← Himilo
Technology & AI

A Bitcoin ransom note on Kenya's presidential website, for the second time in a year

State House, Nairobi — the official residence and office of Kenya's president. The presidential website, a separate system from State House itself, was defaced on July 18, 2026.
State House, Nairobi — the official residence and office of Kenya's president. The presidential website, a separate system from State House itself, was defaced on July 18, 2026.DEMOSH, via Wikimedia Commons

Hackers defaced president.go.ke on July 18, demanding 5 BTC and threatening to leak information about President Ruto. Officials say no sensitive data was taken. It is the second such breach since November.

Sometime after 2pm on Saturday, July 18, anyone who visited president.go.ke stopped seeing the usual fare of state photographs and press releases. Instead they found a message addressed to President William Ruto: \"This message is the third time for you; before we leak everything about you. Do a payment of 5 bitcoins to the Bitcoin wallet... if you want peace before 6 o'clock this evening.\"\n\nThe wallet address sat beside the threat, worth roughly Ksh41.3 million, or about $317,000, at the time. State House confirmed the breach within hours and pulled the site offline. William Kabogo, the cabinet secretary for information, communications and the digital economy, said Kenya's national computer incident response team, KE-CIRT/CC, was managing containment and forensic analysis, and that there was \"no evidence of unauthorised access to sensitive data, data exfiltration, or loss of information.\" The homepage was restored by the end of the day. Whether the attackers ever actually possessed the compromising material they threatened to leak, investigators have not said.\n\nWhat makes this Saturday's incident more than a one-off embarrassment is the calendar. In November 2025, a coordinated attack hit the presidency's site alongside the ministries of health, education, interior, and ICT — some pages were defaced with extremist and white-supremacist content, and a group calling itself PCP@Kenya claimed responsibility. Eight months later, the presidential website has been compromised again. Two breaches of the same office's front door within a year is not a fluke; it is a pattern, and patterns point to something structural rather than a single bad password.\n\nWhy a defaced homepage is cheap theater with real stakes\n\nVictoria Robinson, a cybersecurity research analyst at Ethnos Cyber Limited, told Techpoint Africa that government domains are attractive precisely because the cost of attacking them is so low relative to the payoff in attention. \"A .go.ke or any state domain gives instant credibility to whatever message you deface it with,\" she said. \"You get press coverage, public panic, and leverage for extortion in one shot.\" Contrast that with a breach at an ordinary company, which draws none of that same spotlight. Nairobi-based security practitioner Nick Thiong'o offered a similar read: some of what drives these attacks isn't the ransom at all, but the platform. \"For you to target the head of state, you know you'd actually get the attention that you're seeking,\" he said.\n\nBoth analysts pointed to the same underlying weakness: government websites in Kenya, as in much of the region, tend to be built once, by the lowest bidder, and then left largely unattended. Outdated content-management platforms, admin credentials that are never rotated, and exposed control panels without multi-factor authentication are common threads, according to Robinson. There is no ongoing security budget line the way there would be for, say, physical security at a ministry building — the website gets funded as a project with a launch date, not a piece of infrastructure that needs continuous defense.\n\nThiong'o also flagged a newer wrinkle: generative AI has lowered the skill floor for this kind of attack. Large language models can be jailbroken to write malicious code, meaning an attacker no longer needs to be a competent programmer to script a defacement or a credential-stuffing attempt. \"We're on the cusp of something that would be recurring,\" he said, \"because we don't know where the attackers would focus on next.\"\n\nA test for a policy that already exists on paper\n\nThe frustrating part, from a policy standpoint, is that Kenya has already taken the first institutional step. The government recently approved a National Cybersecurity Agency Order intended to centralize incident response and policy across agencies — exactly the kind of coordinating body Robinson argues is needed. This weekend's breach becomes, in effect, an early stress test of that framework: how fast containment and forensic work moved, and how quickly the homepage came back, are the visible proxies for whether the new structure is actually functioning or still mostly aspirational.\n\nRobinson's prescription, meanwhile, reads like a checklist rather than a mystery: phishing-resistant multi-factor authentication (ordinary SMS codes are now routinely defeated by adversary-in-the-middle kits), a real patch schedule for content-management software instead of a set-it-and-forget-it deployment, network segmentation between the public-facing web tier and anything sensitive behind it, and continuous logging so a breach is caught in minutes rather than discovered by a citizen's screenshot. None of it is exotic. All of it costs money and sustained attention — the two things a one-off government web contract is least designed to provide.\n\nThe pattern isn't unique to Kenya; similar defacements have hit government sites in Nigeria, South Africa, and elsewhere in recent years, part of a broader continental reality in which public-sector digitization has outpaced public-sector security spending. As more government services move online across Africa — tax filing, land registries, health records — the gap between the two only grows more consequential. A defaced homepage is recoverable within a day. Rebuilding public confidence in a government's digital defenses, as one Kenyan outlet put it after the November attack, takes considerably longer.

Illustrative: a laptop secured with a padlock. Security researchers say many government websites in the region lack basic ongoing protections like multi-factor authentication and regular patch cycles.
Illustrative: a laptop secured with a padlock. Security researchers say many government websites in the region lack basic ongoing protections like multi-factor authentication and regular patch cycles.Santeri Viinamäki, via Wikimedia Commons
WhatsAppXLinkedIn