East Africa became one of the continent’s most active cybercrime zones in 2025, according to INTERPOL’s African Cyberthreat Assessment Report 2026. The region’s runaway success with mobile money has created exactly the kind of target criminals want: fast, high volume, and still catching up on security.
From SIM swap fraud in Kenya to a ransomware incident on Uganda’s national power grid, the pattern across the region points to one conclusion. Digital adoption has sprinted ahead of the defenses meant to protect it.
A Region Defined By Two Threats
INTERPOL’s assessment identifies East Africa as a hub for two dominant threats: mobile money fraud and ransomware aimed at critical infrastructure. Unlike Southern Africa, where high value targets draw sophisticated, well resourced attackers, or Central Africa, where underreporting masks the true scale of the problem, East Africa’s exposure comes from something more basic. Millions of people now depend on mobile wallets for daily transactions, and criminals have simply followed the money.
| Country | Key Incident | Impact |
|---|---|---|
| Kenya | 46,786+ DDoS attacks (H1 2025) | Telecom infrastructure disrupted |
| Kenya | SIM swap fraud up 327% | 123,000+ fraudulent SIMs, USD 3.8 million drained |
| Uganda | Suspected ransomware attack on UETCL | National power grid monitoring systems compromised |
| Seychelles | Central bank customer data breach | Exposed even small, high income nations to targeted attacks |
| Ethiopia | Fifth highest vulnerability detections continent wide | Broad exposure to exploitation |
| Tanzania & Rwanda | SIM swap patterns similar to Kenya | Telecom providers struggling with real time biometric verification |
Kenya Sets the Pace, for Better and Worse
Kenya’s numbers dominate the region’s cybercrime statistics, and not in a good way. The country recorded more than 46,786 DDoS attacks in the first half of 2025, most of them aimed at telecom infrastructure, and appeared in SOCRadar’s top phishing detection rankings by September.
Kenya’s Communications Authority separately logged hundreds of millions of intrusion attempts against government and ICT systems between July and September 2025, largely through brute force and system exploitation.
SIM swap fraud tells an even starker story. Fraud linked to hijacked SIM cards jumped 327 percent during the year, with more than 123,000 fraudulent SIMs issued and an estimated USD 3.8 million drained from mobile wallets.
Tanzania and Rwanda reported comparable patterns, suggesting the problem is regional rather than a Kenya specific failure. In each case, telecom providers have struggled to roll out real time biometric verification fast enough to close the gap criminals are exploiting.
Kenya has responded on two fronts. The Kaa Chonjo, Swahili for Don’t Give It, awareness campaign urges the public never to share one time passwords or PINs over calls or messages. Alongside it, Kenya’s Computer Misuse and Cybercrimes Amendment Bill 2024 gives law enforcement clearer legal tools to target SIM swap fraud and scam calls specifically.
Uganda’s Power Grid Becomes a Cautionary Tale
The region’s most alarming incident came from Uganda, where the Electricity Transmission Company Limited experienced a suspected ransomware attack in August 2025 that compromised monitoring systems tied to the national power grid. Backup protocols kept the lights on, but the episode exposed a hard truth: critical infrastructure across the region remains vulnerable to disruption, and incident response coordination has not caught up with the threat.
This was not an isolated case within the broader report. Across Africa, ransomware increasingly targets essential services, from Namibia’s telecom sector to South Africa’s weather service, precisely because disrupting them creates maximum pressure to pay. Uganda’s grid incident shows that East Africa is not exempt from this shift toward infrastructure focused attacks.
Small Nations, Big Exposure
Seychelles offers a reminder that wealth and small population size provide no real protection. The country’s central bank suffered a breach of its customer data, demonstrating that even small, high income nations sit within reach of organized cybercriminal networks. Ethiopia, meanwhile, ranked fifth across the entire continent in vulnerability detections tracked by Shadowserver, evidence that exposure in the region runs deeper than the headline grabbing incidents in Kenya and Uganda.
Legal Reform Is Underway, But Gaps Remain
Kenya and Tanzania have both taken steps toward stronger legal frameworks, with Kenya’s cybercrime amendment bill standing out for directly targeting SIM swaps and scam calls rather than relying on generic provisions. Yet the report is clear that legal reform alone will not close the gap. East Africa still lacks a unified regional mechanism for responding to cybercrime, and that absence lets criminal networks exploit the borders between nations, shifting operations from one jurisdiction to another whenever local authorities close in.
What East Africa’s Experience Signals
Taken together, the picture from East Africa mirrors the broader continental story in INTERPOL’s report: rapid digital adoption without matching investment in security creates an opening that criminals are quick to exploit. Mobile money has genuinely transformed how people in the region save, spend and send money, but the same speed and convenience that made it popular has also made it a target.
Closing that gap will take more than public awareness campaigns. It will require telecom providers to deploy real time biometric verification, governments to harden the infrastructure now in criminal crosshairs, and neighboring countries to build the kind of coordinated response that no single nation can manage alone.


