Kenya’s National Kenya Computer Incident Response Team Coordination Centre (KE-CIRT/CC) detected 2.36 billion cyber threat events between April and June 2026, down 30% from the previous quarter and nearly half the level recorded two quarters earlier.
The latest figures from the Communications Authority of Kenya (CA) show detected cyber threats falling from 4.56 billion in the quarter ended December 2025 to 3.37 billion in the quarter ended March 2026, before dropping further to 2.36 billion in the April-June quarter. The Q4 figure represents a 30.03% decline from Q3 and a 48.3% reduction from Q2.
The decline does not mean Kenyan users experienced 30% fewer successful cyberattacks. CA’s measure covers cyber threat activity detected by the national monitoring and response infrastructure, and the Authority’s previous reports show that the total includes large volumes of automated attempts against connected systems. The scale therefore provides an indication of activity being observed across Kenya’s cyberspace rather than a count of confirmed breaches, victims or criminal cases.
The latest figures also show a different pattern in the number of cybersecurity advisories issued by KE-CIRT/CC. Advisories increased slightly to 20.75 million in Q4 from 20.58 million in Q3, after falling from 21.82 million in Q2.
That leaves Kenya with fewer detected threat events but almost the same volume of technical advisories. The difference is significant because the two measures capture different parts of the country’s cybersecurity response. Threat detections indicate activity observed by the national monitoring system, while advisories are part of the response and warning process used to alert organisations and other stakeholders to risks and recommended protections.
The composition of the threat data also matters. In the quarter ended March, system attacks and vulnerabilities accounted for the overwhelming majority of detected activity, with more than 3.2 billion events falling into that broad category. Malware, brute-force attacks, web application attacks and distributed denial-of-service activity represented much smaller portions of the total.
That pattern helps explain why the headline number should not be treated as a direct measure of successful cybercrime. Automated scanning, attempts to exploit vulnerabilities and other machine-generated activity can produce very large detection volumes without each event resulting in a compromised device, stolen data or financial loss.
Kenya’s wider digital economy continues to give attackers a large connected environment to probe. By June, the country had 64.3 million mobile data subscriptions, 54.9 million mobile broadband subscriptions and 52.3 million smartphones, according to the same CA sector statistics report. Government services, financial platforms, telecommunications networks and online businesses are also increasingly dependent on interconnected digital infrastructure.
Recent security research provides another reason to avoid interpreting the CA decline as evidence that specific forms of cybercrime are easing. ESET reported a 145% increase in QR-code phishing activity in Kenya between the second half of 2025 and the first half of 2026, while TechTrendsKE’s reporting on the threat highlighted continued exploitation of older software vulnerabilities and poorly secured systems.
The two sets of figures are not directly comparable. CA’s national monitoring data covers detected threat events across its monitoring environment, while vendor telemetry measures activity observed through that vendor’s own security infrastructure. A decline in one measurement can therefore occur alongside an increase in a particular attack technique measured through another system.
For organisations, the latest CA figures point to a cybersecurity environment where the volume of automated threat activity can change substantially from one quarter to another without removing the underlying exposure. The continued issuance of more than 20 million advisories in Q4 also shows that the national response system remains active even as the number of detected events falls.
The next question is therefore less about whether Kenya’s cyber threat problem has disappeared and more about what drove the sustained decline in detected events. CA’s quarterly data establishes the movement clearly, but the headline totals alone do not identify whether changes in attack activity, monitoring coverage, threat composition or other factors account for the reduction.
For now, the clearest finding from the April-June data is that Kenya’s cyber threat detection count has fallen for a second consecutive quarter, while the volume of cybersecurity advisories has remained broadly stable.
Real ESG impact doesn’t happen in panels alone, it happens in the rooms where financiers, operators, and policymakers actually align. Our GreenShift Forum 2026 cuts the noise, bringing together the people rewiring Africa’s sustainability and energy frameworks for one focused day in Nairobi. Secure your seat.
Go to TECHTRENDSKE.co.ke for more tech and business news from the African continent and across the world.
Follow us on WhatsApp, Telegram, Twitter, and Facebook, or subscribe to our weekly newsletter to ensure you don’t miss out on any future updates. Send tips to info@techtrendsmedia.co.ke





