By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Safaricom-backed M-Tiba hacked, exposing patient records
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Safaricom-backed M-Tiba hacked, exposing patient records
Computing

Safaricom-backed M-Tiba hacked, exposing patient records

News Room
Last updated: 2025/10/28 at 4:32 AM
News Room Published 28 October 2025
Share
SHARE

Hackers say they have stolen millions of medical and personal records from M-Tiba, a Safaricom-backed digital health wallet, in what could be one of Kenya’s largest-ever data breaches.

A group calling itself Kazu claims to have gained access to more than 17 million files, or approximately 2.15 terabytes of data, from M-Tiba’s servers. The group shared a 2GB sample of the stolen data on its Telegram channel (Kazu Breach), containing what appear to be patients’ names, national ID numbers, dates of birth, phone contacts, and, in some cases, their medical diagnoses and billing information.

The leaked files include information on about 114,000 users, both account holders and their beneficiaries, according to files examined by . Kazu claims as many as 4.8 million people could be affected, a figure that has not been independently verified.

M-Tiba, operated by CarePay, a Nairobi-based health technology company, neither confirmed nor denied the breach. The company asked to share copies of the leaked files to assist with its review.

“At M-TIBA, we take all matters of data security with the utmost seriousness. As part of our standard protocol, we would like to actively investigate the claims you are referring to,” said a CarePay representative, in an email response. “To aid our internal investigation, could you please share the specific source links or posts that have prompted your inquiry?”

An official from the Office of the Data Protection Commissioner (ODPC) said the agency was aware of the incident but declined to elaborate, citing they were not authorised to comment on an active matter.

A screenshot from Kazu Telegram channel claiming a hit on the M-Tiba platform. Image source: Kazu

The sample of stolen data also contains records from about 700 health facilities, with some scans showing full billing sheets and patient diagnostic summaries, including the names of doctors and insurance companies. In one set of documents, patient IDs, contact details, and treatment costs were listed alongside handwritten notes from medical staff.

If confirmed, the M-Tiba breach would mark one of the most serious exposures of medical data since Kenya’s Data Protection Act came into force in 2019. The law classifies health records as sensitive personal information, requiring strict safeguards.

An M-Tiba claim form with a patient’s details and doctor’s notes. 
Image source: Kazu
An Equity Afya billing invoice to M-Tiba. Image source: Kazu

Rising threats

Kenya has witnessed a series of breaches involving private companies and public platforms in recent years, including the 2023 hack on the e-Citizen platform. From education and tax systems to hospitals and fintech apps, the country’s digital shift has often outpaced its cybersecurity capacity.

Cyberattacks have been rising steadily in Kenya as more public and private services move online. The Communications Authority (CA) recorded over 4.6 billion between April and June 2025, an 80% rise compared to the previous quarter. Most incidents involved phishing, ransomware, and data breaches targeting banks, telecommunications companies, and government systems. 

M-Tiba has been one of Kenya’s digital success stories. Launched in 2016 through a partnership between CarePay, Safaricom, and the PharmAccess Foundation, the platform allows users to save and spend money specifically for healthcare. It’s also used to distribute insurance benefits and government health subsidies.

In 2024, M-Tiba claims it has over 4 million users and partnerships with over 3,000 hospitals. Its model — part mobile wallet, part health insurance clearinghouse — has been praised as a practical path toward universal health coverage.

That scale also makes it an attractive target. If the breach is as large as claimed, it could expose individual patients and the internal data of clinics, insurers, and medical professionals.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Spotify Launches New Apple TV Experience With These Features – BGR
Next Article Best Chromebook 2025: Affordable and portable Windows alternatives
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

IT investment in 2026 will rise 9.8% and exceed 6 trillion for the first time
Mobile
The Alienware 16X Aurora Is My Favorite Alienware Laptop in Years
Gadget
Building a Reliability Platform for Distributed Systems | HackerNoon
Computing
Don’t trust big tech? These are the 5 offline-first apps I recommend
News

You Might also Like

Computing

Building a Reliability Platform for Distributed Systems | HackerNoon

9 Min Read
Computing

Is Your Google Workspace as Secure as You Think it is?

10 Min Read
Computing

Amazon confirms 14,000 corporate job cuts, says push for ‘efficiency gains’ will continue into 2026

4 Min Read
Computing

Apple Silicon USB3 Support Queued Ahead Of Linux 6.19

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?