ransomware Credible Kenya (KE) government

Kenya Urban Roads Authority listed by the hunters ransomware group

Kenya Urban Roads Authority

📅 13 July 2024
CompanyKenya Urban Roads Authority
CountryKenya (KE)
Sectorgovernment
Breach date2024-07-13
People affected500,000
Ransomware grouphunters
Data typesNot disclosed

Overview

The Hunters ransomware group listed the Kenya Urban Roads Authority (KURA), the state agency in charge of urban roads, on its leak site on 13 July 2024. The group claimed both data exfiltration and encryption.

What was published

The listing states that data was exfiltrated and systems encrypted. The public post did not include sample files, record counts or a list of the databases involved.

Risks for affected individuals

KURA holds employee records, supplier information and project documentation. Exposure could enable targeted phishing against staff and contractors, and disrupt road project administration.

What remains unknown

The volume and sensitivity of the stolen data are not disclosed, and it is unclear whether any citizen personal data was among the files.

What affected people should do

KURA staff and contractors should treat unsolicited emails with caution and avoid reusing work passwords. The agency should disclose the incident scope and any personal data impact to the public.

Sources

  • https://hunters55rdxciehoqzwv7vgyv6nt37tbwax2reroyzxhou7my5ejyid.onion/companies/2213247662