A Sharp Rise in Cyber Aggression
Distributed denial-of-service (DDoS) attacks targeting Kenyan digital infrastructure more than doubled in the year ending June 2026, according to the latest data from the Communications Authority of Kenya (CA). The number of incidents—in which attackers flood websites, servers, or networks with malicious traffic to render them inaccessible—surged by 114.3 percent, reaching 72.16 million, up from 33.68 million the previous year.
This increase represents the fastest growth among all cyber threats tracked by the regulator. As Kenya continues to position itself as a regional technology hub, the expansion of its digital footprint—including widespread use of mobile money, e-commerce, and government eCitizen portals—has created a larger attack surface for malicious actors, the CA reported.
Mechanics and Strategic Risks
DDoS attacks function by overwhelming a system’s bandwidth, processing capacity, or memory with simultaneous requests from multiple compromised sources. While the primary goal is often to cause downtime, Business Daily Africa notes that these attacks are frequently used as “smokescreens” for more sophisticated intrusions, such as data breaches or ransomware deployments. The shift toward cloud-based services and interconnected APIs means that overwhelming a single critical point can cause cascading failures across entire digital ecosystems.
High-profile targets in Kenya have previously included Kenya Power, Kenya Railways, and the National Transport and Safety Authority (NTSA). In those instances, the hacktivist group Anonymous Sudan claimed responsibility, though authorities confirmed that no data was accessed or lost during the incidents.
Regulatory Response and Industry Challenges
The Communications Authority, through the National Kenya Computer Incident Response Team (KE-CIRT/CC), is tasked with monitoring these threats and coordinating mitigation efforts. However, the regulator acknowledges that many small and medium enterprises lack the specialized infrastructure required to filter massive volumes of malicious traffic effectively.
The government is currently intensifying enforcement of the Computer Misuse and Cybercrimes Act, requiring critical infrastructure operators to conduct regular vulnerability assessments. Despite these efforts, compliance remains uneven. Industry stakeholders are increasingly calling for shared threat intelligence platforms, where data on malicious IP addresses and emerging attack vectors can be pooled to proactively block threats before they impact local networks.

