Kenya Recorded 72 Million DDoS Threats in a Year, Up 114%

General

By Mike Agoya

Published: 2026-09-29T18:05:19 · Updated: 2026-09-29T16:05:19Z

Kenya Recorded 72 Million DDoS Threats in a Year, Up 114%

Kenya detected 72,164,664 distributed denial-of-service (DDoS) attacks in the financial year ended June 2026, more than double the 33,680,462 recorded a year earlier. The figure represents a 114.3% increase, according to the Communications Authority of Kenya (CA), marking a sharp rise in one category of cyberattack designed specifically to disrupt the availability of online services.

The number comes from the National Kenya Computer Incident Response Team Coordination Centre (National KE-CIRT/CC), which monitors and detects cyber threats across the country. It should not, however, be read as 72 million separate incidents in which attackers successfully brought down Kenyan websites or compromised their data. The CA is reporting detected DDoS activity, not a tally of confirmed outages.

What the Attack Disrupts

A DDoS attack is designed to make an online service unavailable. Attackers overwhelm a website, server, network or application with traffic or requests until legitimate users struggle to get through, turning something as simple as opening a webpage or completing a transaction into an access problem.

No data has to be stolen for the attack to cause damage. A customer who cannot log into an account, a payment that cannot be completed or an application that stops responding can all become operational problems for the company behind the service. The longer that interruption lasts, the further it can move from a technical incident into lost transactions, delayed operations and frustrated customers.

That exposure is becoming harder for businesses to ignore as more of their operations move online. Payments, e-commerce, logistics and customer services increasingly depend on systems that have to remain reachable, while public institutions are putting more government services behind digital platforms. Availability has become part of how these organisations deliver their services, not simply a technical property of the systems running them.

The Annual Increase Hides a Sharp Reversal

The annual figure, however, does not tell a story of DDoS activity rising at the same pace throughout the year. The CA recorded 8.20 million attacks between January and March 2026, but only 819,325 in the following quarter, a 90% decline between January-March and April-June.

The figures show that the annual increase did not continue into the final quarter of the financial year. That matters when interpreting the 114.3% rise: the headline number captures the total detected over 12 months, while the quarterly figures show how uneven that activity was within the period.

For a business, though, a lower number in one quarter does not make availability attacks inconsequential. A single large or sustained attack can interrupt customer access, transactions and internal operations, leaving the company to restore service while customers are already looking elsewhere.

Kenya Has Seen How Digital Disruption Spreads

Kenya has already seen how an attack on digital availability can extend beyond the system being targeted. In July 2023, the eCitizen platform was hit by a DDoS attack that disrupted access to government services, with problems also reported across connected services including driver testing and licensing. Kenya Power and Kenya Railways also reported disruptions to some of their digital services, while the government said no data had been accessed or lost.

That incident was separate from the DDoS activity recorded in the CA's 2025/26 figures, but it provides a useful example of the distinction between data compromise and service disruption. A system can remain intact while the people who depend on it are effectively locked out.

For a private company, the same problem can appear in several places at once. A customer may be unable to reach the website, an application may stop accepting requests, or an authentication service may become inaccessible even though the underlying customer records have not been breached. Websites are one layer. APIs, customer portals and authentication systems are others.

The Wider Threat Picture

DDoS activity was also only one part of a much larger volume of cyber threats detected during the year. The CA recorded 11.12 billion detected cyber threats in 2025/26, up from 8.62 billion the previous year, with system vulnerabilities accounting for about 10.6 billion of the total. Web application attacks nearly doubled to 51.51 million, while malware detections rose 64.8% to 230.31 million.

The regulator also recorded 83.1 million cyber advisories during the year, compared with 51.7 million previously. Advisories relating to brute-force attacks rose 365.5% to 25.5 million, while web application attack advisories increased 110.5% to 40.5 million.