ransomware Credible Kenya (KE) government

Office of the Registrar of Political Parties (ORPP) listed by the Qilin ransomware group

Office of the Registrar of Political Parties (ORPP)

📅 14 September 2025
CompanyOffice of the Registrar of Political Parties (ORPP)
CountryKenya (KE)
Sectorgovernment
Breach date2025-09-14
People affected500,000
Ransomware groupqilin
Data typesparty registration records, administrative data, employee information

Overview

The Qilin ransomware group has listed the Office of the Registrar of Political Parties (ORPP), a Kenyan state office responsible for the registration and regulation of political parties, on its leak site. The listing appeared on 14 September 2025. At the time of analysis, the group's leak page was not reachable.

What was published

The group claims to have exfiltrated data from the office. The archive is expected to include party registration records, administrative data and employee information.

Risks for affected individuals

  • Political party records are sensitive.
  • Employees' information may be exposed.
  • Administrative data could be misused.

What remains unknown

  • The volume of data exfiltrated.
  • The exact contents of the leak.
  • Whether the data has been published elsewhere.

What affected people should do

The office should coordinate with Kenyan cybersecurity authorities, review affected systems, and inform staff and registered parties. Parties should be alert to phishing referencing the office.

Sources

  • http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/view?uuid=9b578dea-1096-350f-b534-c82d2075f96f