Visualização normal

Antes de ontemFirewall Daily – The Cyber Express
  • ✇Firewall Daily – The Cyber Express
  • Hackers Deface Kenya President William Ruto’s Website, Demand $330K Ransom Samiksha Jain
    Kenya is investigating a Kenya cyberattack that temporarily defaced President William Ruto’s official website with an anti-government message and a Bitcoin ransom demand for five bitcoins, reportedly worth about $330,000. The attackers replaced the website’s homepage with the message, displayed a cryptocurrency wallet address and threatened to publish unspecified information about President William Ruto unless the ransom was paid. The website was hacked on Saturday, July 18, 2026. Following the
     

Hackers Deface Kenya President William Ruto’s Website, Demand $330K Ransom

Kenya Cyberattack Defaces Ruto Website

Kenya is investigating a Kenya cyberattack that temporarily defaced President William Ruto’s official website with an anti-government message and a Bitcoin ransom demand for five bitcoins, reportedly worth about $330,000. The attackers replaced the website’s homepage with the message, displayed a cryptocurrency wallet address and threatened to publish unspecified information about President William Ruto unless the ransom was paid.

The website was hacked on Saturday, July 18, 2026. Following the incident, access to the presidential website was temporarily restricted as authorities began containment, forensic analysis and restoration efforts. According to local media reports, access to the website was restored by Monday.

Kenya Cyberattack Prompts Incident Response

Kenya’s Ministry of Information, Communications and the Digital Economy confirmed that the official website of the President had been affected by a cybersecurity incident.

The ministry said that after the incident was detected, the ICT Authority immediately activated established cybersecurity incident response protocols.

As a precautionary measure, access to the presidential website was temporarily restricted to facilitate containment, forensic analysis and restoration efforts.

The ministry said appropriate mitigation measures had since been implemented and that restoration of the website was underway.

[caption id="attachment_113245" align="aligncenter" width="600"]Kenya cyberattack Source: Kenya’s Ministry of Information, Communications and the Digital Economy[/caption]

At the time of the statement, the government said there was no evidence of unauthorized access to sensitive data, data exfiltration or loss of information. It also stated that government systems and digital services remained secure and operational.

The ICT Authority is working with relevant government agencies and technical partners to conduct a comprehensive forensic investigation and establish the full circumstances surrounding the incident.

Kenya President William Ruto Cyberattack Investigation

The Kenya President William Ruto cyberattack involved the defacement of the president’s official website. The attackers replaced the homepage with an anti-government message, displayed a cryptocurrency wallet address and demanded five bitcoins.

The attackers also threatened to publish unspecified information about President William Ruto if the ransom was not paid.

The government has not reported evidence of unauthorized access to sensitive data or data exfiltration. The ongoing forensic investigation is expected to establish the circumstances surrounding the incident and determine the extent of the attack.

Kenya Government Website Hack Follows Earlier Incidents

The latest Kenya government website hack follows previous cyber incidents involving government digital services and websites.

In July 2023, Kenya’s eCitizen platform, which is used for dozens of public services, was disrupted by a cyberattack. The incident affected agencies including the National Transport and Safety Authority and Kenya Power.

On November 17, 2025, hackers launched a coordinated attack on several government websites, including the presidency’s portal. The websites were temporarily knocked offline, while some pages were replaced with extremist messages.

According to the information provided by local media, the government later blamed a group calling itself PCP@Kenya, restored the affected platforms and promised stronger cyber defences.

Bitcoin Ransom Demand Targets Presidential Website

The latest incident involved a Bitcoin ransom demand for five bitcoins, reportedly valued at approximately $330,000. The attackers displayed a cryptocurrency wallet address and threatened to release unspecified information about the president.

It remains unclear from the available information whether the attackers accessed systems or data beyond the presidential website. The Kenyan government has said there is currently no evidence of unauthorized access to sensitive data, data exfiltration or loss of information.

The ICT Authority and relevant government agencies are continuing their forensic investigation to establish how the incident occurred and determine the full circumstances surrounding the Kenya cyberattack.

  • ✇Firewall Daily – The Cyber Express
  • Government Website in India Taken Offline After Defacement Attack Ashish Khaitan
    A government website in northern India was taken offline after unidentified hackers allegedly gained unauthorized access and replaced its homepage with pro-Pakistan messages and slogans. The MDA hack targeted the official website of the Meerut Development Authority, a government agency responsible for urban development in the Indian state of Uttar Pradesh. Authorities discovered the breach on Saturday and immediately disabled public access to the website while technical teams worked to contai
     

Government Website in India Taken Offline After Defacement Attack

MDA hack

A government website in northern India was taken offline after unidentified hackers allegedly gained unauthorized access and replaced its homepage with pro-Pakistan messages and slogans. The MDA hack targeted the official website of the Meerut Development Authority, a government agency responsible for urban development in the Indian state of Uttar Pradesh. Authorities discovered the breach on Saturday and immediately disabled public access to the website while technical teams worked to contain the incident and restore services. Instead of the agency's usual information on urban planning, housing, and public services, visitors encountered a black screen displaying objectionable content and political messaging. Instead of the usual information on urban planning and public services, visitors to the government portal were greeted by a black screen displaying objectionable content. 

MDA Hack Forces Website Offline 

Following the discovery of the MDA hack, officials initiated emergency response measures to secure the affected systems and prevent further unauthorized access. The website was placed under maintenance as cybersecurity teams began assessing the extent of the compromise. Authorities are also investigating whether the MDA hack affected any internal systems or data beyond the publicly visible website. The website remains offline while authorities continue working to bring it back online safely. Officials are also assessing the extent of the cyberattack and whether any additional systems or data may have been compromised during the incident. 

Police Register Case After Hackers Deface Website 

Law enforcement agencies have opened an investigation after local officials confirmed that the MDA hack had compromised the government website. Police are working alongside cybersecurity specialists to determine how the attackers gained access, identify the techniques used during the intrusion, and trace those responsible. Investigators are expected to examine server logs and other digital evidence to establish the origin and scope of the cyberattack. Officials have not disclosed whether the MDA hack resulted from an exploited software vulnerability, compromised credentials, or another attack method.

Investigation Underway Into Pro-Pakistan Website Defacement 

Investigators are working to identify the individuals or group responsible for displaying the pro-Pakistan messages on the MDA website. Law enforcement agencies are expected to rely on digital forensic experts to examine server logs, identify the attack methods used by the hackers, and collect evidence that could help establish the origin of the cyberattack.  Officials have not yet disclosed whether the attackers gained access through a technical vulnerability or another method. The investigation is expected to determine the full scope of the breach and recommend measures to prevent similar incidents in the future.

Why the MDA Hack Raises Security Concerns 

The Meerut Development Authority is a statutory body responsible for the planned development of Meerut and the surrounding areas in Uttar Pradesh. Its responsibilities include land acquisition, infrastructure development, housing projects, and urban planning initiatives. As a public-facing government agency, its website serves as an important source of information for residents and stakeholders.  The MDA hack highlights the risks associated with cyberattacks targeting government institutions. Websites operated by public authorities often contain sensitive information and play a critical role in delivering services and official updates. A successful breach not only disrupts these services but can also be used to spread propaganda, as seen in this case with the appearance of pro-Pakistan content on the homepage.  Such incidents can undermine public confidence in government digital platforms and reinforce the need for stronger cybersecurity practices across public institutions. 

Authorities Focus on Strengthening Cybersecurity 

Officials have stated that restoring the website is only one part of the response. Alongside recovery efforts, authorities are reviewing security measures to reinforce the MDA's digital infrastructure against future attacks by hackers.  The investigation is expected to provide insights into the techniques used during the cyberattack and help authorities implement stronger safeguards. The police have assured the public that all necessary steps are being taken to resolve the matter promptly and identify those responsible for the MDA hack. 
❌
❌