Skip to content

Kenya Under Cyberattack: Unpacking Today's Government Website Breaches

Nairobi, Kenya – November 17, 2025. Today, Kenya woke up to a stark reminder of the ever-present dangers in the digital age. A coordinated cyberattack sent shockwaves through the nation.

Seraph Cyber
3 min read
Illustration for the article “Kenya Under Cyberattack: Unpacking Today's Government Website Breaches”

Nairobi, Kenya – November 17, 2025

Today, Kenya woke up to a stark reminder of the ever-present dangers in the digital age. A coordinated cyberattack sent shockwaves through the nation, disrupting critical government online services and raising serious questions about national cybersecurity.

The Digital Blackout: What Happened?

Beginning in the early hours of this morning, a wave of cyberattacks targeted and successfully compromised the official websites of several key Kenyan government institutions. Among the high-profile casualties were:

  • The Presidency: The official portal of the President of Kenya.
  • Vital Ministries: Including the Ministries of Interior, Health, Education, Water, and Labour.
  • Key State Departments: Such as the Directorate of Criminal Investigations (DCI), the Immigration Department, and the Directorate of Public-Private Partnerships.
  • Local Governance: Nairobi City County systems also reported significant disruptions.

Visitors attempting to access these sites were met with error messages, redirects, or defaced pages displaying defiant messages attributed to the attackers. It was a digital blackout that underscored the vulnerability of our online infrastructure.

Who is Behind the Breach?

A group identifying itself as "PCP@Kenya" (or simply "PCP") has swiftly claimed responsibility for the widespread disruption. While the exact motivations behind the attack are still being investigated, their actions have certainly made a powerful, albeit disruptive, statement. The method appears to have primarily involved website defacement and Denial of Service (DoS) attacks, overwhelming servers and replacing legitimate content with their own.

Government Response and Reassurance

In response to the escalating situation, the Principal Secretary for Internal Security, Raymond Omollo, issued an official statement acknowledging the "cybersecurity incident." He reassured the public that the situation has been "fully contained" and that emergency response teams, including the National KE-CIRT/CC, were immediately mobilized to isolate the breach.

While most affected services are reportedly being restored, some users might still experience intermittent access as security protocols are reinforced across government platforms. Crucially, authorities have maintained that critical service platforms like eCitizen, NTSA, and the Judiciary were not impacted by this specific wave of attacks, and core government databases remain secure.

A Wake-Up Call for National Cybersecurity

Today's events serve as a wake-up call. This incident comes on the heels of the Communications Authority of Kenya (CA) reporting a alarming 200% increase in cyber threats earlier this year, with ransomware and DDoS attacks becoming increasingly prevalent. While the government's swift containment is commendable, the fact that such a broad array of critical sites could be compromised raises serious questions:

  • Are our national digital defenses robust enough?
  • How can sensitive data, especially from ministries like Health, be better protected?
  • What measures need to be implemented to prevent future incidents of this scale?

The Path Forward

As Kenya continues its journey towards a fully digitized economy and governance, cybersecurity cannot be an afterthought. It must be a foundational pillar. Today's incident highlights the urgent need for:

  • Increased Investment: In advanced cybersecurity infrastructure and technologies.
  • Enhanced Training: For IT professionals across all government sectors.
  • Public Awareness: Educating citizens on safe online practices and how to report suspicious activity.
  • Continuous Vigilance: Constant monitoring and updating of security protocols to counter evolving threats.

The digital battleground is real, and today, Kenya experienced a significant attack. While the immediate threat appears to be under control, the long-term work of securing our digital future has just become even more critical.

More writing

Threat analysis

The State of Social Engineering in Cybersecurity

The cybersecurity landscape has witnessed a dramatic transformation in social engineering attacks from 2024 to 2025, characterized by unprecedented growth in AI-powered threats and a fundamental shift in attack methodologies.

Seraph Cyber ·

Threat analysis

Supply Chain Security: The Hidden Cyber Risk Most Organizations Overlook

A significant proportion of major cyber incidents over the past decade have originated not from direct attacks on target organizations, but from vulnerabilities within their supply chains.

Seraph Cyber ·

Governance

Board accountability: cybersecurity is governance, not IT

Cybersecurity should not be treated as only an IT function. It is a governance issue that requires active board oversight, accountability, and strategic leadership. Strong board involvement helps organizations manage cyber risk, strengthen resilience, and protect business continuity, reputation, and stakeholder trust.

Seraph Cyber ·