Time flies with great content! Renew in to keep enjoying all our premium content.
Prime
Cyber-attacks surge more than five-times on AI abuse
The growing mobile-phone malware threats represents a new entry point for criminals who typically were used to stealing bank credentials by other means, such as installing skimmers on automatic teller machines or by using scams targeting desktop computer users.
Cyber threat incidents targeting Kenyan organisations surged more than fivefold in the three months to December 2025, underscoring the growing scale and sophistication of attacks on local critical digital infrastructure.
Data from the Communications Authority of Kenya (CA) shows 4.56 billion cyber threat incidents were detected during the period, a 441.27 percent increase from the 842 million recorded in the previous quarter.
This is among the sharpest quarter-on-quarter rises ever reported by the CA’s national incident response unit, reflecting mounting pressure on public and private systems as attackers exploit vulnerabilities.
“The cyber threats detected were largely due to inadequate system patching, limited user awareness of phishing and social engineering, and the increasing use of AI-driven and machine-learning tools by malicious actors,” the CA noted in its latest release.
In response, the Authority issued 21.82 million cyber threat advisories, a 9.34 per cent increase from the previous quarter. “As part of its proactive approach, the Authority continued to enhance the dissemination of advisories to critical information infrastructure sectors,” the report added.
System attacks dominated, with 4.38 billion incidents—a 463.44 percent rise from July–September.
These attacks targeted operating systems, databases, and network infrastructure, particularly systems run by internet service providers (ISPs) and cloud providers.
“Threat actors exploited outdated vulnerabilities to steal user authentication credentials, while the rapid proliferation of IoT devices lacking proper security controls worsened the problem,” the CA said.
Other threats included malware (70.9 million), Distributed Denial of Service (DDoS) attacks (58.3 million), brute force attacks (42.8 million), web application attacks (11.6 million), and mobile application attacks (310,009). DDoS attacks recorded the steepest growth, surging 1,116.06 per cent from the previous quarter.
These attacks targeted critical public ICT infrastructure, with perpetrators using reflection and amplification techniques. Mobile devices and Android TVs were particularly affected.