Naivas, 2023: ransomware reaches Kenya's largest supermarket chain

For years, ransomware headlines from Africa were dominated by South African targets. In April 2023, Naivas — Kenya's largest supermarket chain, with close to a hundred branches — confirmed that it too had been attacked, a milestone moment for East African retail and a reminder that extortion crews follow data and revenue, not geography.

What happened

In late April 2023, Naivas issued a public statement confirming that it had "recently been the target of a ransomware attack by an online criminal group". The disclosure followed claims by the Mallox ransomware operation (also tracked as TargetCompany), which listed Naivas on its leak site and claimed to have stolen company data, threatening publication.

Naivas said it had engaged leading cybersecurity experts to contain the attack and investigate, and moved to reassure customers on the point that matters most in retail: payment data. The company stated that it does not hold customers' debit or credit card information, as card transactions are processed through secure, independent payment channels. It acknowledged that some data had been compromised and said it regretted any inconvenience or concern caused. Stores continued operating, and no prolonged consumer-facing outage was reported. The company indicated it would not engage with the extortionists, consistent with law-enforcement guidance. Details of what data the attackers ultimately held, and whether any was published, were not comprehensively confirmed in public reporting.

How the attack worked

Naivas did not disclose the intrusion vector, and no verified technical account has been published. The Mallox operation, as documented by security researchers in the same period, was known for gaining access through exposed or weakly secured services — with brute-forced or compromised credentials and phishing among the routes reported across its victim set globally. Which route applied at Naivas is not publicly known, and it would be wrong to assert one.

What can be said is that double-extortion ransomware — encrypt what you can, steal what you can, and pressure the victim with both — had clearly arrived in East African retail. Supermarket groups run large, distributed IT estates: point-of-sale systems, supplier portals, loyalty databases and thousands of employee accounts. Every one of those is a potential entry point, and most of them are operated by people whose day job is retail, not security.

The impact

The lasting significance of the Naivas incident is less about measured losses — which were not published — and more about precedent. A household-name Kenyan retailer was named on a criminal leak site, had to brief millions of customers on a cyber incident, and absorbed the forensic, legal and reputational costs that follow. The incident landed in the same year as the eCitizen DDoS wave, contributing to a visible shift in how seriously Kenyan boards and regulators treat cyber risk. For customers, the practical exposure was the possibility of personal data appearing in criminal hands, with the follow-on phishing risk that entails.

Lessons for African organisations

  • Being outside South Africa is no longer distance. Extortion groups target opportunity. East and West African enterprises should assume they are already being scanned and scoped.
  • Retail workforces need retail-shaped training. Thousands of staff on shared terminals and shift patterns need short, frequent, practical awareness — not annual compliance slideware.
  • Not holding card data is a strategy, not luck. Naivas could reassure customers because payment processing was segregated. Data you never store is data you never lose.
  • Prepare the customer statement before the incident. A clear, honest disclosure that says what is and is not affected — as Naivas's did on card data — is worth drafting as a template in peacetime.
  • Watch the leak sites. Victims often learn of extortion claims from researchers or journalists. Monitoring criminal leak sites, directly or through a provider, buys response time.

Sources

  • Naivas public statement confirming the ransomware attack, April 2023
  • Kenyan media coverage including Business Daily and Techweez, 2023
  • Security-industry reporting on the Mallox/TargetCompany ransomware operation, 2023
  • Regional coverage of the incident's significance for East African retail, 2023

Ransomware crews look for the least-prepared workforce in the room — find out where yours stands with the free Human Risk Maturity Assessment.