Back to Blog
Kenya Logged 11.12 Billion Cyber Threats - and 96% Were the Same Attack
Cybersecurity

Kenya Logged 11.12 Billion Cyber Threats - and 96% Were the Same Attack

September 30, 2026GashoTech
Kenya's Communications Authority has published its Q4 FY2025/26 Sector Statistics Report, and the headline number is enormous: the national KE-CIRT/CC detected 11,124,632,684 cyber threat events between July 2025 and June 2026 — 11.12 billion detections in a single financial year, up 29.0% from 8.62 billion the year before.

But the number that actually matters is buried in the mix, not the total. 96% of everything Kenya's defenders caught was the same attack: automated probes against unpatched systems. That changes what Kenyan businesses should do about it — and the answer is more boring, and more urgent, than the headline suggests.

The Scale Is Genuinely New



KE-CIRT/CC is not a niche monitoring post. It is the national incident detection capability, and its annual count is the closest thing Kenya has to a single measurement of the country's external threat exposure. A 29% rise in one year is real growth in attack volume — but it is also the product of increasingly industrialised scanning: attackers don't need skill when automation does the probing. What the total does not tell you is what the attacks actually were. The composition tells that story.

11.12 Billion Detections — The Year in Quarters



The scale is genuinely new. Table 22 of the CA report puts total detections at 11.12 billion for FY2025/26, against 8.62 billion in FY2024/25. Quarter by quarter, the year ran hot in the middle: 842.3 million detections in Q1, a spike to 4.56 billion in Q2, 3.37 billion in Q3, then 2.36 billion in Q4 — a 30% quarter-on-quarter decline into June 2026. The quarterly path matters as much as the annual total, because two of the categories below are waves that rose and fell inside this year, not steady-state trends.

A 29% annual rise sounds like a threat landscape spiralling out of control. The composition tells a more precise story.

96% Was One Attack Class



System vulnerabilities accounted for 10,637,635,755 events — 95.6% of all detections, up 28.2% year on year. These are not sophisticated intrusions. They are background scanning at industrial scale: automated tooling continuously probing internet-facing operating systems, databases, routers, and network devices for known, unpatched vulnerabilities.

This is the single most important fact in the report. Kenya did not face 11 billion clever attacks. It faced one cheap attack, repeated 10.6 billion times, succeeding wherever someone had not applied an update. The threat is not sophistication — it is patch discipline measured at national scale.

The DDoS Wave That Passed



DDoS attacks grew faster than any other category annually: 72,164,664 events, up 114.3% from 33.7 million. But the annual figure hides a wave that has already broken. The October–December 2025 quarter was the peak, and in April–June 2026 DDoS detections collapsed 90% quarter-on-quarter to just 819,325.

Two implications. First, the DDoS surge was episodic — a campaign or set of campaigns that peaked and passed, not a permanent new baseline. Second, any organisation that bought mitigation capacity in a panic during the peak should now right-size it against the quieter trend line, not the spike. Kenya has seen this pattern before: the eCitizen disruption of July 2023 was the same lesson at government scale.

Web Application Attacks: The Number Businesses Should Read



For Kenyan organisations running portals, booking systems, and checkouts, this is the most operationally relevant line in the report. Web application attacks rose 99.0% to 51,508,883 events — nearly doubling in one year.

These attacks concentrate on login pages and online forms: credential stuffing, injection attempts, brute-force logins. Unlike background vulnerability scanning, they hit revenue directly — every attack targets a page a customer or staff member must use. If your business runs any web-facing form, assume it is being probed continuously, because at 51.5 million events nationally, it is.

Malware detections also climbed sharply, up 64.8% to 230.3 million, while brute-force attacks grew only 3.6% to 132.2 million — brute force is old news; the growth is in automation against weaknesses, not password guessing itself.

Advisories Are Outpacing Threats



The CA issued 83,096,015 advisories during the year — up 60.8%, growing faster than the 29% rise in threats. Brute-force advisories alone jumped 365.5% to 25.5 million even though brute-force attacks grew just 3.6%.

Read that carefully: the warning system is scaling faster than the threat itself. Detection and advisories are working. The bottleneck is not visibility — KE-CIRT can see what is happening and is saying so loudly. The bottleneck is whether anyone acts on the warnings.

What This Means for Kenyan Businesses



Three practical conclusions fall out of the data:

  • Your patch queue is the threat model. With 96% of detections being vulnerability probes, the update status of every internet-facing system — the server, the router, the database, the NAS nobody remembers — determines whether you are in next year's 10.6 billion.

  • Web-facing forms are the front line. A 99% rise in web application attacks means login pages and forms need rate limiting, MFA on admin panels, and monitoring — not just a WAF checkbox.

  • Base decisions on the trend, not the spike. DDoS collapsed 90% in the final quarter. Budget for the wave pattern, not the peak panic.

  • Treat advisories as free intelligence. 83.1 million advisories are only noise if nobody reads them. Assign a human to triage KE-CIRT advisories the same way you'd triage an alarm.


The Boring Fix



The most uncomfortable reading of Kenya's 11.12 billion detections is how undramatic the defence is. This is not a nation being out-innovated by attackers; it is a nation where 96% of the threat dissolves with a maintenance discipline that every organisation — from a ministry portal to a two-person SME running a website on a shared host — already has the ability to execute.

Patch everything. Every time. On a schedule, not when it's convenient.

The number next year depends less on what attackers invent than on what Kenyan system owners finish updating.

---

Sources: Communications Authority of Kenya, Q4 FY2025/26 Sector Statistics Report (Table 22, Cybersecurity Landscape), published September 2026; IT News Africa; Kenyans.co.ke; Cyfirma Kenya Cyber Threat Landscape Report 2025–2026. Primary figures verified against the CA report PDF.

Want to learn more?

Contact GashoTech for personalized consultations on AI, automation, and cybersecurity solutions.

Get in Touch