
Kenya’s official presidential website is back online after a reported cyberattack forced the platform offline for several hours. The restoration of president.go.ke follows an incident in which attackers allegedly defaced the homepage, demanded a cryptocurrency ransom and threatened to release unspecified information.
Government officials have said there is no evidence that data was stolen, but the episode has left important questions unanswered about how the attackers gained access and whether the breach was limited to the public-facing website or reached deeper into supporting systems.
A check of the official presidential website on Sunday confirmed that the platform had resumed normal operation after being unavailable following the reported attack.
The restored website appears to have retained its previous content and structure, with access returning to presidential speeches, press releases, official engagements and information about the Presidency.
The disruption began after attackers allegedly replaced the homepage with unauthorised content directed at President William Ruto. They also demanded payment of five Bitcoin and warned they would release unspecified information if the ransom was not paid.
Following the compromise, the State House ICT team took the website offline while restoration work was underway.
Cabinet Secretary for Information, Communications and the Digital Economy William Kabogo said there was no evidence that data had been exfiltrated during the incident.
That statement offers an initial assessment of the attack but does not establish that no information was accessed. Digital forensic investigations often continue after affected systems have been restored, with investigators examining server logs, authentication records and other evidence before determining the full scope of an incident.
As of publication, neither the Presidency nor the ICT Authority had released a technical report explaining how attackers gained access to the website or whether additional security measures had been implemented following the restoration.
The restoration of the website does not answer several important technical questions.
Officials have not disclosed whether the attackers exploited a software vulnerability, obtained administrator credentials or used another method to alter the website.
It is also unclear whether the incident was limited to the website’s front end or whether investigators examined connected systems for signs of unauthorised access.
Equally important is whether the attackers’ claim of possessing additional information has any factual basis. At present, there is no public evidence supporting that assertion, and government officials have not confirmed that any sensitive information was compromised.
Until forensic investigations are completed, the available evidence supports only one confirmed outcome: the public website was altered without authorisation before being taken offline and restored.
The President’s official website serves as the primary online platform for presidential communication. It publishes executive announcements, speeches, policy updates, Cabinet information and records of official engagements.
Because of its role, any compromise attracts attention beyond the technical community. Public confidence in government digital services depends not only on restoring affected platforms but also on understanding how incidents occurred and addressing the underlying weaknesses that allowed them to happen.
Cybersecurity specialists generally recommend that organisations responding to website compromises conduct comprehensive forensic analysis, rotate administrative credentials, review system logs and assess whether vulnerabilities exist elsewhere in their digital infrastructure before closing an investigation.
For now, the restoration of president.go.ke marks an important operational milestone, but several aspects of the incident remain unresolved. A detailed technical report from the relevant authorities would provide greater clarity on the nature of the attack, the effectiveness of the response and whether additional safeguards have been introduced to reduce the risk of similar incidents in future.
Download the free Kaspersky SMB Cybersecurity Guide here to learn how businesses can move beyond traditional antivirus and build a more resilient approach to cybersecurity.




