On July 18, 2026, the official website of Kenyan President William Ruto (president.go.ke) was defaced by hackers who left a ransom demand of 5 Bitcoin (BTC). The attackers replaced the homepage with threats and a Bitcoin wallet address, giving a deadline of 6 p.m. local time before they would release unspecified information. State House confirmed the breach and immediately took the site offline while its ICT team, together with the National Kenya Computer Incident Response Team, launched an investigation.
The defaced page described the demand as a final warning. While some original website elements remained visible, authorities are still determining whether the intrusion was limited to the public-facing front-end or if internal systems and databases were compromised. Investigators are reviewing authentication records, server logs, and infrastructure to establish the attack method and assess any data leaks.
The incident follows a wave of coordinated cyberattacks on multiple Kenyan government websites in November 2025 that disrupted services across several ministries. This latest breach has intensified calls for stronger cybersecurity measures, including regular security audits, enhanced authentication, staff training, and independent vulnerability assessments. The attackers’ use of Bitcoin again highlights how cryptocurrency is exploited in extortion campaigns due to its borderless transferability and perceived transaction privacy.