Kenya’s national cyber response centre detected 11.12 billion cyber threat events between July 2025 and June 2026, up 29% from 8.62 billion a year earlier, according to the Communications Authority of Kenya’s latest sector statistics, reported by IT News Africa.
What grew fastest
- DDoS attacks (flooding a website with junk traffic until real users are locked out): up 114.3% to about 72 million. Most came between July and December 2025, before falling 90% in April to June 2026.
- Web application attacks, often aimed at login pages and forms: up 99% to 51.5 million.
- Malware: up 64.8% to 230.3 million.
- Attacks on mobile apps: up 54% to 789,826.
- Password-guessing (brute force) attacks: almost flat, up 3.6% to 132.2 million.
By volume, the biggest category by far is attempts to exploit unpatched systems, which made up about 96% of events in the first quarter of 2026.
Attempts, not breaches
The 11 billion figure counts attempts and suspicious signals, such as automated scans and malicious traffic, not confirmed break-ins. Think of it as a count of knocks on the door, only some of which lead to a break-in.
What the regulator advises
- Install software, phone and router updates promptly.
- Train staff to spot phishing, including AI-generated scams.
- Tighten access controls and use strong, unique passwords with two-factor authentication.
- Monitor systems so suspicious activity is caught early.
Why it matters for Nigeria
Nigerian banks, fintechs and government portals face the same kinds of attacks, but Nigeria does not publish comparable quarterly threat statistics. The advice applies equally here: most of the attacks recorded in Kenya targeted known weaknesses that a simple update would have fixed.
Source: IT News Africa, using Communications Authority of Kenya data.



