By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: M-Tiba took 10 days to detect breach exposing 5m Kenyans’ health records
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > M-Tiba took 10 days to detect breach exposing 5m Kenyans’ health records
Computing

M-Tiba took 10 days to detect breach exposing 5m Kenyans’ health records

News Room
Last updated: 2025/11/12 at 2:52 AM
News Room Published 12 November 2025
Share
M-Tiba took 10 days to detect breach exposing 5m Kenyans’ health records
SHARE

A cyberattack on M-Tiba, a Kenyan healthtech platform, went undetected for 10 days, exposing the personal and medical information of nearly five million Kenyans, according to an internal status report seen by .

The report—shared by M-Tiba’s operator CarePay Limited to insurance companies including Jubilee, Fidelity, GA Insurance, and AAR Insurance—reveals that the breach occurred between October 17 and 25, but was only discovered on October 27 at 1:23 p.m.

The report paints a picture of delayed detection, limited communication, and potential violations of Kenya’s data protection laws.

10-day blindspot

CarePay said the intrusion began when a third-party healthcare provider’s device was infiltrated, compromising their user credentials. Using the stolen details, the attackers forced access to M-Tiba’s Version 2 platform and extracted a large dataset covering insurance claims, patient information, and clinical records.

“Approximately 4.8 million records were illegally obtained in relation to beneficiaries and claims across various healthcare payers,” CarePay said in the report. “A sample of the dataset has been made available for downloading via the dark web.”

While CarePay has not yet contacted affected individuals, the company says it has notified data controllers, including insurance firms, who are expected to reach out to data subjects directly.

“As the processor, we have informed the controllers who will subsequently inform data subjects,” the report said.

CarePay did not respond to a request for comment.

The affected data includes financial information such as insurance claims, benefit limits, and utilisation; personally identifiable information, including full names, ID numbers, photos, and contact details; as well as sensitive health information such as diagnoses, lab results, prescriptions, and discharge summaries.

Those affected include insurance companies, healthcare providers, and policyholders — including children.

A review of the accessed data found that all major insurance firms were affected, along with thousands of health facilities—public, private, and those run by religious institutions such as the Catholic Church—spread across the country, including rural areas. This points to a massive breach that may have been significantly underreported.

Silence and confusion

Four people at Jubilee and AAR Insurance who asked not to be named told that they learned of the incident from media reports, not from CarePay or the ODPC. 

The regulator itself appeared to confirm this communication lapse. In a public notice on October 29, the ODPC said it became aware of the M-Tiba incident through media reports.

“The ODPC is aware of media reports that mobile-health-wallet platform M-Tiba may have experienced a cyber-incident involving the potential exposure of personal and health data of users,” the regulator said.

ODPC did not respond to ’s request for comment.

Under Kenya’s Data Protection Act (2019), data controllers and processors are required to report breaches within 72 hours of becoming aware of them and to promptly notify affected individuals if the breach is likely to result in a high risk to their rights.

CarePay’s timeline shows that the breach was active for 10 days before being detected, and that neither M-Tiba nor its partner insurers have yet notified affected users.

“As the processor, we have informed the controllers who will subsequently inform data subjects,” the company said, referring to insurers and health payers responsible for patient data.

Regulatory reckoning 

The regulator has opened investigations into the incident. An official confirmed to that the office received the report but was reviewing whether the company complied with local data laws.

If found to have violated reporting and notification requirements, CarePay could face fines and enforcement orders under the Data Protection Act.

M-Tiba, launched in 2016 through a partnership between CarePay, Safaricom, and the PharmAccess Foundation, allows users to save and spend money specifically for healthcare. It handles millions of insurance and out-of-pocket medical transactions annually and claims to have partnerships with over 3,000 hospitals.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Best early Black Friday AirPods deals Best early Black Friday AirPods deals
Next Article Early Black Friday Deal: Lock Down 42% Off Ultraloq Smart Lock U-Bolt Pro Early Black Friday Deal: Lock Down 42% Off Ultraloq Smart Lock U-Bolt Pro
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Space forecasters say severe solar storms could hit Earth and trigger auroras
News
T-Mobile’s T-Life app is acting up again, causing chaos for some users
T-Mobile’s T-Life app is acting up again, causing chaos for some users
News
Best Dyson deal: Save  on Dyson HushJet
Best Dyson deal: Save $50 on Dyson HushJet
News
How Orbs Is Turning Base Network DEXs Into Perpetual Futures Powerhouses | HackerNoon
How Orbs Is Turning Base Network DEXs Into Perpetual Futures Powerhouses | HackerNoon
Computing

You Might also Like

How Orbs Is Turning Base Network DEXs Into Perpetual Futures Powerhouses | HackerNoon
Computing

How Orbs Is Turning Base Network DEXs Into Perpetual Futures Powerhouses | HackerNoon

9 Min Read
Microsoft Fixes 63 Security Flaws, Including a Windows Kernel Zero-Day Under Active Attack
Computing

Microsoft Fixes 63 Security Flaws, Including a Windows Kernel Zero-Day Under Active Attack

6 Min Read
Active Directory Under Siege: Why Critical Infrastructure Needs Stronger Security
Computing

Active Directory Under Siege: Why Critical Infrastructure Needs Stronger Security

8 Min Read
Haiku OS Made Many Kernel & App Improvements In October
Computing

Haiku OS Made Many Kernel & App Improvements In October

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?