EasyEquities, Cell C Fibre and Bidvest Bank issued notices to customers over the weekend saying a third‑party provider was investigating a possible cyber incident that may have exposed customer information.
Who may be affected
Only Cell C specified the types of records it believes may be involved, saying the affected information appears limited to customer names, email addresses, mobile numbers and Cell C Fibre account numbers. EasyEquities described the provider as part of its client verification (FICA) process. Peregrine Capital posted a similar notice and explicitly named the third‑party service as RelyComply, a South African anti‑money‑laundering (AML) and know‑your‑customer (KYC) compliance platform.
| Organisation | Disclosure |
|---|---|
| EasyEquities | Notified customers of a third‑party cyber incident; provider used for client verification (FICA) |
| Cell C Fibre | Disclosed affected records: names, emails, mobile numbers, Fibre account numbers |
| Bidvest Bank | Issued a notice of a third‑party cyber incident; details under investigation |
| Peregrine Capital | Posted a near‑identical notice and named RelyComply as its verification provider |
RelyComply and the nature of the data
Peregrine said it uses RelyComply for identity verification as required by the Financial Intelligence Centre Act (FICA). In its notice Peregrine listed the categories of information that may have been affected. Those categories included names, identity or passport or company registration numbers, dates of birth, contact details, residential addresses and bank account details.
"RelyComply is an established South African AML and KYC compliance platform used by several regulated financial services providers," Peregrine said.
All affected companies emphasised that their own systems were not accessed and that investment values, account balances and online login credentials were not impacted, according to the notices.
Possible link to ransomware and scope still unconfirmed
Reporting indicates the disclosures may be connected to a cyberattack on RelyComply and that a ransomware group known as Dire Wolf is suspected. The companies that issued customer notices used similar wording, saying a third‑party provider was investigating a "cyber incident" and that an inquiry was under way to determine the extent and which records may have been affected.
At this stage the full scope and whether any data has been exfiltrated or published has not been confirmed publicly by the firms involved. Investigations remain ongoing and affected organisations said they are working to establish what data may have been compromised.
Why this matters for consumers and regulated firms
The incident highlights a vulnerability in the outsourcing of compliance checks. Many regulated entities rely on third‑party KYC and AML platforms to meet FICA obligations. If such a platform is compromised, the same categories of sensitive personal and financial data could be exposed across multiple customer bases simultaneously.
Possible consequences include:
- Increased risk of targeted phishing or SIM‑swap attacks using exposed contact details and identity information.
- Regulatory scrutiny for firms that contract third‑party compliance providers, including potential notification obligations to the Information Regulator and FIC.
- Operational disruption and reputational damage to both the regtech provider and its clients.
Consumers affected should monitor communications from their service providers and exercise caution with unsolicited calls, messages or requests for further personal information. Organisations advised to review incident notices and to enhance customer alerts and fraud‑prevention measures.
Further details about the cause, the attacker’s identity and the scale of exposed data are still emerging. WE NEWS will update this report as companies and authorities publish more information.