Kenyan authorities have launched a forensic investigation after hackers defaced the State House website and demanded a Bitcoin ransom of approximately Ksh41 million.
Nairobi, Kenya (Running Africa) — The Kenyan government has launched a forensic investigation after President William Ruto’s official State House website was hit by a cyberattack that saw hackers deface the homepage and demand a Bitcoin ransom reportedly worth Ksh41 million.
The attackers replaced content on the president.go.ke homepage with messages targeting the Head of State before the website was taken offline as authorities moved swiftly to contain the breach.
Government Activates Cybersecurity Response
The Ministry of Information, Communications, and the Digital Economy said the ICT Authority detected the cyberattack and immediately activated Kenya’s national cybersecurity incident response protocols.
Access to the website was temporarily restricted while digital forensic experts began investigating the intrusion’s source and assessing the extent of the compromise.
No Evidence of Data Breach
In a statement, the ministry said there was no evidence of unauthorized access to sensitive government systems, data theft, or loss of official information.
Officials also stressed that the broader Kenyan government digital infrastructure remains secure and that efforts are underway to restore the State House website safely.
At the time of publication, the State House had not issued a separate statement on the incident.
Cybersecurity Concerns Resurface
The attack is the latest in a series of cybersecurity incidents targeting Kenyan government platforms.
In 2023, multiple government websites were disrupted by the hacktivist group Anonymous Sudan, highlighting the growing threat posed by cyberattacks against critical public-sector infrastructure.
The latest breach has renewed debate over the resilience of Kenya’s cybersecurity framework as the country continues to position itself as a regional leader in technology, digital innovation, and e-government services.
Security investigators are expected to determine how the attackers gained access to the website, whether any additional systems were targeted, and who may have been responsible for the attempted extortion, as authorities work to strengthen protections against future cyber threats.