ransomware Credible Kenya (KE) government

IFMIS Kenya listed by the APT73 ransomware group

IFMIS Kenya

📅 27 April 2026
CompanyIFMIS Kenya
CountryKenya (KE)
Sectorgovernment
Breach date2026-04-27
People affected500,000
Ransomware groupapt73
Data typesfinancial management data, internal records, employee information

Overview

The APT73 ransomware group has listed IFMIS Kenya, the Integrated Financial Management Information System used by the Kenyan government for budget and expenditure management, on its leak site. The listing appeared on 27 April 2026.

What was published

The group claims to have accessed the system and copied data. A financial management information system holds government budget data, procurement and payment records and internal administrative information, which are the likely contents of any exfiltration.

Risks for affected individuals

  • Public servants' records may be exposed.
  • Financial management data is sensitive at a national level.
  • Procurement records could enable fraud.

What remains unknown

  • The volume of data exfiltrated.
  • Whether the release is scheduled.
  • The response status of the authorities.

What affected people should do

Kenyan authorities should review the affected systems, notify relevant institutions, and coordinate with national cybersecurity bodies. Public servants should be alert to phishing referencing government systems.

IFMIS leak listing

Sources

  • http://basherq53eniermxovo3bkduw5qqq5bkqcml3qictfmamgvmzovykyqd.onion/page_company.php?id=152