An Interpol 2025 report on cybercrime attacks in African countries has revealed that Kenya is now one of East Africa’s biggest targets for online criminals, with attackers exploiting mobile money platforms and weak telecom safeguards.
The Interpol African Cyberthreat Assessment Report 2026, obtained by Kenyans.co.ke on August 3, singles out Kenya as a hub for mobile money fraud and infrastructure-targeted ransomware, painting a grim reality of a country whose digital growth has outpaced its ability to protect itself.
According to the report, Kenya recorded more than 46,786 Distributed Denial-of-Service (DDoS) attacks in just the first half of 2025, all aimed squarely at telecom companies that millions of Kenyans rely on daily.
These are malicious cyberattacks in which perpetrators flood a target website, server, or network with overwhelming internet traffic using multiple compromised devices, causing the service to slow or become completely offline for real users.
Undated image of Interpol’s headquarters in Lyon, France
New York Times
“Kenya recorded more than 46,786 DDoS attacks in the first half of 2025 targeting telecoms,14 and was included in SOCRadar’s top phishing detection in September 2025,” stated the report in part.
The Communications Authority (CA) of Kenya also flagged hundreds of millions of intrusion attempts against government systems and ICT infrastructure between July and September alone.
Most of these attacks came through brute-force attempts and system exploitation, methods that essentially hammer away at digital defences until something gives.
An example is the incident where the official website of the President was hacked on July 18, forcing its homepage defaced with a message targeting President William Ruto and demanding a ransom in Bitcoin of value estimated Ksh41 million.
Additionally, SIM swap fraud has been especially brutal, surging by 327 per cent in 2025, with more than 123,000 fraudulent SIM cards issued and roughly USD 3.8 million drained from mobile wallets.
When you place Kenya next to its East African neighbours, the picture gets even more interesting, and uglier at the same time.
Uganda made headlines too after its Electricity Transmission Company (ETC) suffered a suspected ransomware attack in August, a rare case involving the national power grid.
Tanzania and Rwanda reported similar SIM swap patterns, but their telecom providers have struggled just as much to roll out real-time biometric verification.
Zooming out to the rest of Africa, Southern Africa still dominates in raw numbers, with South Africa alone accounting for 92 per cent of all ransomware detections on the continent.
West Africa, meanwhile, remains the epicentre of Business Email Compromise scams, with Nigeria and Cabo Verde recording thousands of ransomware detections tied to organised fraud networks.
Still, Kenya’s numbers stand out within East Africa specifically, and Interpol says that without a unified regional response, criminal networks will continue to exploit these jurisdictional gaps with ease.
“The absence of a unified regional cybercrime response mechanism has allowed criminal networks to exploit jurisdictional boundaries between nations,” the report stated.
The official website of the President showing unauthorised content after hackers hacked the homepage.
Kenyans.co.ke
Click Here For The Original Source.
