TechNewsReel
Live

Moldovan Firm Sells Data of 2 Million Kenyan Companies After BRS Breach

Sensitive corporate records, including holdings of Kenya's political elite, were exposed via a vulnerability in the state registration system.

TechNewsReel Newsroom · September 7, 2026

A Moldovan business intelligence firm has allegedly exploited a vulnerability in Kenya's state-owned Business Registration Service (BRS), accessing and selling the sensitive data of more than two million companies. The breach has exposed the private corporate networks and residential details of the nation's most powerful figures, including the families of President William Ruto, former President Uhuru Kenyatta, and former Prime Minister Raila Odinga.

According to reports from Business Daily and ITWeb Africa, the firm B2Bhint monetized the leaked information by offering data packages priced as high as Sh24 million ($186,433). At the other end of the spectrum, the firm sold individual phone numbers for as little as $0.015. The compromised dataset included residential addresses, email addresses, phone numbers, and the identities of beneficial owners—individuals who ultimately own or control a company.

The Disclosure Deadline

The breach is believed to have occurred around January 31, shortly after a critical regulatory milestone. On December 1, the Kenyan government implemented a deadline requiring all companies to disclose beneficial owners holding stakes of more than 10% to the BRS. As the sole custodian of registration information for every entity in Kenya, the BRS became a high-value target immediately after this influx of sensitive ownership data was mandated.

Implications for National Security

This leak provides a rare and unauthorized public glimpse into multi-billion-shilling estates and corporate structures that are typically reserved for law enforcement and regulatory oversight. Beyond the political fallout, the incident underscores severe cybersecurity vulnerabilities within Kenya's critical government digital infrastructure. The ability of a foreign intelligence firm to extract and commercialize the private data of millions of businesses suggests a systemic failure in the protection of state-held digital assets.

Official Response and Disputes

Kenneth Gathuma, Director General of BRS, stated that cybersecurity experts are working with law enforcement and investigative agencies to assess the full scope of the incident. However, the nature of the breach remains a point of contention. A representative for B2Bhint has disputed the claim that they hacked the system, arguing instead that the BRS website contained a direct link where company data was available free of charge, suggesting the information was effectively public.

Investigators are now tasked with determining whether the data was accessed through a technical exploit or a failure in access control settings. For now, the breach leaves millions of Kenyan business owners and the country's political leadership exposed to potential fraud and targeted intelligence gathering.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.