Kenya (KE) Threat Intelligence

KE

Kenya has 9,300 malicious IP addresses with 464,978 abuse reports. Top threat categories include suspicious activity, severe abuse, ssh bruteforce, moderate threat, high threat. Top attacking networks: Safaricom Limited (1,650 IPs), Liquid Telecommunications Ltd (1,581 IPs), CKL1-ASN (1,147 IPs). Data collected since 2022-12-10, last activity 2026-07-28.

Threat Assessment: Kenya exhibits moderate cyber threat activity, with a notable number of malicious IPs across multiple attack categories. The dominant attack types are suspicious activity, severe abuse, ssh bruteforce. The majority of threats originate from networks operated by Safaricom Limited and Liquid Telecommunications Ltd.

Total Reports
464,978
Unique IPs
9,300
First Seen
2022-12-10
Last Activity
2026-07-28

Top Threat Categories

Suspicious Activity 5,403
Severe Abuse 1,042
Ssh Bruteforce 597
Moderate Threat 348
High Threat 250

Top Attacking Networks

AS33771 Safaricom Limited
1,650 IPs
AS30844 Liquid Telecommunications Ltd
1,581 IPs
AS36926 CKL1-ASN
1,147 IPs

Most Reported IPs in Kenya

197.248.207.139 539 reports
41.90.100.147 533 reports
197.248.8.33 528 reports
196.207.177.56 513 reports
105.27.148.94 513 reports

Access this data via API

Get Kenya threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/KE

View full API documentation

See how we classify and verify threats →

Check any IP from Kenya

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS33771 Intelligence AS30844 Intelligence AS36926 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...