Naivas: Confidential Data Theft Claimed by ALPHV
Naivas
Overview
In April 2023, the ALPHV ransomware group claimed to have hacked Naivas, one of Kenya's largest supermarket chains, and stolen a large amount of confidential data. The group published the claim on its leak site alongside a description of the company.
What was published
The listing stated that Naivas was hacked and that a large amount of confidential data had been taken. The post did not include a detailed inventory of the stolen files, so the specific records involved remain undefined. Naivas operates dozens of stores across Kenya and serves a large customer base, which makes the potential scope of the exposure.
Risks for affected individuals
- Customer details held by the retailer, including contact information and purchase history, could be part of the stolen data.
- Employee records and internal company documents may also be affected.
- Stolen data can be used for phishing, fraud, or further attacks against the company's customers and staff.
What remains unknown
- The volume of data and the number of people affected were not disclosed in the listing.
- There is no public confirmation from Naivas about the incident or its response.
- Whether the data was published, sold, or deleted after negotiations is not known.
What affected people should do
Naivas customers should monitor their accounts and be alert to unsolicited messages that reference the retailer. Anyone who used loyalty or payment details with the chain should watch for suspicious transactions. Employees and partners should follow any guidance issued by the company and avoid acting on unexpected requests for credentials or payments.