Incidents of distributed denial-of-service (DDoS) attacks in Kenya rose to 72.16 million in the year ended June 2026, up from 33.68 million a year earlier, according to the Communications Authority of Kenya (CA). This represents a 114.3 percent increase, the highest growth among cyber threats tracked by the regulator. The rise highlights the growing exposure of businesses and public systems as more services move online.
DDoS attacks occur when attackers flood a website, server, or network with high malicious traffic to overwhelm its capacity and make it slow or inaccessible to legitimate users. Attackers often use networks of malware-infected computers and other connected devices, known as botnets, to send large numbers of requests to a target at the same time. This results in service downtime, stopping customers from buying items, logging into accounts, or using online services.
Companies and government agencies end up losing money from missed sales or services, and expensive emergency fixes. Experts have also warned that hackers sometimes use a DDoS attack as a distraction to hide data theft or malware installation on the network. Kenya has previously experienced high-profile DDoS attacks targeting government digital services, including the eCitizen platform in July 2023.
The eCitizen platform, the government’s online services portal, was hit by a major attack that temporarily disrupted access to key agencies. Kenya Power, Kenya Railways and the National Transport and Safety Authority (NTSA) were among the systems reported to have been affected at the time. The government said no data had been accessed or lost, and the hacktivist group Anonymous Sudan claimed responsibility.
The increase in DDoS threats comes as Kenya's digital economy expands, increasing the number of systems and services that rely on internet connectivity. The CA data also shows web application attacks targeting flaws, poor coding, or security gaps in websites, web services, and application programme interfaces (APIs) increased 99 percent to 51.51 million, from 25.89 million in the previous year.
Malware attacks, where cybercriminals use malicious software to infiltrate a computer system or network to steal data, damage operations, or gain unauthorised access, rose 64.8 percent to 230.31 million, from 139.76 million. Overall, the regulator detected 11.1 billion cyber-threat incidents in the year to June 2026, a 29 percent increase from 8.6 billion a year earlier.
System vulnerabilities – weaknesses or flaws in a computer system’s design, code, hardware – remain Kenya’s largest category, accounting for 10.6 billion incidents, or 95.4 percent of all threats recorded in the year to June 2026. The regulator has previously linked the rise of cyber threats to inadequate system patching, limited user awareness of phishing and social engineering, and the increasing use of AI-driven and machine-learning tools by malicious actors.
Key points
- DDoS attacks in Kenya rose 114.3 percent to 72.16 million in the year ended June 2026.
- Web application attacks increased 99 percent to 51.51 million, and malware attacks rose 64.8 percent to 230.31 million.
- Overall, 11.1 billion cyber-threat incidents were detected in the year to June 2026, a 29 percent increase from 8.6 billion a year earlier.