Attackers who compromised M-TIBA, a Kenyan health payments platform, published the stolen data on public Telegram channels in October 2025 in order to force compliance with a ransom demand.
A Leak Site Is Deliberately Hard To Reach
The extortion model this corpus records throughout depends on a dark-web leak site: a hidden service, indexed by researchers, visited by journalists and negotiators. It applies pressure through the threat of wider exposure while keeping the actual exposure narrow.
Telegram is not that. It is an ordinary application on ordinary phones, reachable without special software, searchable, and shareable to anyone. Publishing there collapses the distinction between threatening to publish and publishing.
It removes the attacker’s own leverage — nothing is held back — which suggests either that the negotiation had already failed or that the objective was punishment rather than payment.
And It Changes Who Can See It
A dark-web listing is read by a professional audience. A Telegram channel is read by neighbours, employers, and family.
For health payment records — which reveal what treatment somebody sought and paid for — that distinction is the entire harm. The corpus filed at 25-1010 that there is no equivalent of a credit freeze for a leaked diagnosis. There is also no equivalent of a takedown for a forwarded message.
The Remedy Machinery Does Not Exist Here At All
This desk documented at 25-0502 that the incident record is shaped by mandatory disclosure, collective redress and a security research industry. Kenya’s data protection regime is comparatively recent and this file has no affected count, no notification, and no litigation.
Graded medium: the incident and the publication method are consistently reported, and volume, affected population and organisational response are not established.
Compiled from published regional reporting, listed below. We have not accessed the published data. Affected volume is not established. Corrections: corrections@forensicpost.com.