ransomware Credible Kenya (KE) energy

KenGen listed by the Qilin ransomware group

KenGen

📅 09 July 2025
CompanyKenGen
CountryKenya (KE)
Sectorenergy
Breach date2025-07-09
People affected100,000
Ransomware groupqilin
Data typesoperational records, corporate data, employee information

Overview

The Qilin ransomware group has listed KenGen (Kenya Electricity Generating Company), the largest electric power producer in Kenya, on its leak site. The government enterprise generates electricity for the country and the East Africa region. The listing appeared on 9 July 2025. At the time of analysis, the group's leak page was not reachable.

What was published

The group claims to have exfiltrated data from the power producer. The archive is expected to include operational records, infrastructure data and employee information.

Risks for affected individuals

  • Employees' personal records may be exposed.
  • Operational and infrastructure data could be sensitive.
  • Corporate information may be misused.

What remains unknown

  • The volume of data exfiltrated.
  • The exact contents of the leak.
  • Whether the data has been published elsewhere.

What affected people should do

The company should coordinate with Kenyan cybersecurity authorities, review affected systems, and inform staff. Employees should be alert to phishing referencing the power sector.

Sources

  • http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/view?uuid=a44799a2-c39d-33d0-abe2-0a0ead0ca3e8