Kenya probes breach of President Ruto’s website; 5 BTC demand

Hackers briefly disabled President William Ruto’s official website on July 18, defaced the homepage and demanded five bitcoins. Authorities opened a forensic probe and restricted access.

Kenya is investigating a cyberattack that briefly disabled the official presidential website on July 18. Attackers replaced the homepage of president.go.ke with derogatory messages, posted a demand for five bitcoins and warned they would leak unspecified data if the ransom was not paid. Officials took the portal offline and limited public access while they investigated.

Government technicians began working with the National Computer and Cybercrime Coordination Committee (NC4) and external cybersecurity specialists to restore services and trace the intrusion. William Kabogo, the cabinet secretary for the Ministry of Information, Communications and the Digital Economy, wrote on the platform X: “At this time, there is no evidence of unauthorized access to sensitive data, data exfiltration, or loss of information.” He added that government systems and other digital services remained operational during the investigation.

State House technical teams and NC4 are carrying out forensic tests to determine where security perimeters failed. Officials have not released details on the method used to breach the site and have not confirmed whether any data was copied or removed. No arrests or identifications of perpetrators have been announced.

The July incident is the second widely reported cyberattack on Kenyan government infrastructure within a year. In November 2025, a coordinated attack briefly compromised several ministry websites. An NC4 report issued earlier this year recorded billions of digital threats against critical infrastructure and government systems over a three-month period and prompted initiatives to standardize cybercrime investigation procedures across agencies.

The government has not said whether it will meet the ransom demand. Investigators are prioritizing identification of the attack vector, assessment of any impact on connected systems, and review of defensive measures across related government platforms.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author