Interpol ranks Kenya second in Africa for cyberattacks
This story has significance for readers across Kenya and beyond.
Kenya is Africa’s second-most vulnerable country to cyberattacks, exposing businesses and government agencies to data breaches that are fuelling identity theft, financial fraud and ransomware attacks, a new Interpol report shows.
The report says Kenya accounted for 11.9 percent of all exploitable digital vulnerabilities detected across Africa in 2025, ranking second behind South Africa (43.6 percent) and ahead of Nigeria (9.1 percent).
Interpol attributes the high exposure to poor cyber practices, inadequate investment in cybersecurity and delayed software patching across government institutions and private companies.
Hackers are exploiting internet routers running outdated firmware with known security flaws, unsecured virtual private networks (VPNs) and weaknesses in online document management platforms to gain access to sensitive data.
“These vulnerabilities were not exotic or novel; they were well-documented, publicly known, and easily exploitable,” the report says. “Their persistence reflects ongoing challenges in cyber hygiene, resource allocation, and patch management across both the public and private sectors.”
Compared with Kenya, regional peers recorded significantly fewer vulnerabilities. Tanzania ranked seventh with three percent, Uganda 22nd with 0.5 percent and Burundi 24th with 0.3 percent.
Interpol warns that data breaches are enabling a wide range of cybercrimes by providing criminals with personal information used in ransomware attacks, business email compromise, identity theft and mobile money fraud.
According to the report, cybercriminals are also exploiting leaked personal data to create AI-generated synthetic identities for opening bank accounts, securing mobile loans and registering SIM cards under false names.
“AI-generated synthetic identities, created by combining real personal data with fabricated elements, were used to open bank accounts, secure mobile loans, and register SIM cards under false names,” Interpol says.
The agency also highlights the rapid growth of money muling, in which unsuspecting individuals are recruited through fake online job advertisements as “financial agents” or “remote transaction officers” to receive and transfer illicit funds through their personal bank accounts. Kenya recorded a 327 percent increase in SIM swap fraud during 2025, driven by weak identity verification controls by telecommunications companies.
Criminals hijacked phone numbers through psychological manipulation, commonly known as social engineering, to gain access to victims’ bank accounts and mobile money wallets. The report identifies fragmented identity verification systems and limited real-time information sharing between banks, telecommunications firms and law enforcement agencies as key factors that continue to favour cybercriminals.
“While financial institutions could detect suspicious transactions, they lacked the legal authority or technical channels to block SIM swaps or freeze accounts without court orders, a process that often took weeks to months,” Interpol says. It adds that the absence of an interoperable digital identity framework across Africa has worsened the problem, allowing criminals to steal identities in one country, open accounts in another and launder money through a third with little risk of detection.
Kenya has recorded several high-profile cybersecurity incidents in recent months. Last month, hackers defaced President William Ruto’s official website and demanded a ransom of five Bitcoin, valued at about Sh41 million.
In June, the High Court found the country’s largest telecommunications company, Safaricom, liable for a data breach that exposed subscribers’ financial, location and internet browsing information between 2018 and 2019 after failures in database security.
Hackers have also claimed to have accessed a 2.15-terabyte database containing about 17.1 million personal and medical records managed through the M-Tiba healthcare platform.
Data from the Communications Authority of Kenya (CA) shows that the country recorded 2.35 billion cyber threat events in the three months to June 2026.
The regulator attributed the attacks to inadequate system patching, low user awareness of phishing attacks and the growing use of artificial intelligence by cybercriminals to launch increasingly sophisticated attacks. Web application attacks, at 10.6 million, and system attacks, at 8.4 million, were the most common threats recorded during the quarter.
Reporting originally appeared via Nation Africa. Read the full source for additional context.