Kenya Restores President's Website After Cyberattack
The Government of Kenya has restored President William Ruto's official website after hackers briefly took control of the platform, replacing its content with anti-government messages and a Bitcoin ransom demand.
The Ministry of Information, Communications and the Digital Economy confirmed that the website suffered a cybersecurity incident on 18 July, but said there was no evidence that sensitive government data had been compromised. Access to the website was temporarily restricted while forensic investigations were carried out before the platform was restored later that day.
Hackers Demanded Bitcoin Ransom
During the attack, the hackers defaced the website with messages targeting President Ruto, displayed a Bitcoin wallet address, and demanded 5 BTC in exchange for not releasing what they claimed was sensitive information.
While authorities have not confirmed whether the attackers gained access beyond the website itself, the incident has renewed concerns about the security of Kenya's digital government infrastructure.
Latest in a Series of Cyberattacks
The breach adds to a growing list of cyber incidents targeting Kenyan government platforms.
In 2023, a cyberattack disrupted the country's eCitizen platform, affecting multiple public services, while another coordinated attack in November 2025 targeted several government websites, including the presidency's portal, temporarily replacing pages with extremist content.
The government restored the affected systems following both incidents and pledged to strengthen its cybersecurity capabilities.
Focus Turns to Government Cybersecurity
Kenya has accelerated the digitisation of public services in recent years, making government platforms increasingly attractive targets for cybercriminals, ransomware groups and hacktivists.
Authorities are continuing forensic investigations to determine how the attackers gained access and whether the breach extended beyond the website's public-facing interface.
While the government maintains that its core systems remain secure, the incident is expected to intensify efforts to strengthen cybersecurity across public sector digital infrastructure.