Distributed denial-of-service attacks targeting Kenyan websites, servers and networks more than doubled in the year to June, underscoring the growing threat to digital systems as more services move online.
Data from the Communications Authority of Kenya shows that 72.16 million DDoS attacks were recorded in the year ended June 2026, up 114.3 percent from 33.68 million attacks recorded a year earlier.
The increase was the highest among the cyber threats monitored by the regulator, pointing to a sharp rise in attempts to disrupt access to digital services and systems.
DDoS attacks work by overwhelming a website, server or network with large volumes of malicious traffic, making the targeted system slow or inaccessible to legitimate users.
Attackers can use botnets; networks of malware-infected computers and other connected devices, to generate large numbers of requests and direct them at a target simultaneously.
The resulting traffic can consume a system’s bandwidth, processing capacity or memory, disrupting services without necessarily giving attackers access to the data stored on the affected system.
- Why your team needs to rethink WhatsApp at work
- Human error, not hackers, is Africa’s biggest cybersecurity risk
For businesses and service providers, such disruptions can result in downtime, preventing customers from making purchases, accessing accounts or using online platforms. Organisations may also incur financial losses from interrupted services and the cost of restoring affected systems.
Cybersecurity experts have warned that DDoS attacks can sometimes be used to divert attention while attackers attempt to steal data or install malware elsewhere on a network.
Kenya has previously recorded major DDoS attacks against government digital services. In July 2023, the eCitizen platform, which provides access to government services online, experienced a major cyberattack that temporarily disrupted access to several services.
Kenya Power, Kenya Railways and the National Transport and Safety Authority were among the systems reported to have been affected during the 2023 incident.
