Home News Kenya records over 11 billion cyber threats as digital attacks surge by 29 per cent

Kenya records over 11 billion cyber threats as digital attacks surge by 29 per cent

by Bonny
0 comment

Kenya faced a sharp rise in cyber threats during the financial year ending June 2026, with millions of attempts targeting digital systems, networks and online services across the country.

Data from the Communications Authority of Kenya (CA) shows that 11,124,632,684 cyber threats were recorded during the 2025/2026 financial year. The figure represents a 29 per cent increase from the 8,622,876,858 threats recorded in the previous financial year.

Among the threats that recorded a major increase were Distributed Denial-of-Service (DDoS) attacks, which more than doubled during the period. The attacks rose by 114.3 per cent to 72,164,664, compared with 33,680,462 recorded in the 2024/2025 financial year.

DDoS attacks happen when an online system, network or service is flooded with large volumes of traffic or requests. The high volume can make it difficult for legitimate users to access the targeted service.

Despite the sharp annual increase, the CA data shows that DDoS activity fell significantly towards the end of the financial year. The regulator recorded 819,325 attacks between April and June 2026, a 90 per cent drop from the 8,202,803 attacks recorded between January and March 2026.

The figures show that the increase recorded across the financial year was largely linked to activity reported during earlier periods.

Other categories of cyber threats also increased during the 12-month period. Malware attacks rose by 64.8 per cent to 230,307,810, while web application attacks increased by 99 per cent to 51,508,883.

Mobile application attacks also went up by 54 per cent to 789,826 during the financial year. Brute force attacks increased by 3.6 per cent to 132,225,836.

Also Read  New CA rules force cyber cafés to register customers and keep logs for three years

Brute force attacks involve repeated attempts to gain unauthorised access to systems or accounts, often by trying different passwords or login details.

System vulnerabilities remained the biggest category recorded by the regulator. The CA reported 10,637,635,755 incidents in this category during the financial year, representing a 28.2 per cent increase from the previous period.

The increase in cyber threats was accompanied by a rise in cyber security advisories issued by the regulator. A total of 83,096,015 advisories were recorded during the financial year, up from 51,663,024 in 2024/2025. This represented a 60.8 per cent increase.

Brute force advisories recorded the largest increase, rising by 365.5 per cent during the period. Web application advisories followed with an increase of 110.5 per cent.

DDoS advisories also increased, although at a much smaller rate. The CA recorded 2,673,948 DDoS advisories during the financial year, representing a 3.1 per cent rise from the previous period.

You may also like

You cannot copy content of this page