The defacement of the presidency portal highlights an escalating pattern of cyber aggression targeting Kenya’s critical digital infrastructure /PCS


On Saturday, July 18, the official website of the Kenyan President,  president.go.ke , suffered a high-profile cyberattack.

Threat actors breached the platform and defaced its public-facing homepage with messages targeting President William Ruto directly.

The attackers demanded a ransom of five bitcoin, equivalent to about Sh41.3 million. They issued a strict ultimatum to pay by 6 pm that evening.

In their ransom message, the hackers threatened to leak unspecified sensitive information about the President if their financial demands were not met.

Following the discovery of the breach, the government took the site offline as a precautionary measure to facilitate containment, forensic analysis and restoration.

ICT Cabinet Secretary William Kabogo confirmed the attack, saying the ICT Authority had activated its established cybersecurity response protocols immediately.

Despite the highly visible defacement of the homepage, Kabogo assured the public that preliminary findings showed no evidence of unauthorised access to sensitive government data, data exfiltration, or loss of information.

Comprehensive forensic investigations are still underway by the National Computer and Cybercrime Coordination Committee and State House technical teams. The nature of the attack, however, suggests a superficial layer compromise rather than a deep database intrusion.

Government websites are frequently targeted through unpatched vulnerabilities in their underlying content management systems or exposed administrative credentials that lack multi-factor authentication.

In this incident, the attackers successfully gained unauthorised write-access to the web server's public directory, which allowed them to overwrite the legitimate homepage with their cryptocurrency wallet address and ransom note.

The defacement of the presidency portal highlights an escalating pattern of cyber aggression targeting Kenya’s critical digital infrastructure.

A report in June this year by the National Computer and Cybercrime Coordination Committee revealed that Kenyan government systems and critical digital services faced more than three billioncyberattacks within three months.

Furthermore, the attack on July 18 marks the second compromise of the president.go.ke domain in less than a year, following a coordinated breach in November last that concurrently affected the presidency portal alongside the ministries of Interior, Health, Education, Labour and Energy.

Threat actors are increasingly leveraging the high visibility of official state domains, as defacing a head-of-state portal offers maximum public panic and leverage for financial extortion with minimal technical sophistication.

To shift from reactive containment to proactive defence, the government must adopt stricter security mandates.

E-government platforms must be managed as critical information infrastructure, backed by continuous operational security budgets.

The state should enforce zero-trust architectures, ensuring that administrative access to all state portals is strictly restricted using virtual private networks and mandatory multi-factor authentication. Moving beyond standard firewalls, authorities must mandate automated, continuous vulnerability scanning and proactive threat hunting across all ministries.

Finally, the newly approved National Cybersecurity Agency framework must rapidly enforce unified, cross-sector security protocols to close the structural gaps that enable recurring digital breaches of e-government systems.

The writer is a cyber security researcher at the Global Centre for Policy and Strategy, a Nairobi-based think tank