Kenya has been identified as East Africa's most vulnerable nation to cyber attacks, ranking second on the continent for exploitable digital weaknesses in 2025, according to the Interpol African Cyberthreat Assessment Report 2026.

The report highlights that Kenya accounted for 11.9% of Africa's detected digital vulnerabilities, trailing South Africa's 43.6% but ahead of Nigeria at 9.1%. Factors contributing to this high exposure include poor cyber hygiene, underinvestment in cybersecurity, and delays in applying software updates across both public and private sectors.

Surge in SIM Swap Fraud

One of the most concerning trends is the sharp increase in SIM swap fraud. Investigations revealed a 327% rise in such cases in 2025, with over 123,000 fraudulent SIM cards identified. These scams resulted in losses amounting to approximately KSh 492 million (USD 3.8 million) drained from mobile wallets nationwide.

Fraudsters used social engineering tactics to collect personal information, then impersonated victims when requesting SIM replacements from telecom customer service. Once activated, the fake SIMs allowed criminals to intercept one-time passwords and transaction alerts, gaining unauthorized access to victims' financial accounts.

Interpol pointed out that weak Know Your Customer (KYC) protocols and inadequate real-time identity verification by telecom providers enabled these scams. Additionally, while banks could detect suspicious transactions, legal and technical limitations prevented them from immediately blocking SIM swaps or freezing accounts without court approval.

Other Cybersecurity Challenges

  • Kenya experienced over 46,700 distributed denial-of-service (DDoS) attacks within the first half of 2025, mainly targeting telecom operators.
  • The Communications Authority of Kenya recorded hundreds of millions of intrusion attempts on government and ICT systems between July and September 2025, exploiting outdated routers, unsecured VPNs, and online document management vulnerabilities.
  • These security gaps stemmed from known, publicly documented weaknesses, underscoring ongoing challenges in cyber hygiene and resource allocation.

Artificial Intelligence and Cybercrime

The report also highlighted the expanding role of artificial intelligence in cybercrime, with AI involved in 55% of cases across Africa. Criminals employed AI to automate phishing, create deepfakes for identity theft, and generate synthetic identities capable of bypassing biometric systems.

Such AI-generated identities combined real and fabricated data to open bank accounts, obtain mobile loans, and register SIM cards under false names.

Law Enforcement Efforts

Kenyan authorities arrested 27 suspects during Interpol's Operation Red Card 2.0, a coordinated effort across 16 African countries conducted from December 2025 to January 2026. The operation recovered USD 4.3 million across the region.

Despite these successes, the report stresses the need for a unified regional cybercrime response to effectively combat cross-border criminal networks exploiting jurisdictional gaps.