Kenya’s president’s website was restored on July 18, 2026, after attackers briefly took control of the portal, displayed anti-government messages and posted a Bitcoin ransom demand, the government said. The ICT Ministry confirmed a cybersecurity incident, said access to the site was temporarily restricted for forensic investigations and reported no evidence that sensitive government data was stolen.
## How the breach unfolded
Hours after the defacement, which replaced official content with messages insulting President William Ruto and a visible Bitcoin wallet, authorities regained control of the president’s website. The attackers demanded 5 BTC—about KSh41 million—and threatened to leak unspecified information. Officials have not said whether the intruders accessed other systems beyond the site’s homepage.
## Investigations and official response
Access to the site was limited while forensic teams examined the incident. The ICT Ministry described the event as a cybersecurity incident and maintained that core government systems remained secure. Investigators are working to determine the entry vector and the extent of any compromise.
## Past attacks and the wider context
This is not Kenya’s first high-profile intrusion. In July 2023, a cyberattack disrupted the eCitizen platform and affected agencies including the National Transport and Safety Authority and Kenya Power. On November 17, 2025, a coordinated attack knocked offline several government websites, including the presidency’s portal; the government later blamed a group calling itself PCP@Kenya. Those incidents underscore the risks facing Kenya as it digitises public services.
## Consequences for digital trust and security
Even when a breach is limited to a website defacement, the symbolic targeting of the presidency can erode public confidence and highlight weaknesses that more capable attackers might exploit. Restoring the site is a necessary first step, but authorities and security teams face pressure to strengthen defences across state institutions as more services and records move online.
As investigations continue, the immediate priorities are determining how the attackers gained access, assessing any wider impact, and communicating findings to rebuild trust in the country’s digital infrastructure.

