• Latest
  • All
  • How To
Cyber Threats

Kenya Detects 3.3 Billion Cyber Threats in 2026 Led by System Attacks

May 6, 2026
Pay TV

GOtv and DStv Grow as Kenya’s Pay TV Market Slips

September 18, 2026
Postal Corporation of Kenya

Kenya’s Postal Service Is Dying, but Couriers and E-Commerce Are Picking up the Slack

September 18, 2026
Mobile Subscriptions

Mobile Subscriptions Rise to 88 Million as Mobile Penetration Hits 165%

September 18, 2026
Mobile Money

Mobile Money Accounts Hit 54 Million as M-Pesa Holds 88.8% Share

September 18, 2026
DHgate Tablet Cases deals
Cybersecurity

Kenya Records 29% Rise in Cyber Threats to 11.12 Billion

September 18, 2026
Claude Cowork

Claude Adds Docs and Slides to Compete With Google Workspace

September 17, 2026
Apple TV on Android TV

How to Install Apple TV on Android TV in Kenya

September 17, 2026
WSO2 Agent Manager

WSO2 Launches Agent Manager to Help Companies Control Their Growing Army of AI Agents

September 17, 2026
How to Recover a Terminated YouTube Channel

How to Recover a Terminated YouTube Channel

September 17, 2026
High Court Declares Safaricom Stake Sale to Vodacom Unlawful

High Court Declares Safaricom Stake Sale to Vodacom Unlawful

September 16, 2026
Apple TV

Apple TV Is Now Free With iCloud+ in Kenya

September 15, 2026
New Proposal Wants Kenya to Phase Out Petrol Bikes for Electric Ones

New Proposal Wants Kenya to Phase Out Petrol Bikes for Electric Ones

September 15, 2026
Techweez | Tech News, Reviews, Deals, Tips and How To
  • News
  • Entertainment
  • Reviews
  • Features
  • Editorial
No Result
View All Result
Techweez | Tech News, Reviews, Deals, Tips and How To
  • News
  • Entertainment
  • Reviews
  • Features
  • Editorial
No Result
View All Result
Techweez | Tech News, Reviews, Deals, Tips and How To
No Result
View All Result

Kenya Detects 3.3 Billion Cyber Threats in 2026 Led by System Attacks

Caleb Sama by Caleb Sama
May 6, 2026
in News
Reading Time: 5 mins read
295
0
Cyber Threats

Kenya’s cyber threat monitoring body detected over 3.3 billion threat events between January and March 2026, a 26% drop from the previous quarter but still an enormous volume driven almost entirely by attacks on system infrastructure.

The National KE-CIRT/CC, the government’s cybersecurity coordination center housed at the Communications Authority of Kenya, released its 41st quarterly cybersecurity report covering the first three months of 2026.

Of the 3.37 billion threats, 3.23 billion (~96%) were classified as system attacks, meaning attempts to exploit vulnerabilities in network devices, operating systems, databases, and critical infrastructure.

READ: Mobile Finance Has Become Kenya’s Biggest Cybercrime Target

The remaining threats were spread across malware (68.7 million), brute force attacks (46.4 million), web application attacks (12.1 million), DDoS attacks (8.2 million), and mobile application attacks (219,549).

Something interesting shows up when you compare detections to advisories. Web application attacks generated the most advisories (10.4 million) despite being the third-lowest category by volume.

System attacks, despite making up the vast majority of detections, generated 8.1 million advisories, fewer than web application attacks. Web app vulnerabilities tend to be more exploitable and more damaging per incident, so they warrant more direct guidance to organizations.

Attack typeThreats detectedChange
System attacks3.23 billion↓ 26.14%
Malware68.7 million↑ 3.08%
Brute force46.4 million↑ 8.41%
Web application12.1 million↑ 4.71%
DDoS8.2 million↓ 85.93%
Mobile apps219,549↓ 29.18%
Attack Vectors

What’s Driving the Numbers?

Three root causes keep appearing in the report.

Across almost every category, the report points to the same underlying problems: organizations running software that hasn’t been patched or updated, staff who aren’t trained to recognize phishing or social engineering attempts, and the growing use of AI tools by attackers to automate and scale their operations.

Cyberattack vector trends
Cyberattack vector trends

System misconfigurations specifically (things like cloud environments set up with weak access controls, exposed databases, or default credentials left unchanged) were flagged as a persistent entry point.

The report notes that many organizations, particularly in rapidly digitizing sectors, lack visibility over their own cloud and hybrid systems. That’s a known problem: if you don’t know what you’re running, you can’t secure it.

READ: Cyber Attacks in Kenya Jump 441% in Just Three Months

Brute force attacks rose 8.41% from the previous quarter, partly attributed to expanded remote working and the continued targeting of RDP (Remote Desktop Protocol) configurations.

Attackers are also going after IoT devices through exposed Telnet ports, as smart devices with no password changes are effectively open doors.

Government, ISPs, and Cloud Providers Remain the Main Targets

Internet Service Providers, cloud service providers, and government systems were the most targeted across nearly every threat category.

This makes sense since they hold large volumes of user data and often manage infrastructure that other organizations depend on, making them high-value targets.

Financial services including banks, cryptocurrency platforms, and online trading platforms were also regularly listed among affected industries.

For DDoS attacks specifically, the health sector and government were the top targets. The report notes hacktivists and politically motivated groups (Advanced Persistent Threats, or APTs) were behind much of this activity, with the goal of disrupting public services rather than stealing data.

DDoS Attacks Dropped 86%, But Don’t Read Too Much Into It

The single most dramatic change in the report is the 85.93% drop in DDoS detections, from a much higher figure in October-December 2025 to 8.2 million this quarter. That sounds like progress, but the report doesn’t attribute this to improved defenses.

DDoS campaigns tend to be cyclical, often tied to specific events, geopolitical tensions, or hacktivist campaigns. A large drop in one quarter often simply reflects that the specific campaigns driving the previous spike have run their course.

Kenya Trained 85 People From 25 Organizations on Threat Intelligence Sharing

Beyond the threat data, the quarter included meaningful institutional activity. In partnership with the UK’s Foreign, Commonwealth and Development Office (FCDO), the KE-CIRT/CC ran a 5-day training program from March 2-6, 2026, in Nairobi for members of the National KE-CIRT/CC Cybersecurity Committee.

85 participants from 25 organizations attended, including government agencies, critical infrastructure operators, and academia.

The training covered threat intelligence platforms, specifically the MISP Threat Sharing platform and the PinPoint analytical tool, and focused on how organizations can share threat data with each other in a structured, timely way without getting tangled in legal or trust issues.

READ: KICTANet Pushes for Changes to Kenya’s Draft Cybersecurity Strategy

This was the final program under Phase II of the Africa Cyber Programme (ACP), a UK-funded initiative to build cybersecurity capacity across the continent.

Kenya also sent a delegation to the InCyber Forum Europe 2026 in Lille, France (March 30-April 2), and participated in the Africa CISO Summit in Nairobi (March 11-12), where the central themes were Africa’s cybersecurity skills gap and the need for better public-private collaboration.

A Threat Intelligence Platform Training is Planned for Q2

For the next quarter (April-June 2026), the KE-CIRT/CC plans to run a training program on a Threat Intelligence Sharing Platform (TISP) in collaboration with Expertise France.

The focus will be on getting key national bodies, including sectoral CIRTs and cybersecurity operations centers, to actually use standardized platforms for sharing threat data, rather than relying on ad hoc communication channels.

The goal is to close the gap between having a national cybersecurity framework on paper and having one that functions in practice.

Tags: Communications Authority of KenyaCyberattacksCybersecurityDDOS AttacksKenya Computer Incident Response TeamMalwareSystem AttacksThreat Intelligence
SendShare166Tweet104
Caleb Sama

Caleb Sama

Chief Editor. Pineapple on Pizza is absolutely great and let no one convince you otherwise. Pop in at: [email protected] to get in touch with me.

Related Posts

Pay TV

GOtv and DStv Grow as Kenya’s Pay TV Market Slips

September 18, 2026
Postal Corporation of Kenya

Kenya’s Postal Service Is Dying, but Couriers and E-Commerce Are Picking up the Slack

September 18, 2026
Mobile Subscriptions

Mobile Subscriptions Rise to 88 Million as Mobile Penetration Hits 165%

September 18, 2026
Cybersecurity

Kenya Records 29% Rise in Cyber Threats to 11.12 Billion

September 18, 2026
Airtel Kenya

Airtel Africa Shuts Down Kenya Fiber Unit After Two Years

September 14, 2026
Claude

Anthropic Reveals How Criminals Tried to Weaponize Claude

September 11, 2026

Latest

Pay TV

GOtv and DStv Grow as Kenya’s Pay TV Market Slips

September 18, 2026
Postal Corporation of Kenya

Kenya’s Postal Service Is Dying, but Couriers and E-Commerce Are Picking up the Slack

September 18, 2026
Mobile Subscriptions

Mobile Subscriptions Rise to 88 Million as Mobile Penetration Hits 165%

September 18, 2026
Mobile Money

Mobile Money Accounts Hit 54 Million as M-Pesa Holds 88.8% Share

September 18, 2026
Cybersecurity

Kenya Records 29% Rise in Cyber Threats to 11.12 Billion

September 18, 2026
Claude Cowork

Claude Adds Docs and Slides to Compete With Google Workspace

September 17, 2026

Best devices

Best Infinix Phones of 2025

Best Infinix Phones of 2025: Budget Prices With Premium Features

December 31, 2025

The Best Infinix Accessories Worth Buying in 2025

November 26, 2025

Best Budget Wireless Earbuds To Buy in Kenya (2025)

October 8, 2025

Samsung Galaxy A36 5G vs Samsung Galaxy A56 5G: Comparison Review

August 29, 2025

Infinix Hot 60 Pro+ vs Infinix Hot 60i: Comparison Review

August 22, 2025

Best Budget Smartwatches To Buy in Kenya 2025

February 13, 2025

Techweez is where tomorrow’s tech stories break today, thanks to intelligent analysis, real-world insight, and visionary storytelling.

Follow Us

Editorials

Yubo: The App That Went From Tinder for Teens to 60 Million Users

Tangle Is What Happens When Texting Meets a Phone Call

Absa Next Is Building Something Different From a Banking App

Flighty App: A Flight Tracker With an Early Warning System

Convos Wants to Be the First Messaging App Built for the Age of AI

Marvel Snap: Marvel Heroes, Strategy, and Quick Matches Into One Card Game

More News

How to Install Apple TV on Android TV in Kenya

WSO2 Launches Agent Manager to Help Companies Control Their Growing Army of AI Agents

How to Recover a Terminated YouTube Channel

High Court Declares Safaricom Stake Sale to Vodacom Unlawful

Apple TV Is Now Free With iCloud+ in Kenya

New Proposal Wants Kenya to Phase Out Petrol Bikes for Electric Ones

  • Terms Of Use
  • Techweez Brand
  • Privacy & Policy
  • Contact Us

© 2024 Techweez - Palahala Media Group may earn a commission when you buy through links on our sites.
A Palahala Media Group Brand. All rights reserved.
.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

Techweez | Tech News, Reviews, Deals, Tips and How To
Crunchy Cookies 🍪 Ahead!

Hey there! Just a heads-up: we're big fans of cookies - both the digital and edible kind! 🍪 We use our cookies and some from third parties to ensure your browsing experience on our site is smooth sailing and secure.

 

But wait, there's more! We also use cookies to gather stats and insights on how you navigate our site. It's like getting a behind-the-scenes peek at your digital adventures!

 

Don't worry, you're in control. You can adjust your cookie settings anytime to suit your preferences. Feeling curious? Dive into our Privacy Policy for all the juicy details. Happy browsing! 🚀

Functional Always active
Listen, this legal stuff is about as exciting as watching paint dry. But it basically says we only use your stuff for what you asked us to do, and nobody else gets to peek!
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
It's those sneaky cookie crumbs websites leave behind to count visitors, like counting ants at a picnic! Totally harmless, just for fun facts. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
Hey there! Just letting you know we use some fancy gizmos to remember your preferences. This way, we can show you ads that are, well, not completely bananas.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
Make cookies
{title} {title} {title}
Techweez | Tech News, Reviews, Deals, Tips and How To
Crunchy Cookies 🍪 Ahead!
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
Listen, this legal stuff is about as exciting as watching paint dry. But it basically says we only use your stuff for what you asked us to do, and nobody else gets to peek!
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
It's those sneaky cookie crumbs websites leave behind to count visitors, like counting ants at a picnic! Totally harmless, just for fun facts. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
Hey there! Just letting you know we use some fancy gizmos to remember your preferences. This way, we can show you ads that are, well, not completely bananas.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
Make cookies
{title} {title} {title}
No Result
View All Result
  • News
  • Reviews
  • Features
  • Editorial
  • Automotive
  • Entertainment

© 2024 Techweez - Palahala Media Group may earn a commission when you buy through links on our sites.
A Palahala Media Group Brand. All rights reserved.
.