ransomware Credible Kenya (KE) mining

National Mining Corporation (NAMICO) listed by the Tengu ransomware group

National Mining Corporation (NAMICO)

📅 26 January 2026
CompanyNational Mining Corporation (NAMICO)
CountryKenya (KE)
Sectormining
Breach date2026-01-26
People affectedNot disclosed
Ransomware grouptengu
Data typescorporate records, operational data, employee information

Overview

The Tengu ransomware group has listed the National Mining Corporation (NAMICO), a Kenyan state corporation created under the Kenya Mining Act 2016, on its leak site. The corporation is the government's investment arm in the mining and minerals sector. The listing appeared on 26 January 2026. At the time of analysis, the group's leak page was not reachable.

What was published

The group claims to have exfiltrated corporate data from the corporation. The archive is expected to include operational records, investment documentation and employee information.

Risks for affected individuals

  • Employees' personal records may be exposed.
  • Operational and investment data could be sensitive.
  • Corporate information may be misused.

What remains unknown

  • The volume of data exfiltrated.
  • The exact contents of the leak.
  • Whether the data has been published elsewhere.

What affected people should do

The corporation should coordinate with Kenyan cybersecurity authorities, review affected systems, and inform staff. Employees should be alert to phishing referencing the corporation.

Sources

  • http://longcc4fqrfcqt5lzceutylaxir6h66fp6df3oin6mvwvz6pfdbxc6qd.onion/blog/f48b1e6bde5227d8950b8c30a544e9ba2a6694f6b9f19d8bec21f699ea1abbe8/