Kenya probes hack of Ruto’s official site after bitcoin ransom demand

▼ Summary
– Kenyan authorities are investigating a cyberattack that defaced President William Ruto’s official website with a ransom message and cryptocurrency wallet address.
– The government found no evidence of sensitive data being taken and restored the site by Sunday.
– The intruders demanded five bitcoins (about $317,000) and threatened to leak material if not paid, with the message claiming it was the third such warning.
– The National Computer and Cybercrime Coordination Committee (NC4) was activated to lead the response, alongside State House technical teams.
– The attack is the latest in a series of cyber intrusions against Kenyan government platforms, including a 2023 DDoS campaign and a 2025 assault on dozens of state websites.
Kenyan authorities are investigating a cyberattack that defaced President William Ruto’s official website over the weekend, with the homepage replaced by a ransom note and a cryptocurrency wallet address. The government took president.go.ke offline on Saturday and has since stated that no sensitive data appears to have been compromised.
The intruders demanded five bitcoins, equivalent to roughly 41 million Kenyan shillings (approximately $317,000), and threatened to leak materials if the payment was not made by that evening, according to local media outlets that viewed the page before it was taken down. The message, addressed directly to Ruto, claimed it was the third such warning issued to his administration.
The defaced homepage, first flagged shortly after 2pm on Saturday, contained derogatory language and unspecified allegations against the president alongside the wallet address. By then, the usual content of speeches and press releases had been erased from public view.
William Kabogo, the cabinet secretary for information, communications and the digital economy, confirmed the breach on Saturday. He said access to the site had been “temporarily restricted to facilitate containment, forensic analysis and restoration efforts.” He added that there was “no evidence of unauthorised access to sensitive data, data exfiltration, or loss of information.”
The National Computer and Cybercrime Coordination Committee (NC4) was activated to lead the response, working alongside State House technical teams and external partners. Kabogo assured the public that government systems and digital services “remain secure and operational,” and the site was restored by Sunday with its speeches, press releases and communications intact.
No group has claimed responsibility, and officials have not disclosed how the attackers gained entry or whether they consider the ransom demand credible.
The timing is awkward for an administration that has spent two years navigating both street protests and digital intrusions. Ruto’s government has faced sustained Gen Z-led demonstrations over taxation, the cost of living and police conduct, protests that have played out as much on social platforms as on Nairobi’s streets.
Its online infrastructure has been probed repeatedly during this period, and the defacement of the head of state’s own site carries a symbolic sting the government was quick to contain. Officials moved within hours to restrict access and frame the episode as contained rather than catastrophic.
In 2023, the hacktivist group Anonymous Sudan knocked out the eCitizen portal Kenyans use for thousands of government services, in a DDoS campaign that briefly disrupted everything from passport applications to mobile-money transfers. The ICT secretary at the time, Eliud Owalo, acknowledged the attack but insisted no data had been compromised, the same reassurance offered this week.
A broader assault in 2025 hit dozens of state websites at once, including those of State House and the interior, energy, health and education ministries. Government platforms have become a standing target, with website defacement and ransomware among the most common methods deployed against them.
National figures point the same way. Analysts tracking the country’s systems have logged billions of attempted intrusions over a recent three-month stretch, with Nairobi accounting for the largest share of reported cybercrime, from unauthorised access to identity theft.
Kenya has positioned itself as one of the continent’s leading digital economies, with Nairobi long promoted as East Africa’s tech hub. The government recently approved a National Cybersecurity Agency Order meant to centralise policy and incident response, a framework that a defaced presidential homepage has now put to an early test.
How quickly the site came back, officials will argue, is the measure of whether that investment is paying off. Whether the ransom was ever a serious prospect, or the point was simply to embarrass the president on his own front page, the investigators have not said.
(Source: The Next Web)