Kenyan authorities are investigating a cyberattack that disrupted the official website of President William Ruto.
Attackers replaced the website’s homepage with insulting political messages aimed at the president. They also demanded a ransom of five Bitcoin and threatened to release unspecified information.
The Kenya website breach temporarily forced the presidential portal offline. However, officials have not confirmed whether the attackers accessed government data or internal systems.
Hackers Deface Presidential Website
The cyberattack targeted president.go.ke, the official website of Kenya’s presidency, on Saturday, July 18.
During the incident, visitors could no longer access the normal government content. Instead, the homepage displayed unauthorized messages targeting President Ruto.
The attackers also published a cryptocurrency wallet address. In addition, they demanded five Bitcoin, worth approximately 41 million Kenyan shillings at the time.
According to the ransom message, the hackers would publish unspecified information if the government refused to pay. However, they did not explain what data they had allegedly obtained.
No group has publicly claimed responsibility for the Kenya website breach.
Government Activates Cybersecurity Response
Kenya’s Information, Communications and the Digital Economy Cabinet Secretary William Kabogo confirmed that government cybersecurity teams were responding to the attack.
Meanwhile, the State House technology team began working to contain the incident and restore the presidential website.
Officials removed the defaced homepage and took the website offline. This step prevented visitors from viewing the attackers’ messages while specialists investigated the affected systems.
The government has not disclosed whether it plans to negotiate with the attackers. It has also provided no indication that it will pay the requested ransom.
Scope of the Attack Remains Unclear
Authorities have not confirmed whether the cyberattack went beyond the public-facing website.
Website defacement does not always provide attackers with access to private databases or internal networks. In some cases, hackers only change content visible to the public.
However, the ransom message raised concerns that the attackers may have obtained sensitive information. Investigators must therefore determine how the intruders entered the website and whether they accessed any connected systems.
So far, the government has not reported any confirmed data theft. The hackers have also not published evidence showing that they possess confidential files.
As a result, claims about stolen government information remain unverified.
Kenya Investigates Possible Data Exposure
The investigation will likely examine server logs, administrator accounts, software vulnerabilities, and third-party services connected to the presidential portal.
Cybersecurity teams may also review whether attackers stole login details or exploited an unpatched security flaw. Additionally, they must establish how long the intruders remained inside the system.
The Kenya website breach has renewed concerns about the security of public-sector digital services. Government portals are attractive targets because they carry political importance and often provide essential information to citizens.
Attackers can also use defaced government websites to spread political messages, damage public trust, or pressure authorities into paying a ransom.
Presidential Portal Taken Offline
The website remained unavailable after officials removed the unauthorized content. Authorities have not announced when normal service will return.
Before restoring the portal, cybersecurity specialists will need to confirm that the attackers no longer have access. They may also reset credentials, patch vulnerabilities, and strengthen monitoring around the system.
The investigation remains active. Therefore, it is still unclear who carried out the attack or whether the hackers obtained any sensitive data.


0 responses to “Kenya Website Breach Triggers Government Investigation”