
Kenya accounted for 11.9 percent of all exploitable digital vulnerabilities detected across Africa in 2025, ranking second only to South Africa and exposing businesses and government agencies to cascading data breaches, according to a new Interpol report. The findings reveal systemic failures in cybersecurity investment and basic digital hygiene that are costing the economy through identity theft, financial fraud and ransomware attacks.
South Africa led the continent with 43.6 percent of vulnerabilities, while Nigeria followed Kenya with 9.1 percent. The gap between Kenya and regional peers is stark. Tanzania ranked seventh with three percent, Uganda 22nd with 0.5 percent and Burundi 24th with 0.3 percent.
Poor Practices, Delayed Patching
Interpol attributes Kenya's high exposure to poor cyber practices, inadequate investment in cybersecurity and delayed software patching across government institutions and private companies. Hackers are exploiting internet routers running outdated firmware with known security flaws, unsecured virtual private networks and weaknesses in online document management platforms to gain access to sensitive data.
The report says these vulnerabilities were well-documented, publicly known and easily exploitable. Their persistence reflects ongoing challenges in cyber hygiene, resource allocation and patch management across both the public and private sectors. It's a failure of institutional discipline, not technology.
Data breaches are enabling a wide range of cybercrimes by providing criminals with personal information used in ransomware attacks, business email compromise, identity theft and mobile money fraud, Interpol warns. Cybercriminals are also exploiting leaked personal data to create AI-generated synthetic identities for opening bank accounts, securing mobile loans and registering SIM cards under false names.
SIM Swap Fraud Surges 327 Percent
Kenya recorded a 327 percent increase in SIM swap fraud during 2025, driven by weak identity verification controls by telecommunications companies. Criminals hijacked phone numbers through psychological manipulation, commonly known as social engineering, to gain access to victims' bank accounts and mobile money wallets.
The report identifies fragmented identity verification systems and limited real-time information sharing between banks, telecommunications firms and law enforcement agencies as key factors that continue to favour cybercriminals. Financial institutions could detect suspicious transactions, Interpol says, but they lacked the legal authority or technical channels to block SIM swaps or freeze accounts without court orders—a process that often took weeks to months.
The absence of an interoperable digital identity framework across Africa has worsened the problem, allowing criminals to steal identities in one country, open accounts in another and launder money through a third with little risk of detection.
High-Profile Breaches Mount
Kenya has recorded several high-profile cybersecurity incidents in recent months. Last month, hackers defaced President William Ruto's official website and demanded a ransom of five Bitcoin, valued at about Sh41 million. In June, the High Court found the country's largest telecommunications company, Safaricom, liable for a data breach that exposed subscribers' financial, location and internet browsing information between 2018 and 2019 after failures in database security.
Hackers have also claimed to have accessed a 2.15-terabyte database containing about 17.1 million personal and medical records managed through the M-Tiba healthcare platform.
Data from the Communications Authority of Kenya shows that the country recorded 2.35 billion cyber threat events in the three months to June 2026. The regulator attributed the attacks to inadequate system patching, low user awareness of phishing attacks and the growing use of artificial intelligence by cybercriminals to launch increasingly sophisticated attacks. Web application attacks, at 10.6 million, and system attacks, at 8.4 million, were the most common threats recorded during the quarter.
The agency also highlights the rapid growth of money muling, in which unsuspecting individuals are recruited through fake online job advertisements as financial agents or remote transaction officers to receive and transfer illicit funds through their personal bank accounts.
Why This Matters:
Kenya's cyber vulnerability crisis represents a fundamental breakdown in institutional accountability and private sector discipline that threatens economic growth and investor confidence. When government agencies and major corporations fail to implement basic software updates and security protocols, they're not just exposing data—they're creating an environment where criminals operate with near impunity. The 327 percent surge in SIM swap fraud and the inability of financial institutions to freeze accounts without lengthy court processes reveal regulatory frameworks that haven't kept pace with digital threats. For businesses operating in Kenya, the lack of interoperable identity verification systems and real-time information sharing between institutions means heightened compliance costs and reputational risks. The country's ranking as Africa's second-most vulnerable nation undermines its ambitions as a regional technology hub and signals to international investors that critical infrastructure protection remains inadequate despite well-documented, easily preventable security flaws.