Kenyan businesses are facing a new cybersecurity problem that does not always begin with encrypted files or locked computer systems.
According to cybersecurity company ESET, several Kenyan victims have paid money in response to what they believed were ransomware attacks even though no genuine ransomware was present.
The finding is contained in ESET’s latest H1 2026 Threat Report, which examines cyber threats recorded between December 2025 and May 2026.
ESET says the situation highlights the need for organizations to verify an alleged ransomware attack before responding to a ransom demand.
Some Victims Paid Before Confirming an Attack
Ransomware normally involves attackers gaining access to a computer system, encrypting files or stealing data and then demanding payment from the victim.
However, ESET’s latest assessment points to cases in Kenya where organizations paid what they believed were ransomware demands despite there being no genuine ransomware attack.
Allan Juma, ESET’s Lead Cyber Security Engineer, said organizations need to understand what ransomware looks like and know how to verify a genuine attack before responding to criminals.
The warning is particularly important because a ransom demand by itself does not prove that an attacker has successfully compromised an organization’s systems.
Why Fake Ransom Demands Can Work
A ransom message can create enormous pressure on a business.
An employee or IT administrator may suddenly receive a message claiming that company files have been stolen or encrypted. The attacker may threaten to publish information or increase the ransom if payment is not made quickly.
For a business that depends heavily on its computer systems, the fear of losing access to important information can make executives feel they have to act immediately.
Cybercriminals can exploit that fear by making claims that sound convincing.
This is why cybersecurity specialists recommend investigation and verification before any ransom payment is considered.
Kenya Is Facing a Wider Cybersecurity Challenge
The ESET warning comes as Kenyan organizations continue to face a broad range of cyber threats.
ESET’s H1 2026 data recorded a 145 percent increase in QR-code phishing, also known as quishing, in Kenya between the second half of 2025 and the first half of 2026. ESET cautioned that the comparison is based on an incomplete baseline and should therefore be treated as a directional indicator rather than an exact measurement.
The company also recorded more than a twofold increase in exploitation attempts against CVE-2017-0199, an old Microsoft Office vulnerability that can allow malicious code to execute when a specially crafted document is opened.
The continued exploitation of a vulnerability first disclosed in 2017 highlights a persistent problem: attackers do not necessarily need sophisticated new techniques when organizations leave known weaknesses unpatched.
Ransomware Attacks Are Still Growing
The warning about fake ransomware demands should not be interpreted to mean that ransomware is no longer a serious threat.
ESET’s global H1 2026 report says ransomware attacks continued to grow during the period covered by the research.
At the same time, the proportion of victims willing to pay ransom reached historically low levels. ESET says several industry reports put the percentage of organizations paying ransom at between 14 percent and 28 percent.
The report also identifies the growing use of tools designed to disable endpoint security software before or during ransomware attacks.
ESET researchers have identified more than 100 tools associated with attempts to disable or interfere with endpoint detection and response systems during ransomware operations.
What Kenyan Businesses Should Do Before Paying
The latest warning highlights an important cybersecurity principle: do not assume that a ransom demand means your systems have been successfully attacked.
Businesses should first establish what has actually happened.
Security teams should check whether files have been encrypted, whether unauthorized access has occurred, whether data has been removed from company systems and whether there are indicators of compromise.
Organizations should also preserve system logs and other evidence rather than immediately deleting affected systems or negotiating with attackers.
Where possible, businesses should involve qualified cybersecurity professionals and follow their incident-response procedures.
Regular offline backups are also important because they can allow an organization to recover its data without depending entirely on the attacker.
Kenya’s National KE-CIRT/CC has similarly urged organizations to maintain robust offline backups, use network segmentation, patch systems promptly and maintain updated threat intelligence as part of ransomware preparedness.
Businesses Should Not Panic
For a company facing a ransom demand, the instinct may be to pay quickly to prevent further damage.
But the latest ESET warning shows why that approach can be risky.
If an organization has not established that ransomware is actually present, paying a criminal may simply transfer money without solving a real security problem.
Even when a genuine ransomware attack has occurred, payment does not guarantee that files will be recovered or that stolen information will not later be released.
The better approach is to investigate first, contain the incident, preserve evidence and determine the extent of the compromise.
The Bigger Lesson for Kenyan Companies
The ransomware warning is part of a wider cybersecurity lesson for Kenyan businesses.
Attackers do not always need advanced malware to make money. Phishing, outdated software, exposed remote-access services and social engineering can all provide opportunities.
ESET’s latest findings suggest that some of the biggest risks facing Kenyan organizations continue to involve basic security weaknesses rather than highly sophisticated attacks.
For businesses, the message is straightforward: verify before you pay, patch before you are attacked and maintain backups before you need them.
As more Kenyan companies move their operations online, cybersecurity is no longer simply an IT department issue. It is becoming a core business responsibility.
And when a ransom note suddenly appears on a company’s screen, the first question should not necessarily be, “How much do they want?”
It should be:
“Did they actually get in?”


