{"id":6532,"date":"2025-10-29T18:57:47","date_gmt":"2025-10-29T18:57:47","guid":{"rendered":"https:\/\/regtechafrica.com\/healthcare\/?p=6532"},"modified":"2025-10-29T18:57:47","modified_gmt":"2025-10-29T18:57:47","slug":"kenya-m-tiba-data-breach-sparks-major-cybersecurity-concerns-in-kenyas-health-sector","status":"publish","type":"post","link":"https:\/\/regtechafrica.com\/healthcare\/kenya-m-tiba-data-breach-sparks-major-cybersecurity-concerns-in-kenyas-health-sector\/","title":{"rendered":"Kenya: M-Tiba Data Breach Sparks Major Cybersecurity Concerns in Kenya\u2019s Health Sector"},"content":{"rendered":"<p data-start=\"94\" data-end=\"510\">Kenya\u2019s digital health ecosystem has been rocked by a suspected <strong data-start=\"170\" data-end=\"193\">massive data breach<\/strong> targeting <strong data-start=\"204\" data-end=\"214\">M-Tiba<\/strong>, the country\u2019s leading mobile health wallet backed by <strong data-start=\"269\" data-end=\"282\">Safaricom<\/strong>, <strong data-start=\"284\" data-end=\"295\">CarePay<\/strong>, and the <strong data-start=\"305\" data-end=\"331\">PharmAccess Foundation<\/strong>. Hackers have allegedly accessed and leaked millions of sensitive medical and personal records \u2014 in what could become <strong data-start=\"450\" data-end=\"507\">the largest cyberattack in Kenya\u2019s healthcare history<\/strong>.<\/p>\n<p data-start=\"512\" data-end=\"876\">A cybercriminal group identifying itself as <strong data-start=\"556\" data-end=\"566\">\u201cKazu\u201d<\/strong> has claimed responsibility for the breach, asserting that it infiltrated M-Tiba\u2019s servers and extracted approximately <strong data-start=\"685\" data-end=\"711\">2.15 terabytes of data<\/strong>, including <strong data-start=\"723\" data-end=\"748\">over 17 million files<\/strong>. The group has reportedly released a <strong data-start=\"786\" data-end=\"800\">2GB sample<\/strong> of the stolen data on Telegram through a channel named <strong data-start=\"856\" data-end=\"874\">\u201cKazu Breach.\u201d<\/strong><\/p>\n<p data-start=\"878\" data-end=\"1325\">Preliminary examinations of the leaked files indicate exposure of <strong data-start=\"944\" data-end=\"1053\">patients\u2019 names, national ID numbers, phone numbers, birth dates, medical diagnoses, and billing records.<\/strong> Early estimates suggest that personal information belonging to at least <strong data-start=\"1126\" data-end=\"1143\">114,000 users<\/strong> \u2014 including dependents \u2014 has already been compromised. However, Kazu claims the total number of affected individuals could reach <strong data-start=\"1273\" data-end=\"1288\">4.8 million<\/strong>, a figure that remains unverified.<\/p>\n<p data-start=\"1327\" data-end=\"1468\">When contacted, <strong data-start=\"1343\" data-end=\"1354\">CarePay<\/strong>, which operates M-Tiba, did not confirm or deny the claims but acknowledged that an internal probe is underway.<\/p>\n<blockquote data-start=\"1469\" data-end=\"1748\">\n<p data-start=\"1471\" data-end=\"1748\">\u201cAt M-TIBA, we take all matters of data security with the utmost seriousness. As part of our standard protocol, we are actively investigating the claims you are referring to,\u201d a CarePay spokesperson said in an email response, requesting further details to assist the inquiry.<\/p>\n<\/blockquote>\n<p data-start=\"1750\" data-end=\"2081\">If authenticated, the leaked data could also implicate <strong data-start=\"1805\" data-end=\"1841\">nearly 700 healthcare facilities<\/strong>, exposing doctors\u2019 names, handwritten medical notes, insurance details, and complete payment records. Analysts warn that the breach could endanger not only patients but also hospitals and insurers connected to M-Tiba\u2019s extensive network.<\/p>\n<p data-start=\"2083\" data-end=\"2521\">The <strong data-start=\"2087\" data-end=\"2140\">Office of the Data Protection Commissioner (ODPC)<\/strong> confirmed awareness of the incident but refrained from commenting further, citing ongoing investigations. Under <strong data-start=\"2253\" data-end=\"2292\">Kenya\u2019s Data Protection Act of 2019<\/strong>, medical information is classified as <strong data-start=\"2331\" data-end=\"2358\">sensitive personal data<\/strong>, requiring strict confidentiality and protection. A confirmed breach on this scale could trigger <strong data-start=\"2456\" data-end=\"2518\">regulatory sanctions, lawsuits, and international scrutiny<\/strong>.<\/p>\n<p data-start=\"2523\" data-end=\"2960\">Cybersecurity experts say the attack underscores Kenya\u2019s growing exposure to digital risks as the country accelerates its shift toward online platforms. The <strong data-start=\"2680\" data-end=\"2722\">Communications Authority of Kenya (CA)<\/strong> reported <strong data-start=\"2732\" data-end=\"2767\">4.6 billion cyber threat events<\/strong>between April and June 2025 \u2014 an <strong data-start=\"2801\" data-end=\"2814\">80% surge<\/strong> from the previous quarter. Financial institutions, telecommunications operators, and public sector systems remain the most frequently targeted.<\/p>\n<p data-start=\"2962\" data-end=\"3370\">Launched in <strong data-start=\"2974\" data-end=\"2982\">2016<\/strong>, M-Tiba has become a cornerstone of Kenya\u2019s digital health infrastructure, enabling users to <strong data-start=\"3076\" data-end=\"3119\">save, pay, and receive healthcare funds<\/strong> while managing <strong data-start=\"3135\" data-end=\"3195\">insurance reimbursements and government health subsidies<\/strong>. With <strong data-start=\"3202\" data-end=\"3226\">over 4 million users<\/strong> and partnerships spanning <strong data-start=\"3253\" data-end=\"3272\">3,000 hospitals<\/strong>, it has been widely regarded as a <strong data-start=\"3307\" data-end=\"3348\">model for expanding healthcare access<\/strong> across the country.<\/p>\n<p data-start=\"3372\" data-end=\"3693\">However, experts note that its scale and integration with Kenya\u2019s broader digital economy also make it an attractive target for cybercriminals. The incident, if verified, could prompt renewed discussions on <strong data-start=\"3579\" data-end=\"3647\">data governance, cyber resilience, and digital health regulation<\/strong> in Africa\u2019s fastest-growing digital market.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kenya\u2019s digital health ecosystem has been rocked by a suspected massive data breach targeting M-Tiba, the country\u2019s leading mobile health wallet backed by Safaricom, CarePay, and the PharmAccess Foundation. Hackers&hellip;<\/p>\n","protected":false},"author":1,"featured_media":6533,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[95,80],"tags":[],"class_list":["post-6532","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-kenya-africa","category-news"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/regtechafrica.com\/healthcare\/wp-content\/uploads\/2025\/10\/Massive-Data-Breach-Hits-M-Tiba-Millions-of-Kenyan-Health-Records-Allegedly-Exposed.webp?fit=1200%2C674&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/regtechafrica.com\/healthcare\/wp-json\/wp\/v2\/posts\/6532","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/regtechafrica.com\/healthcare\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/regtechafrica.com\/healthcare\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/regtechafrica.com\/healthcare\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/regtechafrica.com\/healthcare\/wp-json\/wp\/v2\/comments?post=6532"}],"version-history":[{"count":1,"href":"https:\/\/regtechafrica.com\/healthcare\/wp-json\/wp\/v2\/posts\/6532\/revisions"}],"predecessor-version":[{"id":6534,"href":"https:\/\/regtechafrica.com\/healthcare\/wp-json\/wp\/v2\/posts\/6532\/revisions\/6534"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/regtechafrica.com\/healthcare\/wp-json\/wp\/v2\/media\/6533"}],"wp:attachment":[{"href":"https:\/\/regtechafrica.com\/healthcare\/wp-json\/wp\/v2\/media?parent=6532"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/regtechafrica.com\/healthcare\/wp-json\/wp\/v2\/categories?post=6532"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/regtechafrica.com\/healthcare\/wp-json\/wp\/v2\/tags?post=6532"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}