
Hackers have disabled Kenyan President William Ruto’s official website, replaced its homepage and demanded a ransom of 5 Bitcoin.
Summary
- Hackers defaced Kenyan President William Ruto’s website and demanded a ransom of 5 Bitcoin.
- Kenyan authorities found no evidence that sensitive data was accessed, stolen, or lost.
- State investigators and external partners are examining how attackers breached the website’s security.
According to a report, the Kenyan government opened an investigation after attackers took control of president.go.ke on July 18 and posted insulting messages directed at Ruto. The hackers also threatened to release unspecified information unless officials paid the ransom by Saturday evening.
William Kabogo, cabinet secretary for Kenya’s Ministry of Information, Communications and the Digital Economy, confirmed that the government’s ICT Authority activated its cybersecurity response protocols after detecting the breach. Officials restricted public access to the website while technical teams worked to contain the attack and begin a forensic review.
“At this time, there is no evidence of unauthorized access to sensitive data, data exfiltration, or loss of information. Government systems and digital services remain secure and operational.”
Despite the government’s assurance, the website remained unavailable as of 1:51 p.m. EST on July 18, according to the original report. Officials had not publicly confirmed whether they contacted the attackers or considered paying the requested Bitcoin.
The report also did not identify the hackers, explain how they entered the website, or specify what information they claimed to possess. Bitcoin transactions can be viewed on a public blockchain, but the attackers’ wallet address was not included in the available details, preventing an independent review of any payment activity.
Kenya says sensitive government data remains secure
State House officials confirmed that government technical teams were working with the National Computer and Cybercrime Coordination Committee, known as NC4, and external technical partners. Their review focused on restoring the presidential portal and identifying how the attackers passed its security controls.
Kabogo’s statement separated the compromised public website from Kenya’s other government systems, which he described as secure and operational. Authorities had found no evidence of stolen or lost sensitive information at the time of the update, although the forensic investigation remained active.
July’s incident followed another attack on Kenyan state infrastructure in November 2025. According to the report, the coordinated operation briefly compromised several ministry websites and increased scrutiny of the security protecting the country’s digital public services.
An NC4 report recorded billions of cyber threats against Kenya’s government systems and critical infrastructure during a three-month period earlier in 2026. In response, Kenyan authorities have continued efforts to standardize how cybercrime cases are investigated across the country, according to the report.
The demand for Bitcoin placed a crypto payment at the center of the presidential website breach, but Kenyan officials had not attributed the attack to a known ransomware group. Authorities also had not disclosed whether the ransom message contained a payment deadline beyond Saturday evening or evidence supporting the threatened leak.
Crypto-linked breaches keep regulators on alert
Kenya’s investigation comes as governments and financial regulators examine separate attacks involving crypto platforms, executives and state-backed cyber groups.
Earlier in July, Airbnb CEO Brian Chesky confirmed that hackers had compromised his X account after it published a long thread about blockchain-based real-world asset tokenization. The posts discussed digital ownership and financial markets in enough detail that some observers and publications initially treated them as genuine comments from the Airbnb chief.
After the posts were removed, Chesky acknowledged the compromise and joked about the unexpected audience it brought to his profile. His account did not promote a token sale or request a crypto payment in the material described, but the incident showed how attackers can use a recognized executive’s identity to make blockchain-related claims appear credible.
South Korea’s Financial Supervisory Service has also begun a formal sanctions process against Dunamu, the operator of Upbit, following the exchange’s November 2025 wallet breach. SBS reported that the regulator sent Dunamu an inspection opinion letter after examining whether Upbit met its obligations under the Virtual Asset User Protection Act.
South Korean reports valued the Upbit assets affected by the attack at 44.5 billion won, or roughly $32 million at current exchange rates, while an earlier crypto.news estimate placed the loss near $36 million. The incident involved Solana-based assets held by the exchange.
Upbit stated that it transferred assets to cold wallets, suspended deposits and withdrawals, and began tracing the stolen funds after detecting unusual transfers. The company also promised to cover customer losses with its own money, while authorities reviewed the security failure and the timing of its public disclosure.
At the government level, G7 leaders called for coordinated action against North Korea’s cryptocurrency thefts and cybercrime following their June summit in Evian-les-Bains, France. Their geopolitical statement linked the issue to concerns about Pyongyang’s nuclear and ballistic missile programs.
Although the G7 statement urged member countries to act together, it did not announce new sanctions, crypto exchange requirements or mixer restrictions. The leaders also provided no schedule for enforcement against wallets, platforms or intermediaries suspected of handling stolen funds.





