Skip to content

ACRE Africa Breach Allegedly Exposes 14,300 Smallholder Farmers Alongside Source Code and Private Keys

Breach Report Multi-Region Agricultural Insurance Point-Gated Download

ACRE Africa Breach Allegedly Exposes 14,300 Smallholder Farmers Alongside Source Code and Private Keys

A forum user posting as 888 has published what they describe as a breach of ACRE Africa, an authorised insurance intermediary providing agricultural and climate risk cover to smallholder farmers across the continent. The post claims 14,300 user records together with the company's source code, configuration files, access tokens, private keys, and hardcoded credentials. The posted sample shows farmer records carrying full names, registered mobile numbers, subsidy amounts, field agent codes, and location down to ward level, with entries concentrated in Zambia alongside Kenyan numbers. The data is offered behind a forum points paywall. The claim is unverified.

Farmer records14,300
Also takenSource code
RegionsZambia, Kenya
Actor888

Post details

TargetACRE Africa
RegionsZambia, Kenya (sample)
SectorAgricultural insurance
ListingPoints to unlock
Records14,300 claimed
DataFarmer PII, code, credentials
Observed
Actor888

!Allegedly included

  • Farmer names
  • Registered mobile numbers
  • Subsidy amounts
  • Field agent codes
  • Unique enrolment codes
  • County & sub-county
  • Ward-level location
  • Application source code
  • Configuration files
  • Access tokens
  • Private keys
  • Hardcoded credentials

Screenshots

Potential impact

The affected population makes this heavier than the record count suggests. Smallholder farmers are among the most economically exposed users of financial services, and in these markets the registered mobile number is not merely a contact detail but the identifier a mobile money account is built on. A record pairing a farmer's name, mobile number, ward, assigned agent, and expected subsidy amount supplies everything needed for a convincing call about a payment the recipient is genuinely waiting for. Separately, private keys and hardcoded credentials in source code would represent access risk that persists until rotated, potentially reaching the systems through which those payments move.

iStatus

Unverified

A record sample and a repository listing are published as evidence. The post asserts that credentials and keys are present but does not demonstrate what they reach, so whether any remain valid is not established. The account is a long-standing forum moderator with high standing. Nothing has been independently corroborated. The claim is unverified and ACRE Africa has not publicly addressed it.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest