about 8.2 million, illustrating the highly volatile nature of cyberattack campaigns.

Why DDoS attacks matter

A DDoS attack does not necessarily mean hackers have stolen information.

Its immediate purpose is usually disruption.

If thousands or millions of compromised devices simultaneously send requests to a website, legitimate users can no longer reach it.

For an online retailer, that can mean lost sales.

For a bank or mobile financial service, customers may be unable to transact.

For government, citizens could temporarily lose access to essential digital services.

Kenya has experienced the consequences before.

Government digital services, including eCitizen, were disrupted during a major cyberattack in 2023. Authorities said at the time that no data had been accessed or lost.

The increasing number of attacks comes as Kenya aggressively digitises public and private services.

That transformation creates enormous economic opportunities, but it also expands what cybersecurity professionals describe as the “attack surface” — the number of systems and devices criminals can potentially target.

Weak passwords and unpatched systems remain risks

The Communications Authority has previously identified weaknesses including inadequate software patching, phishing, social engineering and poor security practices among users.

Artificial intelligence is adding another dimension.

Cybercriminals can increasingly use automated systems to identify vulnerable targets, create convincing phishing messages and conduct attacks at scale.

At the same time, defensive systems are also using automation and artificial intelligence to detect suspicious behaviour.

For Kenyan organisations, the numbers provide a warning that cybersecurity can no longer be treated solely as an IT department problem.

Website operators need properly configured firewalls, DDoS protection, updated servers, secure APIs, monitoring and tested incident-response procedures.

Organisations should also regularly patch software and restrict administrative access.

A company can spend heavily developing a digital service only to discover that insufficient investment in cybersecurity makes the platform unreliable when it is attacked.

As Kenya moves more banking, government, health, education and commerce online, resilience will become as important as connectivity.

The country has successfully brought millions of people into the digital economy.

The next challenge is keeping the systems they depend upon online and secure.

Continue reading

You may also like

More stories selected for you
1How Much Should a Government Website Cost? State House Hack Reopens the Billion-Shilling Cybersecurity Question
2Interpol Report Reveals Why Kenya Is East Africa's Top Cybercrime Target
3State Agency Issues Warning on Cyber Attacks Targeting Critical Services
4Goodbye Phone Numbers: Digital Life Changes Forever as WhatsApp Introduces Usernames and M-Pesa Hides Transaction Contacts

Category: Technology

Related Video: Dolly Parton’s Family Announces Her Passing in Emotional Tribute

Related Explainer: Kenya’s short rains: What the 2026 forecast means for you

Tags