Presidency hack raises Kenya security concerns

Hackers breached Kenya’s presidency website on 18 July 2026, targeting President William Ruto.
Hackers breached Kenya’s presidency website on 18 July 2026, targeting President William Ruto.

Hackers breached Kenya’s presidency website on 18 July 2026, replacing its homepage with messages targeting President William Ruto and demanding 5 Bitcoin worth about $320,000 (KSh41.3 million), alongside a threat to leak data.

The government took the site offline within hours and said no core state databases were accessed.

The incident highlights growing cybersecurity risks as Kenya expands its digital public services.

The defacement of president.go.ke is the third major public-sector cyber incident in Kenya in three years.

In July 2023, the hacktivist group Anonymous Sudan disrupted the eCitizen platform with a distributed denial-of-service attack, affecting more than 5,000 services.

In November 2025, coordinated attacks defaced multiple ministry websites, exposing weaknesses in government systems, according to the National Computer and Cybercrime Coordination Committee (NC4).

ITWeb Africa has previously reported that as governments digitise services, cyber threats are increasing, with public-sector platforms becoming frequent targets due to their scale and visibility.

William Kabogo, cabinet secretary for information, communications and the digital economy of Kenya, said response protocols were activated immediately and no sensitive data was compromised.

Officials have not attributed the attack to a known group, and no ransom is believed to have been paid.

The breach has renewed scrutiny of whether cybersecurity investment is keeping pace with Kenya’s digital ambitions.

Kenya has prioritised digitisation through initiatives such as digital identity systems and expanded online services, increasing reliance on digital platforms.

Software engineer Ernest John Ndungu said visible investment in cybersecurity is essential to maintain public trust.

“The government needs to show citizens it is investing in cybersecurity. People trust what they see and hear, not just what they are told,” he said.

Ndungu said cybersecurity requires continuous adaptation as threats evolve rapidly.

“A defence mechanism today can become obsolete in a week or a month, so continuous vigilance is needed,” he said.

He recommended regular security testing, audits and continuous monitoring to identify vulnerabilities.

Ndungu said the attack appeared to target a public-facing portal rather than core systems, adding that the recovery time suggested some response capability.

However, repeated incidents point to a widening attack surface as more services move online.

As Kenya advances its digital economy strategy, experts say strengthening cybersecurity resilience will be critical to protecting systems and maintaining public trust.

Based in Nairobi, Sharon W. Kiburi is a multimedia data journalist, researcher, and trainer specialising in data journalism, illicit financial flows , and gender disparities.

Share

Read more
ITWeb proudly displays the “FAIR” stamp of the Press Council of South Africa, indicating our commitment to adhere to the Code of Ethics for Print and online media which prescribes that our reportage is truthful, accurate and fair. Should you wish to lodge a complaint about our news coverage, please lodge a complaint on the Press Council’s website, www.presscouncil.org.za or email the complaint to enquiries@ombudsman.org.za. Contact the Press Council on 011 484 3612.
Copyright @ 1996 - 2026 ITWeb Limited. All rights reserved.