ransomware
Credible
Kenya (KE)
government
Office of the Registrar of Political Parties (ORPP) listed by the Qilin ransomware group
Office of the Registrar of Political Parties (ORPP)
CompanyOffice of the Registrar of Political Parties (ORPP)
Domainorpp.or.ke
CountryKenya (KE)
Sectorgovernment
Breach date2025-09-14
People affected500,000
Ransomware groupqilin
Data typesparty registration records, administrative data, employee information
Overview
The Qilin ransomware group has listed the Office of the Registrar of Political Parties (ORPP), a Kenyan state office responsible for the registration and regulation of political parties, on its leak site. The listing appeared on 14 September 2025. At the time of analysis, the group's leak page was not reachable.
What was published
The group claims to have exfiltrated data from the office. The archive is expected to include party registration records, administrative data and employee information.
Risks for affected individuals
- Political party records are sensitive.
- Employees' information may be exposed.
- Administrative data could be misused.
What remains unknown
- The volume of data exfiltrated.
- The exact contents of the leak.
- Whether the data has been published elsewhere.
What affected people should do
The office should coordinate with Kenyan cybersecurity authorities, review affected systems, and inform staff and registered parties. Parties should be alert to phishing referencing the office.
Sources
- http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/view?uuid=9b578dea-1096-350f-b534-c82d2075f96f