Kenya Power’s customer care account on X (@KenyaPower_Care), which has around 1.6 million followers and is listed on the utility’s own website as an official service channel, was hacked on Tuesday, September 30. The compromised account started posting cryptocurrency-related content, including messages referencing a “trading platform” covering crypto, commodities, indices and forex — content with no connection whatsoever to Kenya Power’s actual services, outage updates, or customer complaints.
A Kenya Power customer care agent publicly confirmed the breach on Thursday, October 1, advising customers to temporarily switch to the company’s Facebook page and other official channels while the issue was being resolved. The utility also posted a security advisory, explicitly warning customers that it would never ask for sensitive information like PINs, bank details, or mobile-money information when handling complaints — a precaution clearly aimed at heading off phishing attempts that often follow this kind of account takeover. The rogue crypto posts were later removed, suggesting Kenya Power had regained control of the account.
This isn’t the utility’s first brush with hacking claims. Back in July 2023, a Sudan-linked hacker group claimed it had breached Kenya Power’s backend systems and disrupted the electricity token payment service via M-Pesa, a claim the company denied at the time, even as customers reported failed prepaid token transactions. Whether or not that earlier incident was fully resolved in the public record, this latest breach raises fresh questions about how well Kenya’s critical utility providers are protecting the official accounts millions of customers rely on for service communication.
