Incidents of hackers flooding websites, servers and networks in Kenya with huge volumes of malicious traffic to make them inaccessible rose 114.3 percent in the year to June as cybercriminals target digital systems.
These cyber assaults, known technically as distributed denial-of-service (DDoS) attacks, rose to 72.16 million in the year ended June 2026, up from 33.68 million a year earlier, according to the latest data from the Communications Authority of Kenya (CA).
This was the highest growth among the cyber threats tracked by the regulator, highlighting the growing exposure of businesses and public systems as more services move online.
DDoS attacks occur when attackers flood a website, server, or network with high malicious traffic to overwhelm its capacity and make it slow or inaccessible to legitimate users.
Attackers often use networks of malware-infected computers and other connected devices, known as botnets, to send large numbers of requests to a target at the same time.
The traffic can consume a system’s bandwidth, processing capacity, or memory, disrupting access even when the attackers have not gained access to the underlying data.
This results in service downtime, stopping customers from buying items, logging into accounts, or using online services.
Companies and government agencies end up losing money from missed sales or services, and expensive emergency fixes.
Experts have also warned that hackers sometimes use a DDoS attack as a distraction to hide data theft or malware installation on the network.
Kenya has previously experienced high-profile DDoS attacks targeting government digital services. In July 2023, the eCitizen platform, the government’s online services portal, was hit by a major attack that temporarily disrupted access to key agencies.
Kenya Power, Kenya Railways and the National Transport and Safety Authority (NTSA) were among the systems reported to have been affected at the time.
The government said no data had been accessed or lost. The hacktivist group Anonymous Sudan claimed responsibility.
The increase in DDoS threats comes as Kenya’s digital economy expands, increasing the number of systems and services that rely on internet connectivity.
The CA data also shows web application attacks targeting flaws, poor coding, or security gaps in websites, web services, and application programme interfaces (APIs) increased 99 percent to 51.51 million, from 25.89 million in the previous year.
Malware attacks, where cybercriminals use malicious software to infiltrate a computer system or network to steal data, damage operations, or gain unauthorised access, rose 64.8 percent to 230.31 million, from 139.76 million.
Overall, the regulator detected 11.1 billion cyber-threat incidents in the year to June 2026, a 29 percent increase from 8.6 billion a year earlier.
“The total number of cyber threats detected during the April-June quarter declined by 30.0 per cent to 2.4 billion, compared with the previous quarter,” the regulator said.
“However, the total number of cyber threats increased by 29.0 per cent during the 2025/2026 financial year, from 8.6 billion recorded in the preceding financial year.”
System vulnerabilities – weaknesses or flaws in a computer system’s design, code, hardware – remain Kenya’s largest category, accounting for 10.6 billion incidents, or 95.4 percent of all threats recorded in the year to June 2026.
The regulator has previously linked the rise of cyber threats to inadequate system patching, limited user awareness of phishing and social engineering, and the increasing use of AI-driven and machine-learning tools by malicious actors.
The emergence of AI agents (systems capable of autonomously carrying out tasks on behalf of users) has also created another cybersecurity risk.