Skip to main content

CarePay International (M-TIBA)CarePay's M-TIBA platform breached, exposing health and insurance records of 4.8 million Kenyans; company missed legal disclosure deadline

Attackers using stolen credentials from a compromised third-party healthcare provider device accessed CarePay's M-TIBA Version 2 platform between October 17-25, 2025, exposing roughly 4.8 million records (about 2.15 terabytes) covering names, national ID numbers, dates of birth, photos, medical diagnoses, lab results, prescriptions, discharge summaries, and insurance claims data from ~700 health facilities across Kenya. A hacker group calling itself 'Kazu' claimed responsibility and shared a 2GB sample on Telegram and the dark web. CarePay took 10 days to detect the breach (discovered October 27, 2025), exceeding Kenya's Data Protection Act 72-hour reporting requirement. Kenya's Office of the Data Protection Commissioner (ODPC) learned of the incident from media reports on October 29, 2025 rather than from CarePay, and insurance-partner staff at Jubilee and AAR Insurance likewise learned of it from the press. CarePay stated it had informed the insurance 'controllers' who would in turn notify data subjects, rather than notifying affected individuals directly. The ODPC opened an investigation; CarePay discontinued its 'My Health Funds' wallet product in March 2026 and began issuing refunds via M-PESA in April 2026.

Scoring Impact

TopicDirectionRelevanceContribution
Corporate Transparency-againstsecondary-0.50
Data Security-againstprimary-1.00
Overall incident score =-0.403

Score = avg(topic contributions) × significance (high ×1.5) × confidence (0.72)× agency (negligent ×0.5)

Evidence (3 signals)

Confirms product_decision Nov 12, 2025 documented

TechCabal: M-Tiba took 10 days to detect breach that exposed Kenyan health data

Follow-up TechCabal reporting detailed the 10-day detection lag, the compromised third-party credentials attack vector, and CarePay's decision to route data-subject notification through insurance-company controllers rather than notifying affected patients directly.

Confirms Legal Action Oct 29, 2025 documented

The Star: ODPC investigates possible M-Tiba data breach after learning of it via media reports

Kenya's Office of the Data Protection Commissioner said it was aware of media reports of the M-Tiba breach and opened an investigation, after learning of the incident from press coverage rather than from CarePay.

Confirms product_decision Oct 28, 2025 documented

TechCabal: Safaricom-backed M-Tiba hacked, exposing 4.8 million patient records

TechCabal reported that M-Tiba, backed by Safaricom, was hacked with 4.8 million patient records exposed, based on a hacker group's Telegram claims and dark-web sample data.

Related: Same Topics