
Kenya accounted for 11.9 percent of all exploitable digital vulnerabilities detected across Africa in 2025, ranking second only to South Africa and exposing millions of citizens to identity theft, financial fraud and ransomware attacks that disproportionately harm ordinary people with limited recourse, according to a new Interpol report.
The findings reveal a troubling gap between Kenya's digital ambitions and the government's investment in protecting the personal data of its citizens. South Africa led the continent with 43.6 percent of vulnerabilities, while Nigeria followed Kenya at 9.1 percent. The report makes clear that these aren't sophisticated, unavoidable attacks. They're exploiting well-documented, publicly known security flaws that persist because of poor cyber practices, inadequate investment in cybersecurity and delayed software patching across government institutions and private companies.
How Hackers Get In
Interpol's analysis shows cybercriminals are targeting internet routers running outdated firmware with known security flaws, unsecured virtual private networks and weaknesses in online document management platforms to gain access to sensitive data. The vulnerabilities were easily exploitable, and their persistence reflects ongoing challenges in cyber hygiene, resource allocation and patch management across both the public and private sectors, the report states.
Regional peers have fared far better with stronger protections. Tanzania ranked seventh with three percent of vulnerabilities, Uganda 22nd with 0.5 percent and Burundi 24th with 0.3 percent. The disparity suggests Kenya's problem isn't inevitable but rather a failure of policy and institutional commitment.
The Human Cost
Data breaches are enabling a wide range of cybercrimes by providing criminals with personal information used in ransomware attacks, business email compromise, identity theft and mobile money fraud, Interpol warns. Cybercriminals are exploiting leaked personal data to create AI-generated synthetic identities for opening bank accounts, securing mobile loans and registering SIM cards under false names.
Kenya recorded a 327 percent increase in SIM swap fraud during 2025, driven by weak identity verification controls by telecommunications companies. Criminals hijacked phone numbers through psychological manipulation, commonly known as social engineering, to gain access to victims' bank accounts and mobile money wallets. The agency also highlights the rapid growth of money muling, in which unsuspecting individuals are recruited through fake online job advertisements as financial agents or remote transaction officers to receive and transfer illicit funds through their personal bank accounts.
Regulatory Gaps Enable Crime
The report identifies fragmented identity verification systems and limited real-time information sharing between banks, telecommunications firms and law enforcement agencies as key factors that continue to favour cybercriminals. Financial institutions could detect suspicious transactions, but they lacked the legal authority or technical channels to block SIM swaps or freeze accounts without court orders, a process that often took weeks to months, Interpol says.
The absence of an interoperable digital identity framework across Africa has worsened the problem, allowing criminals to steal identities in one country, open accounts in another and launder money through a third with little risk of detection.
Recent Breaches Expose Systemic Failures
Kenya has recorded several high-profile cybersecurity incidents in recent months. Last month, hackers defaced President William Ruto's official website and demanded a ransom of five Bitcoin, valued at about Sh41 million. In June, the High Court found the country's largest telecommunications company, Safaricom, liable for a data breach that exposed subscribers' financial, location and internet browsing information between 2018 and 2019 after failures in database security.
Hackers have also claimed to have accessed a 2.15-terabyte database containing about 17.1 million personal and medical records managed through the M-Tiba healthcare platform. Data from the Communications Authority of Kenya shows that the country recorded 2.35 billion cyber threat events in the three months to June 2026. The regulator attributed the attacks to inadequate system patching, low user awareness of phishing attacks and the growing use of artificial intelligence by cybercriminals to launch increasingly sophisticated attacks. Web application attacks, at 10.6 million, and system attacks, at 8.4 million, were the most common threats recorded during the quarter.
Why This Matters:
Kenyans are bearing the direct costs of their government's failure to invest adequately in cybersecurity infrastructure and enforce robust data protection standards. When criminals exploit weak identity verification systems to drain mobile money wallets or hijack phone numbers, it's ordinary citizens—many living paycheck to paycheck—who lose their savings with little hope of recovery. The fragmented regulatory framework means financial institutions can spot fraud but can't act quickly enough to stop it, leaving victims to navigate a court process that takes weeks or months. Without an interoperable digital identity system and real-time coordination between banks, telecom companies and law enforcement, Kenya's digital economy remains vulnerable to exploitation that deepens inequality and erodes public trust in institutions meant to protect citizens.