Attackers using stolen credentials from a compromised third-party healthcare provider device accessed CarePay's M-TIBA Version 2 platform between October 17-25, 2025, exposing roughly 4.8 million records (about 2.15 terabytes) covering names, national ID numbers, dates of birth, photos, medical diagnoses, lab results, prescriptions, discharge summaries, and insurance claims data from ~700 health facilities across Kenya. A hacker group calling itself 'Kazu' claimed responsibility and shared a 2GB sample on Telegram and the dark web. CarePay took 10 days to detect the breach (discovered October 27, 2025), exceeding Kenya's Data Protection Act 72-hour reporting requirement. Kenya's Office of the Data Protection Commissioner (ODPC) learned of the incident from media reports on October 29, 2025 rather than from CarePay, and insurance-partner staff at Jubilee and AAR Insurance likewise learned of it from the press. CarePay stated it had informed the insurance 'controllers' who would in turn notify data subjects, rather than notifying affected individuals directly. The ODPC opened an investigation; CarePay discontinued its 'My Health Funds' wallet product in March 2026 and began issuing refunds via M-PESA in April 2026.
company
CarePay International (M-TIBA)
Health-insurance technology platform operating as M-TIBA in Kenya, connecting mobile money, insurance claims, and health records for millions of users across sub-Saharan Africa.
Track Record
negligent