Ransomware victim disclosure
← All victimsNational Microfinance Bank (NAMICO)
listed as namico.go.ke · Claimed by Tengu · listed 5 months ago
Status timeline
- ListedJan 26, 2026
- Data leakeddate unknown
At a glance
- Group
- Tengu
- Status
- Data leaked
- Country
- Kenya
- Sector
- Public Sector
- Listed on leak site
- Jan 26, 2026
About the victim
AI dossier — public-source company profilenamico.go.ke is a Kenyan government-affiliated microfinance institution operating under the .go.ke domain, indicating it is a state-owned or state-linked entity. The organisation provides microfinance or small-loan financial services to individuals and businesses in Kenya. As a public-sector financial entity, it is likely subject to Kenyan financial regulatory frameworks.
- Industry
- Microfinance & Public Financial Services
Attack summary
Severity: high — The victim is a public-sector financial/microfinance institution in Kenya with a .go.ke government domain, and data has already been published (confirmed exfiltration). This likely involves financial records, customer PII, and government-linked data, warranting a high severity rating. Insufficient detail to confirm the full scale required for critical.The Tengu ransomware group claims to have published data exfiltrated from namico.go.ke; the disclosure status is listed as 'data_published', indicating stolen data has been released rather than merely threatened.
Data the group says was taken
AI dossier — extracted from the leak post- Exfiltrated organizational data (published)
What the group claims
The National Mining Corporation (NAMICO) is a Kenyan state corporation that serves as the government's investment arm in the mining and minerals sector. Established under the Kenya Mining Act 2016, its primary objective is the exploration, development, management, and investment of the country's mineral resources on behalf of the state.
The leak post
captured from the group's siteShisa Ransomware Blog Shisa RANSOMWARE DATA LEAKS BLOG HOME AFFILIATE PROGRAM CONTACT crown-security.com.tw PUBLISHED Crown Security is a technology company specializing in information security and digital systems, offering advanced solutions to protect corporate networks and data from breaches and cyberattacks The company focuses on providing security consulting and implementing integrated protection systems tailored to each organization's needs 27,470 👁 Sileno Companies Inc PUBLISHED Sileno Companies Inc. A US company primarily operating in the hospitality and real estate sectors, its activities include: Hotel operation Property management Management of hotels' restaurants and bars Hospitality project development 22.9TB was encrypted in 14 hours on 3/5/2026 More than 67.07 GB was extracted 29,787 👁 Eos Technology srl PUBLISHED Eos Technology srl is a company with 15 years of experience in the ICT sector, initially starting as an assembly and repair laboratory for PCs and peripherals. Over time, it has developed expertise that has allowed it to become a partner of various international brands. The company offers a range of services including IT assistance, multimedia services, h…
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

