Kenya National Highways Authority (KeNHA) listed by the Deadlock ransomware group
Kenya National Highways Authority (KeNHA)
Overview
The Deadlock ransomware group has listed the Kenya National Highways Authority (KeNHA), the state agency responsible for building and maintaining Kenya's national highways, on its leak site. The listing appeared on 25 July 2026.

What was published
The group claims to have accessed the authority's systems and to be preparing a data release. The data is expected to include project documentation, contractor records, internal correspondence and employee information. The authority manages a national road network, so technical and procurement data are the likely targets.
Risks for affected individuals
- Employees' personal records may be exposed.
- Contractor and supplier data could be used in fraudulent schemes.
- Infrastructure documentation may be sensitive from a national security perspective.
What remains unknown
- The volume of data exfiltrated.
- Whether the release has been scheduled or is still under negotiation.
- The attack vector used against the agency.
What affected people should do
Government employees and contractors should monitor their accounts and be cautious of phishing referencing official projects. KeNHA should coordinate with Kenya's national cybersecurity authorities and communicate the scope of the incident to affected parties.
Sources
- http://deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion/s3.php?d=d2FzYWJpOmRhdGEta2VuaGEuY28ua2V8ZXUtY2VudHJhbC0xfERFN1VJR09INllWUFg0QjlFMUlXfDBaWDVGdzJCOWxHd3BiZUw1cW9HZ2JlQzRLTGoydk5xcEVZanp2Z00%3D