Kenyan Government Sites Restored After Hacking

A hacker in a hoodie and gloves types on a laptop, symbolizing the cyberattack on Kenyan government websites

Several high-profile Kenyan government websites, including the Ministries of ICT, Energy, and Tourism, are back online after suffering a cyberattack earlier today, 11/17/2025.

Briefly, the affected sites displayed a defacement message with extremist phrases, such as “Heil Hitler.” Government technical teams subsequently restored the sites.

The Incident Details ( The “How and “When)

The attack was first observed around 10:00 am EAT and compromised several key government and public-facing entities. 

Those affected included the websites for the State House, Nairobi County, the Immigration Department, the Directorate of Criminal Investigations (DCI), and the Government Press, along with crucial ministries such as Agriculture and MITI, and the Hustler Fund.

The compromised pages displayed a terminal-style message, which 

Screenshot of the defacement message from the Kenyan government website hack, showing a terminal with the extremist text "White power world wide!
Image: Kenyans.co.ke

The swift recovery, implemented at approximately 1:30 PM EAT, points toward the possibility of a superficial defacement. However, the complete scope of the breach remains undetermined.

We are still awaiting an official statement from government officials, though a report is anticipated soon. Not all ministries were affected; for instance, the Ministry of Treasury was reportedly unharmed. Furthermore, other government websites, such as the Kenya National Examination Council and NTSA, were not compromised.

The Big Question (“Why and “What”)

Despite the websites being back online, critical questions surrounding the attack persist. Responsibility has not yet been claimed by any group, and a key unknown is whether the incident was limited to a simple defacement or if the perpetrators managed to penetrate deeper into government servers or access sensitive citizen information.

The ICT Authority and the National KE-CIRT (Kenya Computer Incident Response Team) have yet to issue an official statement. This statement is expected to detail the nature of the breach and the measures being implemented to secure the affected platforms.

Context & Conclusion (The Broader Picture)

This incident underscores the continuous security challenges facing Kenya's digital infrastructure. It follows notable past events, such as the significant DDoS attacks against the e-Citizen platform in 2023. 

Consequently, as the government advances its digital transformation efforts, safeguarding these vital assets remains a critical and persistent necessity.

The Communications Authority of Kenya's recent cyber report indicates a sharp surge in cyber threats. Specifically, the first quarter, covering October to December 2024, saw the detection of over 840 million threat events. This figure represents a significant 27.82% jump compared to the previous quarter.