Kenya's national cyber response team detected 2.36 billion threat events between April and June 2026, a figure that sounds alarming on its own but actually represents a steep decline from the quarter before. The country's Computer Incident Response Team logged 3.37 billion threats in the prior quarter and 4.56 billion in the one before that, a roughly 48% drop from the year's peak.
Kenyan officials are urging businesses not to read the falling numbers as falling risk. The Communications Authority has stressed that most of what gets counted as a "detected threat event" is automated scanning and vulnerability-probing traffic, not confirmed breaches or financial losses, and that a decline in scanning volume says nothing about whether attackers who do get in are succeeding. Advisories issued to businesses and government bodies actually rose slightly in the same period, to 20.75 million from 20.58 million the quarter before, suggesting the response apparatus stayed just as busy even as raw detection numbers fell.
Some of the more concerning trends sit beneath the headline totals. Security researchers at ESET recorded a 145% jump in QR-code phishing activity between late 2025 and mid-2026, a technique that sidesteps traditional email filtering by moving the malicious link into an image a phone camera has to scan. With Kenya's mobile data subscriber base now at 64.3 million as of June, the shift toward mobile-first, QR-based attacks tracks a digital economy that has moved further onto phones than onto desktops — and that authorities say has not yet built matching mobile-security habits to go with it.

