On the morning of Saturday 18 July 2026, the homepage of president.go.ke temporarily stopped being the official website of the President of the Republic of Kenya. In its place sat a ransom note, a cryptocurrency wallet address and a deadline. The attackers wanted five bitcoins, about KSh 41.3 million at that day’s exchange rate, and threatened to publish materials they claimed to possess relating to President William Ruto[MK1] if they were not paid by six o’clock that evening.
By the evening bulletins the site had been pulled down and replaced with a maintenance 1notice. Information, Communications and the Digital Economy Cabinet Secretary William Kabogo confirmed the incident, said access had been restricted to allow containment and forensic analysis, and reported that there was at that point “no evidence of unauthorized access to sensitive data”, exfiltration, or loss of government information. The ICT Authority, he said, was working with other agencies on a full forensic investigation.
Eight months earlier, on November 2025, a coordinated attack defaced government websites across the Ministries of Health, Education, Labour, Environment, ICT, Tourism and Interior, along with Nairobi City County, Immigration, the Directorate of Criminal Investigations, the Hustler Fund and the Government Press. The presidential website was among them, which means president.go.ke has now been compromised twice within eight months.
Before that, in July 2023, the eCitizen platform was attacked and access to major government services was paralyzed. Anonymous Sudan claimed responsibility, saying the attack was retaliation for Kenya’s alleged interference in Sudanese affairs. Then ICT Cabinet Secretary Eliud Owalo told the country that no data had been lost.
What makes the eCitizen attack instructive is what preceded this attack. In her report for the financial year ended June 2023, Auditor-General Nancy Gathungu had already recorded that eCitizen operated without an approved ICT policy, without an ICT steering committee, without an approved business continuity plan and without a secondary backup site. The platform was breached days into the following financial year. The warning had already been formally tabled in Parliament before the attack occurred.
In the last week of July 2026 the National Assembly’s Public Accounts Committee, chaired by Butere MP Tindi Mwale, took evidence from Energy Principal Secretary Alex Wachira. The Auditor-General’s report on the State Department for Energy’s 2024/25 accounts had flagged that staff were conducting official government business through private email accounts, despite the department holding an official government email domain, and despite a Head of Public Service circular of 14 June 2022 prohibiting exactly that practice.
Wachira did not dispute the findings. He told the committee the department was “in the process of” designating an officer to serve as Data Protection Officer, and “in the process of” registering as a controller and processor in compliance with the Act. On the private email accounts, he said management had noted the observation, had since allocated official addresses to employees, and had directed officers to use only government accounts.
Kenya’s Data Protection Act came into force in 2019. The registration rules were implemented in July 2022. In November 2025, the ODPC issued a guidance note for ministries, state departments and agencies, outlining these specific responsibilities. During the committee proceedings, Aldai MP Marianne Kitany questioned why compliance with a law enacted in 2019 had taken several years. Funyula MP Wilberforce Oundo highlighted the penalties for non-compliance, While Lugari MP Nabii Nabwera called for a systems audit to determine whether confidential government information had been exposed. Committee Chairperson, Tindi Mwale subsequently directed the Auditor-General to undertake the audit and establish whether the use of private email accounts had resulted in data breaches.
That directive is perhaps the most important issue here. Parliament had to order an audit to determine whether the Ministry of Energy had suffered a breach because the ministry itself could not say.
This is what non-compliance actually costs, and it is not primarily a matter of fines. Section 43 of the Data Protection Act requires a controller to notify the Data Commissioner within 72 hours of becoming aware of a breach, and to communicate with the affected person in writing. A department with no Data Protection Officer, no registration and years of official correspondence sitting in private inboxes may lack the governance structures needed to promptly detect, assess and respond to a personal data breach. The 72-hour clock never starts, because one has nothing to start it with. Registration and a named officer are the means by which an institution becomes aware that something has gone wrong and tells the person it happened to.
The scale of what that machinery is meant to catch is not in dispute. The National KE-CIRT/CC detected 3.37 billion cyber threat events between January and March 2026, of which approximately 96 per cent involved attempts to exploit system vulnerabilities. According to the Communications Authority, the volume reflected persistent weaknesses including inadequate system patching, insufficient user awareness of phishing and other social engineering threats, and the growing use of AI-enabled techniques by malicious actors. In June, the National Computer and Cybercrime Coordination Committee put a similar figure before Interior PS Omollo and warned that the threat environment was becoming more complex.
So the question is not whether the state knows. It knows in detail, quarterly, in published reports written by its own agencies.
Consider what that department holds. The same committee is examining a wayleave compensation programme worth KSh 17.02 billion, of which approximately Ksh 4.03 billion remained unpaid across projects spanning more than thirteen years. The programme concerns compensation to landowners affected by electricity transmission infrastructure and therefore involves personal data capable of identifying individual claimants and facilitating payments. Yet, according to the Auditor-General’s findings on the State Department for Energy, some official correspondence was conducted through private email accounts that fall outside the government’s security controls and administrative oversight.
The farmer in Kakamega whose land is affected by the programme may never know whether his personal information has been adequately protected. If that information were exposed, he could discover if only after receiving a fraudulent call, finding a loan taken out in his name, or learning that a stranger possesses information that should never have left government systems.
That is the real human impact. Data protection is not merely about databases or computer systems. It is about protecting people’s privacy, dignity and security..
There are four practical steps the state could take this quarter. Publish the forensic report on the July breach, including whether the intrusion extended beyond the homepage and what the first two messages said. Ensure every ministry, state department and agency appoints a designated Data Protection Officer and publicly confirms the appointment. The Office of the Data Protection Commissioner should publish an up-to-date register of compliance by ministries, state departments and agencies, allowing the public to monitor progress. And when the Auditor-General’s systems audit is complete, table it in Parliament and make its findings on security failures public.
Cybersecurity is ultimately about protecting people, not merely systems. Accountability is measured by whether public institutions explain what happened, remedy the failures that exposed people to harm, respect individuals’ rights to information and privacy, and allow the public to verify that those failures have been been addressed.
Sharlene Muthuri writes in her own capacity. [email protected]


