Hackers target government logins as web attacks hit 17.4 million

Hackers intensified attempts to break into government and internet service provider systems in the three months to June 2026, with web application attacks jumping 43.7 percent to 17.4 million as criminals increasingly targeted user credentials and sensitive databases.

Web application attacks are malicious attempts to exploit vulnerabilities in internet-facing software, such as websites, to access sensitive data, disrupt operations, or compromise backend systems.

New official data shows that government systems and internet service providers accounted for the biggest share of the attacks as hackers sought access to authentication credentials, vulnerable web browsers and database servers.

The trend signals a shift towards attacks targeting online services that store sensitive information. Previously, attackers mainly sought to disrupt websites and digital platforms.

“Government systems and Internet Service Providers (ISPs) constituted the primary targets, with threat actors prioritising the compromise of user authentication credentials, vulnerable web browsers and database servers,” said the Communications Authority of Kenya (CA).

“These attacks exploited vulnerabilities such as unauthenticated remote code execution, privilege escalation, and reflected cross-site scripting to gain unauthorised access, elevate permissions and expose sensitive information, leading to data breaches and reputational damage to the affected organisation.”

Once attackers gain entry, they can steal usernames, passwords, financial records and personal information or use compromised systems to launch further attacks.

Successful compromises can expose millions of customer records while disrupting essential services relied upon by businesses and households.

The findings highlight growing risks facing Kenya as government services, banking, telecommunications and commerce become increasingly dependent on internet-based platforms.

The government has accelerated digital service delivery through online platforms handling tax payments, business registration, licensing, immigration services and other public transactions.

Private businesses have, similarly, expanded digital operations as customers increasingly shift towards online shopping and mobile-based service delivery.

The expanding digital economy has significantly increased the number of internet-facing applications requiring continuous monitoring and timely security updates.

Cyber criminals usually target web applications because they often provide direct pathways into databases containing valuable financial and personal information.

Unlike traditional malware campaigns, web application attacks frequently exploit software vulnerabilities rather than relying on users downloading malicious files.

The latest findings suggest that attackers are becoming more sophisticated by identifying weaknesses within applications instead of indiscriminately attacking network infrastructure.

The CA has advised affected organisations to upgrade end-of-life software products, as well as apply available security patches immediately.

Failure to install software updates leaves organisations exposed to vulnerabilities that have often already been publicly documented and weaponised by attackers.

The report indicates that many attacks targeted systems running outdated software or insecure configurations despite available vendor security fixes.

Cyber security experts have, over the years, recommended remedies such as multi-factor authentication, regular vulnerability assessments, as well as continuous system monitoring to reduce exposure to credential theft.

Businesses have also been encouraged to strengthen application security throughout software development rather than relying solely on perimeter network defences.

Leave a Reply

Your email address will not be published. Required fields are marked *