The Kenyan government has assembled a multi-agency team to investigate a breach at the Business Registration Service (BRS) after Moldovan firm B2BHint was reported to have accessed data belonging to Kenyan-registered companies, including shareholders' residential addresses and telephone numbers.
The breach is believed to have occurred earlier this year, exposing records for roughly two million companies. The data was temporarily searchable through B2BHint's platform before being taken down.
BRS director general Kenneth Gathuma said cybersecurity experts are working with law enforcement and investigative agencies to establish the scope of the incident.
"Our cyber security experts are working closely with our cybersecurity partner, law enforcement, and investigative agencies to assess the scope of the incident, determine any potential impact, and implement necessary containment and mitigation measures," Gathuma said.
The agency has since tightened its security protocols while verifying the full extent of the compromised data. It says affected parties will be notified once investigations conclude.
Kenyans who registered companies with BRS between 2015 and 2021 were advised to change their eCitizen passwords as a precaution.
The incident follows earlier attacks on government-linked systems, including a leak of Kenya Airports Authority data after the agency did not meet a ransom demand from the Medusa ransomware group, and a denial-of-service attack on the eCitizen platform.
Kenya recorded 657.8 million cyber threats between July and September 2024, with more than 583 million linked to system vulnerabilities.
The Ministry of ICT has urged businesses and individuals to strengthen their cybersecurity measures, verify websites and emails, guard against phishing and back up important data regularly.
BRS said it will provide further updates once its investigation is complete.
Share

