VYPR
breachPublished Jul 21, 2026· 1 source

Kenya Investigates Hack of President's Website, Ransom Demand Issued

Kenya is investigating a cyberattack that defaced the president's official website, demanding a bitcoin ransom and threatening to release sensitive information.

Kenya is currently probing a significant cyberattack that saw the official website of the president defaced with an anti-government message and a demand for cryptocurrency. The incident, which occurred on Saturday, replaced the homepage with a message containing a Bitcoin wallet address and a threat to publish unspecified information concerning President William Ruto unless a ransom of five bitcoins, approximately $330,000, was paid.

Authorities confirmed the cyberattack over the weekend, with the Cabinet Secretary for Information, Communications and the Digital Economy, William Kabogo, stating that government cybersecurity teams were actively investigating. As a precautionary measure, access to the Presidential website was temporarily restricted to facilitate containment, forensic analysis, and restoration efforts. Kabogo assured the public that initial findings indicated no evidence of unauthorized access to sensitive data, data exfiltration, or loss of information, emphasizing that government systems and digital services remained secure and operational.

Screenshots of the defaced website, circulated on social media, showed the attackers claiming this was their "third" warning to the president before threatening to release data. However, authorities have not verified this claim, and no confirmed data leak has been made public to date. The identity of the perpetrators remains unknown.

This incident is not the first time Kenyan government websites have been targeted. In November 2025, a coordinated cyberattack disrupted multiple government websites, including those of the presidency and several key ministries. During that attack, ministry websites were defaced with white supremacist slogans, indicating a different motive and actor group.

The current investigation aims to identify the attackers and understand the full scope of the breach. While the website has since been restored, the incident highlights ongoing cybersecurity challenges faced by government entities in the region.

The demand for Bitcoin suggests a financially motivated attack, though the threat to release unspecified information could also indicate a motive for political disruption or reputational damage.

Officials are working to enhance security measures to prevent future occurrences and to reassure the public about the integrity of government digital infrastructure.

The investigation is ongoing, with authorities expected to provide further updates as more information becomes available.

Synthesized by Vypr AI