If you’ve ever walked into your house only to find a stranger has changed the locks and left a note on the door, you’ll have a fair idea of how Kenya’s information technology (IT) team felt on Thursday.
On July 18, William Kabogo Gitau, Kenya’s tech minister, confirmed a detail that most citizens have speculated for several hours. The country’s official website was hit by a cybersecurity attack. Reports circulating in the media said the attackers had held the state to ransom and demanded 5 Bitcoins, worth KES 41.3 million ($320,000).
However, Gitau said that there was “no evidence of unauthorised access to sensitive data, data exfiltration, or loss of information.” As of Monday, however, the website was back functioning, and for those engineers who worked overtime, the nights of pumping caffeine probably paid off.
But, according to a new report by the Communications Authority of Kenya (CAK), the country’s telecoms, IT, and digital economy regulator, these incidents happen more frequently than anybody cares to keep count of.
What happened? According to the regulator, web application attacks targeting government systems and Internet service providers (ISPs) increased by 43.7%, rising from about 12.1 million in the previous quarter to 17.4 million by June. If you do the maths, this means hackers attacked these platforms about 191,000 times a day, or 133 times every minute. That’s some never-give-up spirit.
But why is this happening at such an alarming rate?
Explain like I’m new here: Every website has a front door, the page you see, and a back room where databases, logins, and software do the actual work. A web application attack is an attempt to find weaknesses in that back room. Hackers constantly probe websites for vulnerabilities they can exploit to steal data, disrupt services, or gain control. Most attacks fail because systems block or detect them, but defenders still have to stop every attempt, while attackers only need one mistake to get in.
Are the attackers trying to say something? The July 18 attack was the second attempt on Kenya’s government website this year. With the country heading towards presidential elections in 2027, all sorts of theories could be up in the air to answer why waves of these attacks are hitting critical platforms. But without evidence, it’s safer to see these attacks for what they are: part of a much broader wave of automated cyberattacks targeting government systems in 2026.
Globally, a surveillance system used by the US’ Federal Bureau of Investigation (FBI) suffered a cyber incident. Other countries, including Brazil, and local governments in Poland have suffered the same. Closer to home, South Africa has been dealt the same hand.
Zoom out: As governments move more services online, their digital infrastructure becomes critical national infrastructure. That also makes it a bigger target. IT could get a lot more attention as it plays a huge role in how governments keep public services running.
Crédito: Link de origem