
Kenya accounted for 11.9 percent of all exploitable digital vulnerabilities detected across Africa in 2025, and Interpol says that failure is exposing businesses and government agencies to data breaches, identity theft, financial fraud and ransomware attacks.
Who Pays for the Weak Links
The people at the bottom are the ones left holding the bill. Interpol’s report says hackers are exploiting internet routers running outdated firmware with known security flaws, unsecured virtual private networks and weaknesses in online document management platforms to gain access to sensitive data. Those vulnerabilities were well-documented, publicly known and easily exploitable, yet they kept sitting there across government institutions and private companies. That’s not some mystery. It’s a record of neglect, underinvestment and the usual bureaucratic shrug while ordinary users absorb the damage.
Kenya ranked second in Africa for cyberattacks, behind South Africa at 43.6 percent and ahead of Nigeria at 9.1 percent. Tanzania ranked seventh with three percent, Uganda 22nd with 0.5 percent and Burundi 24th with 0.3 percent. Interpol attributes Kenya’s high exposure to poor cyber practices, inadequate investment in cybersecurity and delayed software patching across government institutions and private companies. The report says the persistence of these vulnerabilities reflects ongoing challenges in cyber hygiene, resource allocation and patch management across both the public and private sectors.
What the System Leaves Open
Data breaches are feeding a wider machine of theft and fraud. Interpol warns that leaked information is enabling ransomware attacks, business email compromise, identity theft and mobile money fraud. The report says cybercriminals are also using leaked personal data to create AI-generated synthetic identities, which they then use to open bank accounts, secure mobile loans and register SIM cards under false names. The agency says these synthetic identities combine real personal data with fabricated elements. Clean paperwork for dirty hands.
Money muling is growing too. Interpol says unsuspecting individuals are being recruited through fake online job advertisements as financial agents or remote transaction officers to receive and transfer illicit funds through their personal bank accounts. Kenya recorded a 327 percent increase in SIM swap fraud during 2025, driven by weak identity verification controls by telecommunications companies. Criminals hijacked phone numbers through psychological manipulation, commonly known as social engineering, to get into victims’ bank accounts and mobile money wallets.
The Gatekeepers Can’t or Won’t Stop It
Interpol identifies fragmented identity verification systems and limited real-time information sharing between banks, telecommunications firms and law enforcement agencies as key factors that continue to favour cybercriminals. Financial institutions could detect suspicious transactions, the report says, but they lacked the legal authority or technical channels to block SIM swaps or freeze accounts without court orders, a process that often took weeks to months. The apparatus moves slowly, and the damage moves fast.
The report adds that the absence of an interoperable digital identity framework across Africa has worsened the problem, allowing criminals to steal identities in one country, open accounts in another and launder money through a third with little risk of detection. That’s what happens when fragmented systems are treated like protection instead of a liability.
Kenya has already seen the cracks in public. Last month, hackers defaced President William Ruto's official website and demanded a ransom of five Bitcoin, valued at about Sh41 million. In June, the High Court found the country's largest telecommunications company, Safaricom, liable for a data breach that exposed subscribers' financial, location and internet browsing information between 2018 and 2019 after failures in database security. Hackers have also claimed to have accessed a 2.15-terabyte database containing about 17.1 million personal and medical records managed through the M-Tiba healthcare platform.
The Communications Authority of Kenya says the country recorded 2.35 billion cyber threat events in the three months to June 2026. The regulator blamed inadequate system patching, low user awareness of phishing attacks and the growing use of artificial intelligence by cybercriminals to launch increasingly sophisticated attacks. Web application attacks, at 10.6 million, and system attacks, at 8.4 million, were the most common threats recorded during the quarter. The numbers keep climbing while the institutions meant to guard the data keep proving how thin their defenses really are.