
Cybersecurity
Kenya Is Africa's #2 Cyber Target — Reading INTERPOL's 3 August Report Against the New NCSA Mandate
August 7, 2026GashoTech
Kenya Is Africa's #2 Cyber Target — Reading INTERPOL's 3 August Report Against the New NCSA Mandate
On 3 August 2026 INTERPOL published the African Cyberthreat Assessment Report 2026, a 40-page document drawn from survey data across 36 African member countries and partner telemetry from the Shadowserver Foundation, Fortinet, Mastercard, S2W and TrendAI. The headline number for Kenya is stark: 11.9% of all exploitable digital vulnerabilities detected across the continent in 2025 sit on Kenyan infrastructure. That places the country second in Africa, behind only South Africa (43.6%) and ahead of Nigeria (9.1%).
The number is not a vanity ranking. It is the same indicator the Shadowserver Foundation uses to count the unpatched routers, vulnerable VPNs and misconfigured web-based document management platforms that attackers actually exploit. It counts the holes, not the incidents. By that measure Kenya is now the continent's second-largest concentration of holes.
What 11.9% means in practice
INTERPOL's methodology looks at exposed systems that are well-documented, publicly known, and trivially exploitable. The top three attack surfaces are outdated and unpatched routers, vulnerable VPNs, and misconfigured document management platforms. None of these are exotic zero-days. They are hygiene failures — and they are concentrated, by the report's own count, in South Africa, Kenya and Nigeria, the same three countries with the largest internet user bases on the continent.
For Kenya, that means the country's cyber exposure is not a function of which sophisticated threat group has decided to target it. It is a function of how many internet-facing systems the country has failed to patch, segment, or authenticate. The attacker profile is global; the vulnerability profile is local.
The AI-enabled shift
The single most cited finding of the report is that 55% of reported cybercrimes across Africa are now AI-enabled. This is not a future prediction; it is the 2025 baseline. AI is now used to automate every stage of an attack — reconnaissance, phishing, credential harvesting, extortion, and evasion. Neal Jetton, Director of INTERPOL's Cybercrime unit, put it plainly: "Cybercrime has emerged as one of the most significant criminal threats to the region. AI is automating every stage of a cyberattack."
The attack surface is moving in three directions at once. First, online scams remain the most reported category, and they are increasingly mobile-money and social-media-native. Second, business email compromise (BEC) is now AI-generated — correspondence that once carried tell-tale grammar mistakes now reads as if a fluent local wrote it. Third, criminals are no longer stealing existing credentials; they are generating entirely synthetic identities that combine real personal data with fabricated elements, and those personas are now bypassing biometric verification at scale. The report records roughly 600,000 sextortion detections from TrendAI in 2025 alone, the great majority of them deepfake-driven.
The East Africa mobile-money risk
INTERPOL's regional breakdown is unflattering for Nairobi. East Africa has emerged as a hub for mobile-money fraud and infrastructure-targeted ransomware. The first risk is structural: M-Pesa alone now holds more than 53 million accounts in Kenya, and the broader mobile-money ecosystem is the settlement layer for everything from utility payments to school fees. A successful attack on a tier-1 mobile-money operator is no longer a cybersecurity incident; it is a national payments incident.
The second risk is ransomware aimed at infrastructure — power, water, transport, healthcare. The report does not name targets, but the trend line is clear: as African economies digitise, the same critical systems that ransomware crews hit in Europe and North America are coming into scope in East Africa. The Colonial Pipeline moment in the United States, when a single ransomware operator shut down the East Coast fuel pipeline for six days in 2021, is now a planning scenario, not a foreign curiosity.
The financial scale
Across Africa, INTERPOL puts the financial toll of cybercrime at USD 484 million in 2025, more than double the USD 192 million recorded in 2024. The growth is driven primarily by AI-facilitated scams, credential harvesting and automated social engineering. 72% of surveyed countries now host scam centres, with the highest concentration in Southern and West Africa — but the targeting is continental, and the financial-services, telecoms and government sectors are the hardest hit.
It is important to be careful with the USD 484 million figure. It is the reported loss, not the total loss. Most African cybercrime is never reported, especially when the victim is a small merchant or a household that lost KES 50,000 to a mobile-money scam. The real number is materially larger. The reported number is the floor, not the ceiling.
The NCSA's first 100 days
Kenya's response to this report is the National Cybersecurity Agency (NCSA), established under the National Cybersecurity Agency Order, 2026, issued by President William Ruto under the State Corporations Act and approved by Parliament in June 2026. The agency is now the body corporate responsible for the National Cybersecurity Operations Centre, sector-based cybersecurity units, audits of critical information infrastructure, technical advisories, and a new Cybersecurity Centre of Excellence for research, innovation and skills development.
The strategic read is that the NCSA has to operationalise into a threat landscape that is already moving. Its first-year footprint — staffing, budget, sector coverage — is being set against attackers who are now AI-enabled, mobile-money-native, and synthetic-identity-capable. The agency is starting behind. Closing the gap requires three concrete moves in the first 100 days.
First, mandate baseline vulnerability disclosure for all critical information infrastructure operators, with quarterly reporting. The 11.9% figure exists because nobody was forced to count the holes before. Counting them is the first step to fixing them.
Second, integrate the National Cybersecurity Operations Centre with the mobile-money sector's fraud monitoring. East Africa's mobile-money fraud hub status is not a separate cybersecurity problem; it is the same problem as the broader continent-wide AI-enabled shift. The data has to flow between the telcos, the banks and the agency in real time — the report explicitly identifies the absence of real-time inter-agency data sharing as a dangerous blind spot.
Third, fund the Cybersecurity Centre of Excellence as an applied institution, not a research one. The skills gap the report names — AI literacy among law enforcement officers, standardised digital forensic capabilities — is exactly what an applied centre would build. The risk is that the Centre becomes a publishing outfit; the requirement is that it ships trained personnel and tested playbooks.
What founders and CISOs should do now
For Kenyan founders, the operational read is direct. The threat volume is up, the attack methods are now AI-native, and the regulator is still hiring. The minimum baseline that has to be in place before the end of Q4 2026 is: (1) external attack-surface mapping for every internet-facing system, with a patching SLA of 14 days for critical CVEs; (2) phishing-resistant authentication — hardware keys or passkeys, not SMS OTPs — for all admin and finance roles; (3) a tested mobile-money fraud response playbook with the relevant telco and bank counterparties named; and (4) a synthetic-identity detection layer in any onboarding flow that still uses selfie + ID document verification.
The INTERPOL report is a baseline, not a forecast. The numbers will get worse before they get better. Kenya is now formally the second most cyber-exposed country in Africa. The next 100 days of NCSA operational decisions will determine whether that ranking improves by the time the 2027 report drops, or whether the new agency is benchmarking against a moving target it cannot catch.
Sources
- INTERPOL, African Cyberthreat Assessment Report 2026, published 3 August 2026
- INTERPOL press release, INTERPOL report finds AI linked to more than half of cybercrime in Africa, 3 August 2026
- Tuko.co.ke, Interpol Ranks Kenya Second in Africa for Cyber Attacks, 4 August 2026
- Small Wars Journal, Interpol Releases Report on AI Cybercrime in Africa, 5 August 2026
- Fintech Association of Kenya, Kenya Establishes National Cybersecurity Agency, June 2026
- ITWeb Africa, Kenya approves national cyber security agency, 23 June 2026
Want to learn more?
Contact GashoTech for personalized consultations on AI, automation, and cybersecurity solutions.
Get in Touch