ransomware
Credible
Kenya (KE)
government
IFMIS Kenya listed by the APT73 ransomware group
IFMIS Kenya
CompanyIFMIS Kenya
Domainifmis.go.ke
CountryKenya (KE)
Sectorgovernment
Breach date2026-04-27
People affected500,000
Ransomware groupapt73
Data typesfinancial management data, internal records, employee information
Overview
The APT73 ransomware group has listed IFMIS Kenya, the Integrated Financial Management Information System used by the Kenyan government for budget and expenditure management, on its leak site. The listing appeared on 27 April 2026.
What was published
The group claims to have accessed the system and copied data. A financial management information system holds government budget data, procurement and payment records and internal administrative information, which are the likely contents of any exfiltration.
Risks for affected individuals
- Public servants' records may be exposed.
- Financial management data is sensitive at a national level.
- Procurement records could enable fraud.
What remains unknown
- The volume of data exfiltrated.
- Whether the release is scheduled.
- The response status of the authorities.
What affected people should do
Kenyan authorities should review the affected systems, notify relevant institutions, and coordinate with national cybersecurity bodies. Public servants should be alert to phishing referencing government systems.

Sources
- http://basherq53eniermxovo3bkduw5qqq5bkqcml3qictfmamgvmzovykyqd.onion/page_company.php?id=152