Home » Inside the #SHAAt28Million Campaign: Coordinated Messaging or Organic Outrage?

Inside the #SHAAt28Million Campaign: Coordinated Messaging or Organic Outrage?

On November 24, 2025, the Office of the Ombudsman and Africa Uncensored received a response dated 21st November from Kenya’s Social Health Authority (SHA) to a Freedom of Information Act (FOIA) request. Africa Uncensored had submitted the request on August 4, 2025,  seeking clarity on SHA’s means-testing system and the criteria used to determine monthly premiums for Kenyans in the informal sector ahead of publishing the documentary ErrorByDesign.                       


Screengrab of FOIA request and Reply from SHA 

Two weeks later, on December 8th, the hashtag #SHAAt28Million with the phrase “means testing” was trending on X. Between 10:57 UTC and 23:36 UTC  (a span of 12.6 hours) 871 tweets were captured from 158 unique accounts (dataset). Of these, 465 were reposts (53.4%) while 406 were original posts or replies (46.6%). The activity showed unusually high amplification patterns, with repost-driven engagement dominating the conversation. The trend displayed several overlapping indicators commonly associated with coordinated and inauthentic amplification rather than organic public discourse.

Screengrab of posts during the SHAAT28Million Campaign

Piga Firimbi investigated the accounts, comments, reposts, and posts driving the narrative on X and found evidence suggesting a highly coordinated campaign bearing the hallmarks of an influence operation, likely aimed at diverting public attention from the substantive concerns raised about SHA’s means-testing system.

Network diagram showing retweet amplification: Source Gephi.

Kenya’s Health System

The Social Health Authority uses proxy means testing (PMT) to estimate income for people in the informal sector, who make up nearly 80% of Kenya’s workforce and often lack formal income records. Households are required to contribute 2.75% of their income to the Social Health Insurance Fund (SHIF). While salaried employees have the amount deducted directly from their wages, non-salaried workers are assessed through an algorithmic model that predicts household welfare using more than 43 variables derived from several questions asked during registration. These include housing material, ownership of assets such as bicycles or refrigerators, education level, household size, access to electricity and sanitation, employment status, geographic location among others.

The model, built using data from the 2021 Kenyan Continuous Household Survey covering about 17,000 households, applies regression to estimate per-capita consumption, which is then used as a proxy for income and used to calculate premiums. Households assessed at Ksh 300 or below pay a base premium of KSh 300 and may qualify for subsidies, while those estimated above that threshold pay the full calculated contribution without government support. Citizens can access the means-testing process through the Afya Yangu portal by declaring themselves self-employed and some answering a series of socio-economic questions. 

However, investigative findings by Africa Uncensored, Lighthouse Reports and Guardian have raised concerns about the fairness and accuracy of the model, showing that it tends to overestimate the income of poorest households while underestimating that of wealthiest ones. In the documentary ErrorbyDesign nearly 80% of the poorest households  are likely charged more than they should be, while over 60% of the wealthiest households would contribute less than expected. Critics also had noted high exclusion error rates, especially among vulnerable households with access to electricity, education, or those living in relatively affluent counties. Although the model demonstrates moderate predictive accuracy overall, its limitations at the extremes of the income distribution have fueled concerns about inequity in the implementation of universal health coverage financing in Kenya. 

Heat map showing the campaign trend on Dec 9th from 10am to 23:59 am

Means testing directly assesses a household’s income or consumption to determine eligibility or contribution levels. Proxy means testing (PMT) estimates income/consumption when direct data is unavailable, using observable household characteristics  that correlate with economic status

DEFLECTION & TIMELINE ANALYSIS

The hashtag #SHAAt28Million AND means testing campaign followed a classic astroturfing curve of a low morning start to massive midday burst to sustained afternoon tail. Organic discussions of government health programs typically spread across multiple days with gradual growth curves, not single-day explosive spikes.

 

The Twitter campaign’s peak burst at 12:25 UTC occurred less than 3 weeks after SHA’s reply, consistent with a reactive, coordinated counter-narrative operation timed to flood the information space with positive SHA/Taifacare content on the same day as the critical inquiry was made. The evidence includes synchronized posting bursts, near-identical copy-pasted content replicated up to 28 times, a small cluster of “seed” accounts whose messages were mass-amplified within narrow time windows, a heavy concentration of newly created accounts, and near-total absence of critical or negative sentiment.

Bubble chart showing overall sentiments in the data set.

 

All tweets combine #SHAAt28Million with “means testing” and often “Taifacare” a precise, coordinated hashtag strategy. The hashtag #SHAAt28Million itself appears to be a campaign-created hashtag designed to flood search results and trend organically.

METHODOLOGY

We used a data set of 872 tweets captured from 9th Dec 2025 to 10th Dec 2025.

TIMELINE ANALYSIS

1.1 Posting Concentration

The campaign was compressed into approximately 13 hours. The most dramatic finding is the extreme burst at 12:25–12:35 UTC:

Chronological Activity Log

5- Minute window Tweet Volume Activity Phase
11:55 52 Morning escalation
12:15 38 Build-up phase
12:25 94 Pre-peak surge (Immediately before peak)
12:30 120 Peak burst (9.5% of all tweets in 5 min)
12:35 48 Immediate post-peak retraction

 

Chronological Narrative

  • 11:55 – Morning Escalation: 52 tweets. The initial uptick began here, setting the baseline for the subsequent surge.
  • 12:15 – Build-up Phase: 38 tweets. While volume decreased slightly, this period marked the final consolidation before the peak.
  • 12:25 – Pre-Peak Surge: 94 tweets. Volume increased by nearly 150% in just ten minutes, signaling an imminent burst.
  • 12:30 – Peak Burst: 120 tweets. This 5-minute window accounted for 9.5% of all daily tweet activity.
  • 12:35 – Post-Peak Retraction: 48 tweets. Activity levels returned to near-morning escalation levels immediately following the burst.

A total of ~214 tweets in just 10 minutes (12:25–12:35 UTC). This level of burst posting is inconsistent with normal organic engagement. For 214 tweets to occur in 10 minutes from independent users, each of the 158 unique accounts would need to be posting simultaneously, which is statistically implausible without coordination.

Heat map showing the chronological activity from 10:55am- 22:35am

1.2 Synchronized Posting Windows

A synchronized posting analysis reveals multiple instances where many different accounts posted within the same narrow time window:

  • 12:25–12:35 UTC: 214 tweets from what appear to be many different accounts, in just 10 minutes
  • Multiple 5-minute windows exceed 38+ tweets — unusual for a campaign involving 158 accounts unless coordinated
  • Inter-tweet median interval: only ~17 seconds during peak windows

Truly organic Twitter engagement from independent users produces a Poisson-distributed posting pattern with much longer median gaps. Sub-minute median intervals across campaign windows are inconsistent with organic behavior.

Accounts race showing coordinated posting from 10:45 a.m -16:30 p.m

 

Network diagram showing co-timing of accounts posting / Source : Gephi

2. Seed Account Amplification Network

The campaign operates through a clearly identifiable two-tier structure:

Tier 1 — “Seed” Accounts (original posters): A small group of accounts posted the original campaign messages.
Tier 2 — “Amplifier” Accounts (retweeters): A larger group of accounts rapidly retweeted the seed content.

Seed Account Times Amplified Amplification Pattern
@Bristol_254 33 Concentrated burst
@cosmochoy 45 (rt_count includes original tweets) Most-repeated individual message (28×)
@punny_biz 25 Coordinated amplification
@SeyMonicah 22 Cross-cluster amplification
@IsajiBrian1 21 Coordinated amplification
@Ruto_nated 19 Pro-government aligned
@_EvelynKe 19 Coordinated amplification
@naledifusion 19 Coordinated amplification
@ke_johnnieh 18 Coordinated amplification
@Shaccari254 17 Coordinated amplification


Bubble chart showing seed accounts and amplifier accounts

Key observation: Account names like “Ruto Stan!”, “Ruto_nated”, “UDA Documentation“, “Didmus Barasa Commentary”, “Speaker Wetangula Commentary”, and “Kenya Kwanza Commentary” explicitly align with the ruling UDA/Kenya Kwanza political coalition, suggesting the CIB campaign has political/government affiliations

2.2 STRUCTURAL FINDINGS: THE OPERATION’S ARCHITECTURE

Based on the data, the probable structure of this CIB campaign is:

COORDINATION LAYER (unknown orchestrator)  

        │  

        ▼  

SEED ACCOUNTS (~20 accounts)  

@bristol_254, @cosmochoy, @punny_biz, @SeyMonicah,   

@IsajiBrian1, @Ruto_nated, @_EvelynKe, @naledifusion,   

@ke_johnnieh, @Shaccari254, @KKCommetary, @Motiryot_…  

        │  

        │ Post pre-written template messages  

        ▼  

AMPLIFIER ACCOUNTS (~140 accounts)  

“Didmus Barasa Commentary”, “Ruto Stan!”,   

“Speaker Wetangula Commentary”, “UDA Documentation”…  

        │  

        │ Rapid retweet within narrow time windows  

        ▼  

HASHTAG TRENDING TARGET  

#SHAAt28Million → Trend → Counter FOIA narrative  

Network diagram of seed and amplifier accounts for  #SHAAt28Million AND means testing

3.  FAKE ACCOUNT INDICATORS

3.1 Account Profile Flags

The accounts in the data set- to be in word

Indicator Count % of Unique Accounts
No Profile Bio 31 19.6%
Low Followers (<200) 35 22.2%
Hyperactive (≥10 tweets/day) 10 6.3%
High Retweet Rate (≥80%) Multiple
Following > Followers Significant
Not Verified 142 89.9%
Followers < 10 4 2.5%

 

3.2 Notably Suspicious Individual Accounts

Account Tweets Followers Red Flags
Didmus Barasa Commentary 🇰🇪
@khadija34020960
48 819 48 tweets in 1 day; political commentary account
Ruto Stan!
@ruto_nated
34 9,035 “Stan” account explicitly dedicated to ruling party
Speaker Wetangula Commentary
@kijanayabukembe
32 354 Fake commentary on serving politician; only 354 followers
Rolex Rono Kirwogin.
@rolexrono
30 1,488 30 tweets/day
Punny Business
@punny_biz
19 9,868 No bio; high follower count despite no bio
Ebony Ella
@ebonyella372786
6 91 Very low followers; no bio; created 2024–2025
Robin Man 8 3 Only 3 followers; created 2024–2025
Viny Ke
@vinyke356100
8 73 Very low followers; new account
Cyancutie🥰
@cyntty001
7 86 Low followers; new account

3.3 Account Age Analysis

Using Twitter numerical ID ranges as a proxy for account creation dates:

Creation Period Unique Accounts %
2024–2025 (very new) 35 22.2%
2023 44 27.8%
2020–2022 50 31.6%
2013–2019 25 15.8%
Pre-2013 4 2.5%
Total 158 100.0%

 

50% of participating accounts were created in 2023 or later. This is a significant red flag: a disproportionate number of very new or recently-created accounts participating in a single-day coordinated campaign is a classic CIB indicator.

4. COORDINATED INAUTHENTIC BEHAVIOR PATTERNS

4.1 Content Duplication   

The most damning evidence of CIB is the systematic use of identical/near-identical copy-pasted content:

Metric Value
Total tweets 871
Tweets with duplicated content 743
% of tweets with duplicate content 85.3%
Unique content groups where same text was repeated 153
Single message repeated most times 28× (identical)

Most-repeated messages (verbatim copy-paste, multiple accounts):

  1. [28×] “Milestone unlocked! SHA surges to 28 MILLION registrations via Afyangu portal! 28,011,729 Kenyans strong, with ~29K daily…” — @cosmochoy
  2. [19×] “Kenya strengthens SHA adoption with 28,011,729 registrations as Taifa care investments deepen. Means testing reaches 7,319,758…”
  3. [18×] “Huge win for Kenyan health! SHA hits 28 MILLION registrations! 28,011,729 strong & growing with ~29K daily…”
  4. [15×] “A modern system. A reliable process. A healthier country. Kenya is moving with confidence…”
  5. [14×] “Kenyans continue showing strong interest in SHA information sessions…”
  6. [13×] “SHA’s structured means testing ensures Taifa Care benefits genuinely reach households requiring assistance…”
  7. [11×] “With 29,000 daily registrations, Kenyans are signaling confidence in Taifa Care…”
  8. [11×] “SHA’s Means Testing Report shows millions of Kenyans are now properly assessed…”

Organic individuals expressing genuine opinions about healthcare policy do not independently compose identical word-for-word tweets. This pattern is consistent with accounts receiving pre-written message scripts (“tweet templates”) from a coordinating party, or a single operator running multiple accounts.

Screengrab of the identical repeated messages during the campaign

Network Analysis showing 

4.2 Narrative Templates

All campaign content follows a set of pre-approved talking points:

  1. “28 million registrations” milestone celebration
  2. “7.3 million means-tested members” statistic promotion
  3. “29,000–40,000 daily registrations” momentum narrative
  4. “Taifacare is working” / “Taifa care” branding reinforcement
  5. SHA means testing as a positive equity mechanism

Screengrab of Narrative templates used during the campaign.


Bubble chart showing narratives used during the #SHAMeansTesting campaign 

These talking points are consistent with official government/SHA communications, suggesting the campaign may have been organized with coordination from official sources, or by political operatives aligned with the ruling party.

4.3 Political Naming Pattern of Accounts

A striking pattern in account names and bios reveals the campaign’s political character:

  • “UDA Documentation & News @Williamruto supporter”
  • “Ruto Stan!”
  • “Didmus Barasa Commentary 🇰🇪” (Didmus Barasa is a senior UDA MP)
  • “Speaker Wetangula Commentary” (Moses Wetangula is Speaker of the National Assembly, UDA alliance)
  • “Kenya Kwanza Commentary 🇰🇪” (Kenya Kwanza is the ruling coalition)
  • “The Dawn 🇰🇪🇱🇷”  “Political analyst, Online Influencer”

These accounts form a visible network of pro-government amplifiers that participated simultaneously in the campaign.

Multiple posts with hashtag SHAmeans testing shared by Kenya Kwanza Commentary

Multiple posts shared by Ruto stan with the hashtag SHAmeans testing

Network graph showing co-content duplication

5. Language Pattern — English Only Despite Kenyan Campaign

A genuine grassroots Kenyan healthcare discussion would include significant Kiswahili content not English 871 tweets (100%).The absence of Kiswahili is consistent with accounts operating from a shared English-language script, possibly managed by a centralized operation or content farm.

6. GEOGRAPHIC ANOMALIES

Country Tweets %
Kenya 424 48.7%
Unknown 291 33.4%
United States 53 6.1%
Uganda 21 2.4%
Belgium 15 1.7%
Austria 14 1.6%

 

33.4% of tweets have unknown/unverifiable origin. A further 7.7% come from outside Africa entirely (US, Belgium, Austria, Cyprus, Guernsey). For a campaign ostensibly about Kenyan healthcare, significant activity from Europe and North America warrants scrutiny — this pattern is consistent with either VPN use to mask true locations, or diaspora account farm operations.

7. COORDINATION SIGNAL MATRIX

Signal Observed Significance
Exact duplicate content (>1x) 85.3% of tweets 🔴 CRITICAL
Single-day campaign burst All 871 tweets in 13 hours 🔴 CRITICAL
214 tweets in 10-minute window 12:25–12:35 UTC 🔴 CRITICAL
Near-zero negative sentiment (0.23) vs. expected 15–30%+ 🔴 CRITICAL
Pre-written template narratives Identical text across accounts 🔴 CRITICAL
50% accounts created 2023–2025 New accounts for a 1-day campaign 🟠 HIGH
Political naming pattern UDA/Kenya Kwanza aligned names 🟠 HIGH
No Kiswahili in Kenyan campaign 100% English-only 🟠 HIGH
31 accounts with no bio (19.6%) Typical bot/fake ratio 🟠 HIGH
22.2% accounts with < 200 followers Low-reach amplifiers 🟠 HIGH
Timed to FOIA filing date Campaign = response to inquiry 🟡 MEDIUM
33.4% unknown geographic origin VPN/non-Kenyan accounts 🟡 MEDIUM
98.2% unverified accounts Near-total lack of verified voices 🟡 MEDIUM

ERROR BY DESIGN BACKLASH: HOW SHA DEFENDED ITS CONTROVERSIAL MEANS TESTING ALGORITHM” 

Africa Uncensored’s documentary ERROR BY DESIGN examines major weaknesses in Social Health Authority’s AI-driven means testing system, arguing that the model systematically misjudges the economic realities of millions of Kenyans and results in fair health insurance contributions. According to  Lighthouse Reports’ methodology, the  investigation dives into how a machine learning model is being used to set the health insurance premiums of millions of Kenyans. By obtaining the training data and variables, we were able to reconstruct the model in order to test its effectiveness and how it would calculate premiums for different kinds of people.



Flourish chart showing the Prediction of Urban versus Rural


Flourish chart illustrating patterns of poverty misclassification by the SHA means-testing algorithm.

The investigation revealed substantial inaccuracies in the proxy means testing algorithm. It correctly predicted consumption for just 16 percent of the poorest households, while overestimating consumption for 80 percent of them. Among wealthier households, the model performed somewhat better but still underestimated consumption levels for more than 60 percent of households, raising concerns about the fairness of the assessment system. 

Screengrab of Social Health Authority response to Error By Design.

In response, the Social Health Authority on X defended the new model as a necessary reform of the former NHIF contribution structure, which it says disproportionately burdened low-income earners. According to SHA, the previous system required some of the poorest contributors to pay up to 5% of their income, while higher earners contributed as little as 1.12%. The agency maintains that proxy means testing is an internationally recognized approach used in countries such as Colombia and Indonesia, and says the current framework was designed using nationally representative data from approximately 17,000 households to minimize exclusion and inclusion errors. SHA also argues that most households in the informal sector are grouped into lower contribution bands, with safeguards intended to cushion families from inflated estimates. While acknowledging that “no data system is flawless,” the authority says changing household conditions, including job loss, fluctuating income, or the death of a breadwinner, make periodic inaccuracies unavoidable.

At the center of this debate is whether SHA’s appeals and review mechanisms are sufficient to correct the documented inaccuracies. The agency says more than half of formal sector workers experienced reduced premiums under the revised structure and has pledged to strengthen the appeals process through shorter review timelines and Alternative Dispute Resolution mechanisms.

Screengrab of Africa Uncensored’s reply

In a follow-up statement issued after SHA responded to the investigation, Africa Uncensored argued that the Authority had not substantively addressed several questions submitted before publication, particularly regarding the fairness of the means-testing model and the design choices that shaped its outcomes. Africa Uncensored maintained that concerns about the model’s impact on low-income households remained unresolved, fuelling further public debate over whether the system protects vulnerable Kenyans or risks unfairly burdening them.

METHODOLOGY

The dataset analysed for this investigation comprises 871 records scraped from X using hashtag  #SHAAt28Million and “means testing”  The data spans 9th Dec 2025 to 10th Dec 2025 and includes metadata on content type, author handle, posting time, hashtags, engagement metrics (likes, reposts, replies, views), geographic tags, and text content. 

Limitations should be noted: the dataset reflects a hashtag-filtered collection, not a full platform capture. Account creation dates, follower counts, and verification status were unavailable, constraining the ability to identify newly created or bot-like accounts with certainty.

Follow Africa Uncensored’s WhatsApp Channel for verified facts and updates on what’s happening online.  

This article was produced with research by Moffin Njoroge of Code for Africa’s iLab.

Add comment

Your email address will not be published. Required fields are marked *