State agencies bosses face disciplinary action over Sh4 billion cyber attacks
National
By
Josphat Thiongó
| Aug 02, 2026
Chief Executive Officers of State Corporations are now facing disciplinary action over failure to secure government systems even as it emerged that national digital systems suffered approximately 4 billion cyber-attacks in a period of two years.
The Sunday Standard has established that the cyber-attacks took place between the year 2022 and 2025 with the latest being a State House website attack last month.
The hack on the State House website saw the homepage defaced and replaced by messages targeting President William Ruto. The hackers demanded a ransom in Bitcoin equivalent to approximately Sh41 million.
Correspondence seen by The Standard reveals that heads of government agencies are on the spot for the failure or delay to implement government websites' domain and email protection measures in collaboration with the Communications Authority of Kenya.
READ MORE
Kenya's infrastructure boom faces costly maintenance crisis
Vision 2060: Can Ruto build Kenya's future amid a trail of failed projects?
Shahbal secures Sh12 Billion DP World SEZ deal
Safaricom halves M-Pesa merchant fees in CBK-led move
Strain on households mounts as inflation holds stubbornly above 6pc
Safaricom shareholders back changes as State cedes control
Kirubi family tops Sh521m Centum dividend windfall
Safaricom, EABL spark corporate bonds frenzy
AGOK: Betting industry pays more tax than it gets credit for
They have now been issued with show-cause letters demanding that they explain their failure to adhere to a 2025 circular from the Head of Public Service Felix Koskei, on the implementation of domain and email protection across government ministries, departments, agencies and state corporations.
Those on the hook include the Kenya Revenue Authority (KRA) Commissioner General Aden Abdalla Mohammed, Kenya Urban Roads Authority (KURA) CEO Silas Murira, Rural Electrification and Renewable Energy corporation (REREC) CEO Rose Mkalama, Information and Communication Technology Authority CEO Jessy Maruti, Kenya National Bureau of Statistics CEO George Obudho and Kenya National Examinations Council CEO Kabita Njengere.
Others include National Intelligence and Research University acting CEO James Kibon, National Government Constituency Development Fund(NGCDF) acting CEO Benjamin Magut, Nuclear Power and Energy Agency CEO Justus Ambutsi, National Youth Service CEO James Kipsiele, Kenya Space Agency CEO Brigadier Hillary Kipkosgei, National Transport and Safety Authority (NTSA) CEO Nashon Kondiwa , Kenya Medical Practitioners and Dentists Council CEO David Gicheru and Kenyatta National Hospital acting CEO Richard Lesiyampe among others.
“...As you are aware, recent times have proved that the Government information asset continues to be a key target of cyber criminality. It is therefore imperative that all efforts and skills are employed to enhance cyber resilience. Unfortunately, despite the Government policy intervention on this front and the reiteration of the need for its implementation, your institution has failed to commence any action towards compliance. This is deemed to be an infraction that calls for severe deterrent measures against yourself as the Agency’s Chief Executive Officer and the Board of Directors,” reads a 28th July 2026 letter from the Executive office of the President and copied to all state agencies.
“Accordingly, it has been decided that you show cause why deterrent measures should not be meted against yourself, and the board membership for blatant dereliction of responsibility by failing to implement a Government policy directive. Your representations if any should reach this office by no later than 14th August,2026,” it adds.
The initial policy directive was issued on January 13,2025 and required Government Ministries, Departments, Agencies and State Corporations to adopt a whole-of-government approach to the implementation of domain and Email protection.
Through a letter addressed to all Principal Secretaries and CEO’s of State corporations, Head of Public Service Kosgey noted that there had been an increase in the frequency and sophistication of cyber attacks leveraging Internet domain names and online platforms. He highlighted that Phishing, ransomware, domain name system attacks, and advanced persistent threats posed significant risks not only to the country but globally.
Kosgey stated that the attacks had led to data breaches, financial losses, and service disruption.
“This certainly poses a great risk to the successful implementation of the government's National Digital Transformation Agenda, and therefore threatens the benefits the public is bound to derive from the adoption of digital technologies in the delivery of public services,” stated the Head of Public Service.
The document also revealed that during the fiscal year ending 30th June 2024, over 3.5 billion cyber threat incidents against Kenyan government digital systems were detected in the country. The incidents had increased from 855 million in the previous 2022/23 fiscal year.
It further detailed that between April and June 2024, nearly 1.1 billion cyber threat incidents were detected, compared to 139 million over the same period in the 2022/23 fiscal year.
“This surge is largely attributed to insecure domain names and misconfigured online systems given that cyber threat actors are increasingly leveraging on the exploitation of domain name and email vulnerabilities in staging cyber attacks,” added the letter.
Kosgey also brought to the fore that a number of government agencies had also fallen victim to ransomware attacks in 2024, in a trend which was also observed globally. He also went ahead to issue intervention strategies to address the threat of domain name propagated attacks.
“Accordingly, all Ministries, Departments, Agencies and State Corporations are directed to adopt and use dot KE domain names only, and further ensure that the security and reliability of any dot KE domain names in use is safeguarded through the deployment of domain and email protection measures in collaboration with the Communications Authority of Kenya,” he directed.
“All Accounting Officers are directed to ensure adherence and compliance with the dictates of this Circular within six (6) months from the date hereof.”
The efforts, Kosgey noted, were aimed at fostering public trust in the legitimacy of government domain names and online public services, enhance national security through protection of government data, enable the government to comply with both local and international cyber security regulations and prevent loss of public funds through cyber-criminal activity.
“In that regard, and in order to protect Kenya's digital assets, enhance domain and email security and therefore advance the National Digital Transformation Agenda and digital sovereignty, it is hereby notified that the Communications Authority of Kenya has been designated as the centralized government entity responsible for domain and email protection across Ministries, Departments, Agencies and State Corporations,” added the letter.
Subsequent correspondence reveals that by 11th November, the directive was yet to be fully implemented and the Chief of Staff granted the agencies an additional three months to ensure full compliance. This meant that full compliance was to be achieved by 10th February 2026.
He also directed the Communications Authority to engage all agencies on the implementation of Domain and Email protection framework to ensure a coordinated and efficient execution of the directive. The Authority was also required to give monthly compliance status reports detailing the progress achieved.
However, a letter dated 26th January, 2026 revealed that with less than 15 days to the compliance deadline, less than 50 state corporations had complied. To fast track its implementation, the State Corporations Committee domiciled in the Executive office of the President directed that each state corporation was required to nominate two officers, one of whom was required to be a Head of ICT to serve as project focal point.
The State House Website hack on July 18 seemingly prompted the July 28,2026 letter where the CEO’s were required to show cause over their failure to ensure full compliance of the directive.
As of 30th June 2026, however, the government noted that various institutions' level of compliance fell below 60 percent. This was revealed through another letter from Kosgey also dated July 28.
To ensure full compliance, the Chief of Staff has now issued a 30-day period extension to agencies that are yet to fully implement the directive.
“Since you have commenced some compliance initiatives, you are hereby granted an opportunity of thirty (30) days from the date of this circular letter to realize full compliance. Should this not be made good by then, further measures as contemplated, shall proceed forthwith against yourself and Board of Directors in terms of section 7 of the State Corporations Act,” the letter adds.