SYS::ONLINE
Wasteland.
Briefs1634
Issues21
SinceFeb 2026
LIVE
▣ Breach M-TIBA-KENYA 2026-07-31

M-Tiba: Kazu Claims 17 Million Patient Records Exfiltrated

"The cybercrime syndicate Kazu is advertising what it says is a 2.15-terabyte trove of patient data lifted from M-Tiba, the mobile health wallet operated by Kenyan firm CarePay, and samples of that data are now…"

The cybercrime syndicate Kazu is advertising what it says is a 2.15-terabyte trove of patient data lifted from M-Tiba, the mobile health wallet operated by Kenyan firm CarePay, and samples of that data are now circulating on dark web forums and Telegram. No primary-tier confirmation exists in the available reporting: neither CarePay, the Office of the Data Protection Commissioner (ODPC), nor Kenya's National Computer and Cybercrime Coordination Committee has published a public statement in the sources reviewed here. What is available comes from secondary coverage, and it does not agree on scale. Streamline puts the actor's claim at 17,158,105 files affecting an estimated 4.8 million individuals and dependents. The Africa Cyber Defense Forum (ACDF) cites the same 2.15TB and 17 million file figures and the same 4.8 million user estimate, but headlines its own brief "Five Million Records Exposed." Readers should treat the 17 million figure as a file count claimed by the attackers, not a verified count of distinct patients.

What Happened

According to ACDF, the intrusion ran from 17 to 25 October 2025 and was not noticed by CarePay until 27 October, roughly ten days after it began. ACDF reports the attackers did not breach M-Tiba directly but entered through a compromised device belonging to a third-party healthcare provider, using stolen credentials to reach claims and clinical systems covering approximately 700 health facilities.

Kazu subsequently listed the dataset on a dark web forum and, per Streamline, published a 2-gigabyte sample on its Telegram channel to substantiate extortion demands. Streamline reports that cybersecurity researchers who reviewed that sample assessed the structured data as authentic. That assessment is attributed to unnamed researchers by a single source and has not been independently corroborated in the material available.

ACDF further reports that CarePay's own internal report to partner insurers, including Jubilee, Fidelity, GA and AAR, later confirmed "almost identical numbers" to the actor's claims. That internal document has not been published, so its contents cannot be verified here.

Accounts differ on timing framing as well. Streamline dates the disclosure to "late 2025" without a precise incident window; ACDF supplies the October 2025 dates. Where the two conflict, ACDF's account is the more specific and internally consistent, but neither is a primary source.

What Was Taken

The data types described across both accounts are consistent and severe. Streamline and ACDF both list full names, national ID numbers, dates of birth, specific patient diagnoses, insurance claims data and billing records. ACDF adds clinical records drawn from roughly 700 facilities.

On volume, the figures reported are:

The gap between 17 million files and 4.8 million people is the crux. A single patient generates many files across visits, claims and lab results, so a file count is not a headcount. Any downstream reporting that treats 17 million as a victim tally is inflating the incident.

This is diagnosis-level data tied to national ID numbers. Unlike a credential dump, it cannot be rotated or reissued. A leaked HIV status, oncology record or psychiatric history stays leaked permanently, and a Kenyan national ID number is a durable key for insurance fraud, SIM-swap attempts and identity takeover.

The Notification Failure

The most operationally damning claim in the reporting concerns disclosure rather than intrusion. ACDF reports that CarePay's partner insurers say they learned of the breach from media coverage rather than from CarePay, and that the Data Protection Commissioner says the same. Kenya's Data Protection Act, 2019 sets an expectation of notification within 72 hours of identifying a qualifying breach, as PrivacyNeedle's compliance guidance restates.

If ACDF's account holds, that is two stacked failures: ten days to detect, then a notification path that reportedly ran through journalists instead of through the regulator and downstream data controllers. ACDF also notes that CarePay had received ISO/IEC 27001 certification for its information security management system roughly two months before the intrusion, a reminder that certification evidences a documented framework, not a working detection capability.

For its part, M-Tiba's public communications channel in mid-2026 has been focused on industry positioning rather than the incident. The company's most recent public post covers an AI challenge at InsurTech Forum Nairobi and, notably, an executive's remarks on auditability and trust in insurance decisioning. The absence of a public breach statement in that channel is itself a data point for anyone assessing the company's disclosure posture.

Why It Matters

The ODPC has been visibly sharpening enforcement in exactly this sector. In Complaint No. 2125 of 2025, Data Commissioner Immaculate Kassait ordered St Luke Orthopaedic and Trauma Hospital in Eldoret to pay KSh525,000 after the facility repeatedly released one patient's test results to another and shared her information with an external laboratory without explicit consent, per Noah Intelligence. The regulator found the hospital lacked adequate technical and organisational safeguards and that sensitive personal data warrants the highest protection. Separately, Leaked reports the ODPC found NCBA Bank liable in matters involving unauthorised disclosure of customer data, including transaction information repeatedly sent to a wrong email address despite attempts to flag the error.

Those are single-complainant cases producing six-figure shilling penalties. An incident touching millions of health records, if substantiated and if the notification failures are confirmed, sits in a different tier entirely.

The national context compounds it. ITWeb Africa reports that on 18 July 2026 attackers defaced president.go.ke, replacing the homepage with messages targeting President William Ruto and demanding 5 Bitcoin, around $320,000, alongside a threat to leak data. Reuters reported the Ministry of Information, Communications and the Digital Economy said the ICT Authority detected the incident, restricted access to contain it, and found no evidence of unauthorised access, exfiltration or data loss, per Cabinet Secretary William Kabogo Gitau. ITWeb notes this was the third major public-sector cyber incident in three years, after the 2023 Anonymous Sudan DDoS against eCitizen that affected more than 5,000 services and coordinated ministry website defacements in November 2025. The presidency defacement is a separate incident from the M-Tiba breach and should not be conflated with it, but together they describe a digitisation programme outpacing its security investment.

The Attack Technique

Per ACDF, the initial access vector was a compromised endpoint at a third-party healthcare provider combined with stolen credentials, giving the attackers a legitimate-looking path into M-Tiba's environment rather than a direct assault on CarePay's perimeter. This is the standard supply-chain pattern for health platforms: the aggregator hardens its own front door while hundreds of connected clinics operate with thin endpoint controls and shared logins.

The eight-day dwell time with 2.15TB reportedly moving out points to gaps in egress monitoring and data loss prevention rather than a novel exploit. Streamline argues the volume implies prolonged undetected presence and raises questions about at-rest encryption for medical databases, though that is inference from the claimed dataset size rather than confirmed forensic finding. No malware family, ransomware strain or infrastructure indicators have been published in the available sources, and Kazu's own attribution rests on its forum and Telegram postings.

What Organizations Should Do

  1. Treat partner and provider endpoints as in-scope attack surface. Enforce phishing-resistant MFA on every third-party integration account, scope provider credentials to the minimum records they need, and set short session lifetimes. A clinic laptop should not be able to authenticate to a national claims database and pull hundreds of facilities' worth of records.
  2. Instrument for volume, not just intrusion. Alert on anomalous bulk reads and outbound transfer thresholds per account. A control that fires at gigabytes exfiltrated is the difference between an incident and a national one, and it would have compressed a ten-day window into hours.
  3. Rehearse the 72-hour clock as an operational drill, not a policy document. PrivacyNeedle's framework is sound: contain and reset privileged credentials in hours 0 to 12, scope the exposed data categories in hours 12 to 48, then notify. Pre-draft regulator and partner notification templates now, and name the person who sends them.
  4. Notify downstream controllers directly and first. If partner insurers and the ODPC learn of your breach from a news cycle, you have converted a security failure into a regulatory and contractual one. Maintain a current contact roster for every data-sharing partner and treat it as an on-call artifact.
  5. Do not mistake certification for detection. An ISO/IEC 27001 audit two months before an eight-day undetected exfiltration is a case study in the difference. Validate controls with purple-team exercises that specifically test bulk-read and egress alerting.
  6. For health data specifically, encrypt at rest with segmented key management and tokenise national ID numbers away from clinical records. The goal is that a single compromised database dump does not yield a joinable identity-plus-diagnosis profile.
  7. Monitor dark web forums and Telegram for your own data. Kazu's sample-release model means there is usually a window between the listing and broad redistribution. Use it to warn affected individuals about targeted medical insurance fraud and ID-based social engineering.

Sources: Hunting Kenya’s 17 Million Stolen M-Tiba Records Streamline | Breach Brief Ten Days Undetected, Five Million Records Exposed Afr... | Kenyan hospital ordered to pay over data breach involving patient r... | What the 2026 Execution Advantage AI Challenge at InsurTech Forum N... | Kenya investigating cybersecurity incident affecting president’s we... | Presidency hack raises Kenya security concerns ITWeb Africa | Data Breach: What Kenyan Companies Should Do (72 Hours) | Data regulator indicts NCBA over failure to protect confidential cu...