ransomware
Credible
Kenya (KE)
healthcare
Bomu Hospital listed by the Krybit ransomware group
Bomu Hospital
CompanyBomu Hospital
Domainbomuhospital.org
CountryKenya (KE)
Sectorhealthcare
Breach date2026-04-30
People affected100,000
Ransomware groupkrybit
Data typespatient data, medical records, corporate information
Overview
The Krybit ransomware group has listed Bomu Hospital, a Kenyan social enterprise providing healthcare services, on its leak site. The listing appeared on 30 April 2026.
What was published
The group claims to have exfiltrated data from the hospital. The archive is expected to include patient records, medical documentation and corporate information. The full dataset has not been released publicly at this stage.
Risks for affected individuals
- Patient medical data may be exposed.
- Healthcare records are sensitive and could be used for fraud.
- Employees' personal information may be included.
What remains unknown
- The volume of data exfiltrated.
- Whether the data has been published.
- The extent of the intrusion.
What affected people should do
Patients should monitor for unusual activity and be cautious of unsolicited communications referencing the hospital. Bomu Hospital should notify affected patients and authorities, review its systems, and follow data protection requirements for medical data breaches.

Sources
- http://krybitqsdzwmhnitvwuhvsntfgf2wrhxveyxroxpc44c6gkft2cqldyd.onion/blog/00b2166002a46d2c1f0677b1e0da903b062734a5166c18de1d2d4e01ad295e23/