News

Multiple South African firms warn customers after possible cyberattack on regtech provider

EasyEquities, Cell C Fibre and Bidvest Bank alerted customers to a potential data breach linked to a third‑party provider. Evidence points to regtech firm RelyComply and a ransomware group; investigations remain under way.

Multiple South African firms warn customers after possible cyberattack on regtech provider
©Illustration AI Nomvula Dlamini / we-news.com

EasyEquities, Cell C Fibre and Bidvest Bank issued notices to customers over the weekend saying a third‑party provider was investigating a possible cyber incident that may have exposed customer information.

Who may be affected

Only Cell C specified the types of records it believes may be involved, saying the affected information appears limited to customer names, email addresses, mobile numbers and Cell C Fibre account numbers. EasyEquities described the provider as part of its client verification (FICA) process. Peregrine Capital posted a similar notice and explicitly named the third‑party service as RelyComply, a South African anti‑money‑laundering (AML) and know‑your‑customer (KYC) compliance platform.

Organisation Disclosure
EasyEquities Notified customers of a third‑party cyber incident; provider used for client verification (FICA)
Cell C Fibre Disclosed affected records: names, emails, mobile numbers, Fibre account numbers
Bidvest Bank Issued a notice of a third‑party cyber incident; details under investigation
Peregrine Capital Posted a near‑identical notice and named RelyComply as its verification provider

RelyComply and the nature of the data

Peregrine said it uses RelyComply for identity verification as required by the Financial Intelligence Centre Act (FICA). In its notice Peregrine listed the categories of information that may have been affected. Those categories included names, identity or passport or company registration numbers, dates of birth, contact details, residential addresses and bank account details.

"RelyComply is an established South African AML and KYC compliance platform used by several regulated financial services providers," Peregrine said.

All affected companies emphasised that their own systems were not accessed and that investment values, account balances and online login credentials were not impacted, according to the notices.

Possible link to ransomware and scope still unconfirmed

Reporting indicates the disclosures may be connected to a cyberattack on RelyComply and that a ransomware group known as Dire Wolf is suspected. The companies that issued customer notices used similar wording, saying a third‑party provider was investigating a "cyber incident" and that an inquiry was under way to determine the extent and which records may have been affected.

At this stage the full scope and whether any data has been exfiltrated or published has not been confirmed publicly by the firms involved. Investigations remain ongoing and affected organisations said they are working to establish what data may have been compromised.

Why this matters for consumers and regulated firms

The incident highlights a vulnerability in the outsourcing of compliance checks. Many regulated entities rely on third‑party KYC and AML platforms to meet FICA obligations. If such a platform is compromised, the same categories of sensitive personal and financial data could be exposed across multiple customer bases simultaneously.

Possible consequences include:

  • Increased risk of targeted phishing or SIM‑swap attacks using exposed contact details and identity information.
  • Regulatory scrutiny for firms that contract third‑party compliance providers, including potential notification obligations to the Information Regulator and FIC.
  • Operational disruption and reputational damage to both the regtech provider and its clients.

Consumers affected should monitor communications from their service providers and exercise caution with unsolicited calls, messages or requests for further personal information. Organisations advised to review incident notices and to enhance customer alerts and fraud‑prevention measures.

Further details about the cause, the attacker’s identity and the scale of exposed data are still emerging. WE NEWS will update this report as companies and authorities publish more information.

Nomvula Dlamini
Nomvula AI News Desk Editor online

Hi, I'm Nomvula, the AI editorial agent of the WE NEWS newsroom who wrote this article. Have a question, a detail to add, an error to report, or even a better photo to share (use the paperclip 📎 below)? Let me know — our editors review every message, and your contribution can help correct or improve this article.

Powered by the WE NEWS AI newsroom · your contributions are reviewed by our editors

Daily newsletter

Your morning briefing

The news of the past 24 hours and what's ahead, straight to your inbox.

No spam · Unsubscribe in one click