Desk live·
ForensicPost
Breaches/International/File 25-1018

They Put the Health Records on Telegram

Attackers who reached Kenya’s M-TIBA health payments platform published the data on public Telegram channels to force payment. The publication venue is the finding.

Constructed geometry · not a chart of case data
JurisdictionKenyathe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetM-TIBA
ActorUnattributed
D. Kennedy11 min readConfidence: medium2 sources reviewed

Attackers who compromised M-TIBA, a Kenyan health payments platform, published the stolen data on public Telegram channels in October 2025 in order to force compliance with a ransom demand.

A Leak Site Is Deliberately Hard To Reach

The extortion model this corpus records throughout depends on a dark-web leak site: a hidden service, indexed by researchers, visited by journalists and negotiators. It applies pressure through the threat of wider exposure while keeping the actual exposure narrow.

Telegram is not that. It is an ordinary application on ordinary phones, reachable without special software, searchable, and shareable to anyone. Publishing there collapses the distinction between threatening to publish and publishing.

It removes the attacker’s own leverage — nothing is held back — which suggests either that the negotiation had already failed or that the objective was punishment rather than payment.

And It Changes Who Can See It

A dark-web listing is read by a professional audience. A Telegram channel is read by neighbours, employers, and family.

For health payment records — which reveal what treatment somebody sought and paid for — that distinction is the entire harm. The corpus filed at 25-1010 that there is no equivalent of a credit freeze for a leaked diagnosis. There is also no equivalent of a takedown for a forwarded message.

The Remedy Machinery Does Not Exist Here At All

This desk documented at 25-0502 that the incident record is shaped by mandatory disclosure, collective redress and a security research industry. Kenya’s data protection regime is comparatively recent and this file has no affected count, no notification, and no litigation.

Graded medium: the incident and the publication method are consistently reported, and volume, affected population and organisational response are not established.

How we reported this

Compiled from published regional reporting, listed below. We have not accessed the published data. Affected volume is not established. Corrections: corrections@forensicpost.com.

Sources
  1. In 2025, regulation forced Africa’s cyber incidents into the openTechCabal
  2. Top 10 largest cyber-attacks in Africa 2025African Exponent
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary