Hard truths.

Technology

Kenya records 11.1 billion cyber threats in one year, Communications Authority of Kenya says

The Communications Authority of Kenya recorded 72,164,664 DDoS attacks, up 114.3 per cent from the 33,680,462 incidents reported in the 2024/2025 financial year.

By Bradley Bosire
2 min read
Kenya records 11.1 billion cyber threats in one year, Communications Authority of Kenya says

Kenya’s digital space came under growing pressure in the year to June 2026, with cyber threats climbing to more than 11.1 billion as attackers stepped up attempts to target systems, networks and online services.

The Communications Authority of Kenya (CA) recorded 11,124,632,684 cyber threats during the 2025/2026 financial year, marking a 29 per cent rise from the 8,622,876,858 incidents reported in the previous financial year.

Among the biggest increases were Distributed Denial-of-Service (DDoS) attacks, which more than doubled during the period.

The CA recorded 72,164,664 DDoS attacks, up 114.3 per cent from the 33,680,462 incidents reported in the 2024/2025 financial year.

DDoS attacks involve sending huge amounts of traffic or requests to a system, network or online service in an attempt to disrupt its normal operation and make it difficult for genuine users to access it.

However, the number of such attacks fell sharply in the final three months of the financial year. The regulator recorded 819,325 DDoS attacks between April and June 2026, down 90 per cent from the 8,202,803 attacks reported between January and March.

Despite the sharp decline towards the end of the financial year, the higher numbers recorded during the other periods pushed the annual DDoS figure above that of the previous year.

The CA data further shows that several other forms of cyber threats increased during the 12-month period.

Malware attacks rose by 64.8 per cent to 230,307,810, while web application attacks increased by 99 per cent to 51,508,883, almost twice the figure recorded in the previous financial year.

Mobile application attacks also went up by 54 per cent to 789,826.

Brute force attacks increased by 3.6 per cent to 132,225,836. Such attacks involve repeated attempts to break into systems or accounts without authorisation.

System vulnerabilities continued to make up the largest category recorded by the authority.

The CA reported 10,637,635,755 incidents linked to system vulnerabilities during the financial year, an increase of 28.2 per cent compared with the previous year.

The rise was also reflected in the number of cyber advisories issued by the regulator.

A total of 83,096,015 cyber advisories were recorded during the financial year, compared with 51,663,024 advisories in 2024/2025, representing a 60.8 per cent increase.

Brute force advisories recorded the biggest growth, rising by 365.5 per cent.

Web application advisories followed with a 110.5 per cent increase, while DDoS advisories rose by 3.1 per cent to 2,673,948.

The figures point to a broad increase in cyber activity during the financial year, with Kenya recording higher numbers across several categories of attacks, vulnerabilities and advisories.

More from TechnologyBrowse the section
Continue to the next story →