Skip to content
Under attack?Get emergency help now
All articles
14 September 2026F1 IT Solutions

Four Breach Notices, One Shared Vendor

Third-Party RiskVendor RiskRansomwarePOPIACybersecuritySouth Africa

Over the weekend of 12 and 13 September, four South African financial and telecoms brands told their customers much the same thing. A third-party provider had suffered a cyber incident, an investigation was underway, and some customer data might be affected.

Bidvest Bank went first. Cell C and EasyEquities followed on the Saturday evening. The notices were near identical in wording, and none of the three named the provider.

It was Peregrine Capital, reported by MyBroadband to have posted a very similar notice, that named it outright: RelyComply, a South African anti-money-laundering and KYC compliance platform used by regulated financial services providers to verify client identities under FICA.

None of these four businesses was breached. Their own systems, by their own accounts, were untouched. They are all writing to customers anyway, because they all handed the same job to the same supplier.

What has been claimed, and what is confirmed

It is worth separating those two things, because the picture is still incomplete.

Confirmed by the companies themselves: four firms issued customer notices about a third-party cyber incident. Cell C said the records involved appeared limited to names, email addresses, mobile numbers and Cell C Fibre account numbers. Peregrine said the information affected may include name, identity, passport or company registration number, date of birth, contact details, residential address and bank account details. RelyComply has confirmed it is aware of a cyber incident and is investigating with cybersecurity experts, but declined to confirm whether the four disclosures relate to it.

Claimed, and not independently verified: the Dire Wolf ransomware group posted a listing dated 9 September claiming it breached RelyComply's production databases and cloud storage, and that it took roughly 200GB covering billions of rows, including tens of millions of rows of core customer identity data drawn from more than twenty organisations. Ransomware gangs inflate their numbers, so treat the volumes as marketing until somebody credible verifies them. What is harder to dismiss is the timing, which lines up with the date Cell C gave its customers.

Dire Wolf runs a double extortion model: encrypt, steal, then threaten publication if the ransom is not paid, and the listing carries a countdown. The same group claimed an attack on a large South African vehicle tracking business days earlier.

The real story is concentration, not compromise

Every business accepts that a supplier might be breached. What this weekend illustrated is sharper. When many companies in one regulated sector converge on a single specialist provider, that provider quietly becomes systemically important, and nobody sets out to make it so.

FICA and RICA obligations push firms towards specialist platforms. Building identity verification in-house is expensive and easy to get wrong, so buying it is the sensible commercial decision, and it is the decision nearly everyone makes. The result is that a market full of competitors ends up sharing a single point of failure, and none of them can see the others stacked up behind it.

That concentration also inverts the usual logic of attacker economics. Breaching one mid-sized compliance platform is far cheaper than breaching twenty banks and brokerages, and the payload is better, because a KYC provider holds precisely the verified identity documents an attacker would otherwise have to assemble.

Which brings us to the part that does not wash off. A leaked password is an inconvenience; you reset it. A leaked ID number, date of birth, residential address and bank account number cannot be reissued. That data supports identity fraud and highly convincing impersonation for years, and every customer of every affected brand now carries that exposure whether or not a cent moves.

What to actually do about it

None of this argues for bringing compliance in-house. It argues for knowing what you have outsourced, which most businesses do not.

Map your fourth parties, not just your third parties. You probably have a list of your suppliers. You almost certainly do not have a list of who they depend on. Ask each critical vendor which subprocessors touch your customer data, and where those subprocessors overlap across your other suppliers. Overlap is the thing to look for.

Treat onboarding checks as a starting point, not the control. A security questionnaire signed at contract time tells you about a vendor on one day, years ago. Posture drifts. This is exactly the gap continuous monitoring is meant to close, and it is why we run third-party risk management as an ongoing service rather than a once-off assessment. The wider case for that approach is in our guide to managing third-party vendor risk.

Write the notification path down before you need it. Under POPIA you remain the responsible party even when your operator was the one breached, so the duty to notify the Information Regulator and affected data subjects lands on you, on facts you do not control and cannot verify quickly. Decide now who drafts the notice, who signs it off, and what you will say while the vendor is still investigating. Our POPIA compliance checklist covers the obligations; the speed with which you meet them is an incident response question.

Contract for information, not just for liability. Most vendor agreements cover who pays if things go wrong. Far fewer commit the vendor to telling you what happened, within a defined window, in enough detail to meet your own regulatory clock. Ask for that explicitly at renewal.

A takeaway

Four companies did nothing wrong on their own networks and still spent a weekend writing to customers. That is worth sitting with, because it is not a story about weak security. It is a story about a dependency none of them had mapped.

The useful question this week is not whether your suppliers are secure. It is whether you could name, today, every outside party holding your customers' identity data, and which of your suppliers are quietly relying on the same one.

Reporting on this incident by Jan Vermeulen for MyBroadband, 13 September 2026. Details remain subject to ongoing investigation.

Want this handled for you?

Talk to the F1 team about cybersecurity, AI and managed IT for your business.