The Kenya Revenue Authority (KRA) has confirmed that its official X account, @KRACare, was hacked and the handle altered to “StandsX.”
In a statement issued through its verified corporate X account, the authority cautioned the public against engaging with any messages, posts, or links from the compromised account, warning that they may be used for fraudulent purposes.
“Members of the public are strongly warned not to engage, share personal information, or send money to any messages or posts from this account, as they are fraudulent,” KRA stated.
The tax agency said it has launched immediate efforts, in partnership with X, to recover control of the account and reinforce its security systems.
Until the issue is resolved, official communication will continue through KRA’s verified platforms, including Facebook at facebook.com/KRACare and WhatsApp via 0711099999.
Cybersecurity experts say such incidents are increasingly common, with hackers targeting trusted public accounts to trick followers into revealing personal or financial details. Attackers often use phishing tactics, weak passwords, or insider access to take control, later posting malicious content or links that appear legitimate.
The change of the handle to “StandsX,” analysts note, is a common strategy used by hackers to disguise an account’s identity while maintaining its follower base.

KRA’s quick response underscores growing concern about the reputational and operational risks posed by social media breaches. The agency urged Kenyans to always verify posts through official channels and remain vigilant against online scams.
Experts recommend using two-factor authentication, strong passwords, and regular monitoring to enhance account security.
KRA assured the public that it is treating the breach as a top priority and will provide updates once the account is fully secured.
The Lower Eastern Times Opening The Third Eye