Four South African financial and telecoms companies told customers over the past weekend that a third-party provider had suffered a cyber incident and their data may be affected. EasyEquities, Cell C Fibre, Bidvest Bank and Peregrine Capital all issued near-identical notices within hours of each other.
Only Peregrine named the provider: RelyComply, a South African-founded compliance platform used to verify client identities under the Financial Intelligence Centre Act.
Interesting insights on the RelyComply breach
The Dire Wolf ransomware gang claimed the attack on its dark web leak site in a post dated 9 September, the same date Cell C gave for the incident. The group says it took 200GB covering 3.57 billion rows from RelyComply's production databases and Amazon S3 storage, including roughly 92 million rows of core customer data, with the bulk drawn from transactions and score matrices belonging to 23 organisations.
Dire Wolf runs a double-extortion model, encrypting systems and stealing data, then publishing if no payment comes. Its listing gives RelyComply 17 days before the full dataset is released. Ransomware(dot)live counts 135 victims claimed by the group worldwide since it emerged in May 2025, and it separately claimed an attack on vehicle tracking firm Cartrack, owned by JSE- and Nasdaq-listed Karooooo, in the past week.
What was exposed varies by customer. Cell C says its affected records were limited to names, email addresses, mobile numbers and account numbers. Peregrine's list is far longer: name, identity, passport or company registration number, date of birth, contact details, residential address and bank account details.
RelyComply confirmed it is investigating a cyber incident but declined to say whether the three unnamed disclosures relate to the Dire Wolf attack.
What others are saying about the RelyComply breach
MyBroadband's Jan Vermeulen connected the four disclosures to a single provider by matching the wording, the timeline and Peregrine's decision to name RelyComply outright. Cell C's notice is the only one specifying which fields were affected. MyBroadband also reported Dire Wolf's claimed attack on Cartrack, which has 2.2 million subscribers, indicating the group is working through South African targets.
Compliance vendors are the new single point of failure
This is the same structure as the Lego breach we covered last month, at far greater scale. Nobody attacked a bank, a broker or a network operator. They attacked the company those businesses all outsourced their FICA checks to, and collected identity documents from every one of them at once.
That is the uncomfortable logic of KYC and anti-money-laundering compliance: the law requires you to collect identity numbers, passports, addresses and bank details, most firms sensibly outsource the verification, and the vendor then holds the most sensitive dataset in the chain while the responsible party under POPIA remains you.
Three practical points. Ask your compliance, payments and verification vendors who else they serve, because concentration is the risk. Get a contractual notification deadline in writing, since customers here found out via a weekend SMS. And note that only one of four companies named the provider, which is a choice each of them made about how much their customers get told.
You might also like our piece on the Lego South Africa data breach and who stays liable under POPIA, the SA banking trojan reading one-time PINs off Android phones, and why AI financial crime in SA keeps outrunning compliance.
Get more SA tech and business news and subscribe to The Open Letter.


