Hackers demanding a ransom in Bitcoin seized control of Kenyan President William Ruto’s official website, replaced its homepage with abusive messages and forced the portal offline, prompting an urgent government investigation.
The presidential site, president.go.ke, was compromised on 18 July, with attackers threatening to leak unspecified information unless they received 5 Bitcoin by Saturday evening, according to an initial report on the incident.
Officials say they have so far found no evidence that sensitive government data was accessed or stolen, but the breach has raised fresh questions over the security of Kenya’s digital public infrastructure.
Presidential portal taken offline after breach
Kenya’s Cabinet Secretary for Information, Communications and the Digital Economy, William Kabogo, confirmed that the government’s ICT Authority triggered emergency cybersecurity procedures as soon as the intrusion was detected.
Public access to the presidential website was swiftly cut while technical teams moved to contain the attack and begin a forensic probe.
Kabogo said in a statement:
“At this time, there is no evidence of unauthorized access to sensitive data, data exfiltration, or loss of information. Government systems and digital services remain secure and operational.”
Despite those assurances, the presidential portal remained unavailable as of 13:51 EST on 18 July, the report said. Authorities had not publicly disclosed whether they had made any contact with the attackers or were considering paying the 5 Bitcoin ransom.
The hackers’ messages – which included insults directed at President Ruto – did not publicly identify the group behind the attack or spell out the nature of the information they claimed to hold. No cryptocurrency wallet address was shared in the available material, making it impossible to independently track any payment.
Forensic review and NC4 involvement
State House officials said government specialists were working alongside the National Computer and Cybercrime Coordination Committee (NC4) and external partners to restore the site and determine how the intruders breached its defences.
The investigation is focusing on the technical route used to bypass the portal’s security controls and whether any other connected systems were probed during the incident.
Kabogo stressed that the compromised website is being treated as separate from core government networks and databases, which he again described as “secure and operational”. The forensic review remains ongoing.
The attack comes against a backdrop of mounting cyber pressure on Kenyan state infrastructure. In November 2025, several ministry websites were briefly compromised in a coordinated operation that renewed scrutiny of government cyber defences.
An NC4 assessment recorded billions of cyber threats targeting Kenyan government systems and critical infrastructure in just three months in early 2026. In response, authorities have been working to harmonise cybercrime investigation procedures across the country.
Bitcoin ransom highlights rising crypto-linked attacks
While the demand for payment in Bitcoin placed a cryptocurrency transaction at the centre of the presidential website breach, Kenyan officials have not attributed the case to any known ransomware organisation. It also remains unclear whether the hackers set a firm deadline beyond Saturday evening or provided proof of the alleged data they threatened to release.
The incident comes as governments and regulators worldwide confront a wave of cyber-attacks with digital asset links.
Earlier in July, Airbnb chief executive Brian Chesky said hackers had compromised his X account after it began posting an extended thread about blockchain-based tokenisation of real-world assets. The posts were detailed enough that some readers initially interpreted them as Chesky’s legitimate views.
After the messages were deleted, Chesky admitted the compromise and joked about the surge in attention to his profile. The hijacked account did not promote a token sale or solicit crypto payments, but it illustrated how attackers can exploit a high-profile identity to lend apparent credibility to blockchain-related claims.
Global regulators tighten focus on crypto security
In South Korea, the Financial Supervisory Service has initiated a formal sanctions process against Dunamu, the company behind the Upbit cryptocurrency exchange, following a wallet breach reported in November 2025.
Broadcaster SBS said the regulator had sent Dunamu an inspection opinion letter after examining whether Upbit complied with the Virtual Asset User Protection Act. South Korean media valued the affected assets at 44.5bn won (around $32m), while one earlier estimate put the loss closer to $36m, primarily involving Solana-based holdings.
Upbit said it shifted funds into cold storage, suspended deposits and withdrawals, and began tracing the stolen tokens. The company also pledged to reimburse customer losses from its own resources while officials review both the security lapse and the timing of its disclosure.
At the intergovernmental level, G7 leaders used their June summit in Evian-les-Bains, France, to call for joint action against North Korea’s crypto thefts and wider cybercrime, linking such activity to concerns over Pyongyang’s nuclear and missile ambitions.
Their statement urged closer coordination but stopped short of unveiling new sanctions, exchange obligations or restrictions on crypto mixers. No timetable was set for enforcement measures targeting wallets, platforms or intermediaries suspected of handling stolen digital funds.
Against this global backdrop, Kenya’s probe into the attack on President Ruto’s website underscores how political institutions, financial platforms and technology executives alike are increasingly being targeted in cyber operations with a cryptocurrency dimension.
