Thursday, 24 September 2026
ZAR/USDR16.440.54%. Rand weaker against the US dollar
ZAR/EURR18.680.17%. Rand weaker against the euro
ZAR/GBPR21.730.13%. Rand weaker against the pound
Tech & Telco

One hacked compliance vendor has put clients of at least six South African financial firms on alert

One hacked compliance vendor has put clients of at least six South African financial firms on alert

A single breach at a company most South Africans have never heard of has forced a stockbroker, a hedge fund, an ETF provider, a home loan lender and at least two banks to warn clients that their personal information may be in criminal hands. The company is RelyComply, a South African regtech firm that runs anti-money laundering and know-your-customer checks for regulated financial services providers.

On 9 September the Dire Wolf ransomware group listed RelyComply on its dark web leak site and claimed it had stolen 200GB of data from the company’s production database and Amazon S3 cloud storage, MyBroadband reported. The gang says the haul runs to 3.57 billion rows, including 92 million rows of customer identity information. Those figures are the attacker’s own claims and have not been independently verified.

“RelyComply is aware of a cyber incident affecting customers and is currently investigating the matter with the utmost priority,” the company said.

Who has said what

EasyEquities, Peregrine Capital, Satrix and SA Home Loans have confirmed that their clients’ data may have been accessed through the incident. EasyEquities said the breach occurred at a vendor involved in its client verification process in line with regulatory obligations, and that it had found no evidence that its own systems or those of its parent, Purple Group, had been compromised. Peregrine Capital said investment values, account balances and online login credentials are held on its own systems and were not involved.

Bidvest Bank has notified customers that a third-party service provider had confirmed Bidvest Bank data was held in the affected environment and should be treated as potentially affected, Connecting Africa reported, although the bank has not named the provider. Standard Bank said its specialist teams were working closely with the service provider to establish the scope of the incident and any potential impact on the bank and its clients, MyBroadband reported.

SA Home Loans’ notice shows what a KYC file contains. It said the data involved could include full names, identity or passport numbers, gender, date of birth, email addresses, cellphone numbers, the address of the property on loan, country of residence, citizenship, derived income, politically exposed person status and employer details. The lender said the breach occurred on 2 September, was identified on 8 September, and that it was notifying clients on a precautionary basis, which “should not be interpreted as confirmation that any individual’s information was accessed, compromised or misused”.

Cell C also warned customers during the same week, but its incident involved a different third party supporting Cell C Fibre, where compromised access credentials exposed customer names, email addresses, mobile numbers and account numbers.

Why one vendor reached so many brands

The Financial Intelligence Centre Act requires financial institutions to verify who their clients are, and many outsource that work to specialist platforms. That is efficient, but it concentrates the most sensitive data a financial firm holds, identity documents, income and screening results, in a small number of suppliers. A firm can secure its own systems well and still find its clients exposed because a vendor was breached.

The timing fits a wider pattern. In the past month Hungry Lion, the Furniture Bargaining Council, CarTrack, Serengeti Estates and Toyota South Africa have also reported cybersecurity incidents, and Rand Water disclosed an incident on 3 September, Daily Maverick reported. Dire Wolf has separately claimed a breach of CarTrack. Daily Maverick, citing Sophos research, reported that 85% of South African ransomware victims said the breach was linked to an identity compromise, against 67% globally.

What affected clients and businesses should do

The immediate risk for individuals is not that someone empties an account with this data alone, but that criminals use real identity details to make phishing calls, emails and SIM swap attempts more convincing. Clients of the affected firms should treat any unexpected contact that quotes their personal details with suspicion, and can apply for free protective registration with the Southern African Fraud Prevention Service, which flags their identity number to participating lenders.

For businesses, the lesson is about suppliers. Firms that hand customer data to a vendor should know exactly what that vendor stores, for how long, and how quickly it will tell them about an incident, and should check that the contract says so. Section 22 of the Protection of Personal Information Act requires the responsible party to notify the Information Regulator and affected people as soon as reasonably possible after a compromise, and that obligation does not transfer to the supplier.

For more on technology risk and South African business, see our Tech & Telco coverage.