INTERPOL Reveals Why Kenya Is Emerging as East Africa’s Cybercrime Hotspot
Kenya is facing a growing wave of cyberattacks as criminals target telecom networks, government systems, financial platforms and increasingly digital services, with INTERPOL warning that East Africa’s rapid digital transformation is creating new opportunities for cybercriminals.
Kenya’s rise as one of East Africa’s most digitally connected economies is coming with a darker side: the country is increasingly becoming a target for sophisticated cybercriminals.
The warning is contained in INTERPOL’s 2025 Africa Cyberthreat Assessment Report, which identifies Kenya, Uganda, Tanzania, Rwanda and Ethiopia among East Africa’s rapidly expanding technology and financial hubs — but warns that this digital transformation is also making the region increasingly attractive to cybercriminals.
INTERPOL says cybercrime has become a significant component of criminal activity across Africa, with 30 per cent of reported crime in both Western and Eastern Africa linked to cyber-related offences, according to surveyed member countries.
The organisation identified online scams, ransomware, Business Email Compromise, digital sextortion and identity theft among the most significant cyberthreats facing the continent.

Neal Jetton, INTERPOL’s Cybercrime Director, said the threat was evolving rapidly and required countries to work together.
“No single agency or country can face these challenges alone,”
Jetton said, warning that emerging threats, including AI-driven fraud, require an urgent response.
Kenya’s telecom networks under attack
The scale of attacks against Kenya’s digital infrastructure was highlighted by separate cybersecurity data.
According to NETSCOUT data reported in 2025, Kenya recorded 46,786 Distributed Denial-of-Service (DDoS) attacks between January and June 2025, the highest number recorded in East Africa during that period.
Telecommunications companies were the biggest targets.
Wired telecommunications carriers suffered 20,349 attacks, while wireless telecommunications carriers recorded another 15,919. Computer-related services accounted for 8,730 attacks.
A DDoS attack occurs when criminals overwhelm a website, server or network with huge volumes of internet traffic, often using large numbers of compromised devices. The result can be severe slowdowns or complete disruption of legitimate services.

The figures underline the vulnerability of a country where millions of people depend on mobile networks and digital platforms for communication, banking, business and government services.
Government systems also in the crosshairs
INTERPOL’s report records several cases in which Kenyan public infrastructure has been targeted.
Among them was a breach involving the Kenya Urban Roads Authority (KURA), which compromised important road infrastructure data.
The report also refers to cyberattacks against Kenya’s Micro and Small Enterprise Authority in December 2024.
And the threat has continued into 2026.
In July, hackers breached the official website of President William Ruto, replacing its homepage with unauthorised messages directed at the President and demanding payment in Bitcoin.
The attackers reportedly demanded five Bitcoin — worth approximately KSh41 million at the time — and threatened to release information if their demands were not met.
State House confirmed that its ICT team was handling the incident, while ICT Cabinet Secretary William Kabogo said agencies responsible for protecting government websites were dealing with the attack.

The website was subsequently restored.
The incident provided a dramatic reminder that even highly visible government platforms can become targets for cybercriminals.
Mobile money and SIM-swap fraud raise fresh fears
Kenya’s huge mobile-money ecosystem also presents an attractive target.
INTERPOL’s Africa assessment specifically identifies SIM-swap fraud as a notable problem in East Africa, particularly in Uganda and Tanzania, where criminals exploit weaknesses in mobile-network processes to fraudulently obtain replacement SIM cards and hijack victims’ telephone numbers.
Kenya has faced its own serious mobile-related fraud cases.
In one major investigation, the Directorate of Criminal Investigations said a syndicate used fraudulently generated identification details to register thousands of SIM cards and exploit Safaricom’s Fuliza service.
Detectives said more than 123,000 mobile numbers had taken Fuliza loans in January 2022 before the numbers were later deactivated or became unreachable. The investigation was linked to a fraud scheme estimated at almost KSh500 million.
The case illustrates how weaknesses in identity verification and SIM registration can be exploited to facilitate large-scale financial crime.
Kenya is not alone
Across East Africa, INTERPOL says countries are experiencing similar pressures as their economies become increasingly digital.
Kenya, Uganda, Tanzania, Rwanda and Ethiopia have all rapidly expanded their technology and financial sectors.
But the same infrastructure that makes digital banking, mobile payments, e-commerce and online government services possible can also provide new opportunities for criminals.
INTERPOL says critical infrastructure, government institutions and financial services are frequently targeted.
Ethiopia, meanwhile, was identified as the world’s most targeted country for cyberattacks in 2024 based on malware detections.
Africa faces a wider cybercrime crisis
The problem extends far beyond East Africa.
INTERPOL reported that ransomware detections across Africa increased in 2024, with South Africa recording 17,849 detections and Egypt 12,281. Kenya followed with 3,030 detections, alongside Nigeria with 3,459.
The organisation also warned that online scams, ransomware and Business Email Compromise are increasingly organised and capable of causing enormous financial losses.
The challenge is compounded by limited law-enforcement capacity.
INTERPOL found that 75 per cent of African countries surveyed said their legal frameworks or prosecution capacity required improvement, while 95 per cent reported inadequate training, resource constraints or insufficient access to specialised cybercrime tools.
Even more troubling, 86 per cent said their ability to cooperate internationally against cybercrime needed improvement.
That matters because cybercriminals rarely respect national borders.
A criminal operating from one country can target a victim, bank or telecommunications provider in another while moving stolen money through several additional jurisdictions.
INTERPOL calls for stronger regional response
INTERPOL says African countries need stronger international cooperation, improved prevention and public awareness, better investigative capacity and greater use of technology to combat increasingly sophisticated cybercriminal networks.
The organisation’s warning is stark: Africa’s digital transformation is creating enormous economic opportunities, but without stronger cyber defences, those same advances could leave governments, businesses and ordinary citizens increasingly exposed.
As Kenya continues its push towards a more digital economy, the latest attacks raise a difficult question — is the country’s cybersecurity infrastructure keeping pace with the speed at which its digital economy is expanding?
INTERPOL’s assessment suggests that closing that gap will require more than individual countries acting alone.
As Jetton put it:
“No single agency or country can face these challenges alone.”
Also Read: KRA launches free tax education programme for women entrepreneurs and chamas
