Kenya is under digital siege. The East African nation absorbed a staggering 4.6 billion cyber threat events in just three months ending December 2025, according to a Communications Authority of Kenya report I reviewed.
This represents a jaw-dropping 441.3% jump from the previous quarter's 842 million events. Notably, not just the scale, but the speed at which these attacks are evolving.
AI Weaponization Drives Attack Surge
The Communications Authority of Kenya directly blamed AI-driven tools exploited by malicious actors for this unprecedented spike. System vulnerabilities dominated the threat landscape with 4.37 billion events, climbing 463.4% quarter-on-quarter.
Mobile application attacks were not spared either, jumping 303.2%. But the most alarming category was Distributed Denial-of-Service incidents, which overwhelm websites until they crash.
Here is where the numbers become truly concerning: DDoS attacks exploded by 1,116.7%, yet authorities issued only 1.34 million advisories out of 21.8 million total responses. This massive mismatch between threat velocity and regulatory attention exposes Kenya's structural cybersecurity gap.
The Financial Stakes Keep Rising
Kenya already lost an estimated $83 million to cybercrime in 2023, ranking second in Africa behind Nigeria's $1.8 billion losses. The timing of this surge could not be worse.
The country's fintech sector is projected to handle $1.5 trillion in payments by 2030. M-PESA alone processes over 100 million transactions daily across the same networks these attackers are targeting.
Warning Signs Were Already There
This explosion did not happen overnight. The National Kenya Computer Incident Response Coordination Centre detected 657.8 million threat events in July-September 2024, already showing a 41.87% quarterly increase.
By the first quarter of 2025, Kenya recorded 2.54 billion cyber threat events—a 201.7% surge. The December quarter's 4.6 billion figure represents another doubling, creating an exponential growth pattern that should terrify policymakers.
Official Response Falls Short
The Communications Authority recommended standard measures in their report: multi-factor authentication, comprehensive password policies, proper network firewall configuration, and continuous system patching advisories.
"Key measures for mitigating emerging cyber threats may be achieved through the implementation of multi-factor authentication with comprehensive password policies, proper network firewall and antivirus software configuration, and continuous enhancement of advisories to emphasise regular system and application patching," the CA recommended.
While these recommendations sound reasonable, they feel inadequate against AI-powered attack vectors that are evolving faster than traditional defences. Kenya needs more than patching—it needs a fundamental rethink of its cybersecurity architecture.
The country's digital economy dreams depend on solving this crisis before it reaches the point of no return. With AI technology accelerating both opportunities and threats, Kenya faces its biggest cybersecurity test yet.
