On the weekend of 13 September 2026, three separate South African financial services brands sent notifications to their customers about a potential data breach.
Cell C Fibre notified customers on Saturday evening. EasyEquities sent its notification the same night. Bidvest Bank’s notice came out a few hours earlier. The wording across all three was almost identical: a third-party service provider had experienced a cyber incident, some customer data may be affected, and an investigation was underway.
None of the three named the affected company in their initial disclosures.
By Sunday morning, MyBroadband had identified the common thread. All three notifications traced back to a single organisation: RelyComply, a South African-founded regtech company that provides anti-money laundering, identity verification, transaction monitoring, compliance screening and credential management services to financial institutions.
On 9 September 2026, a ransomware group operating under the name Dire Wolf listed RelyComply on its dark web leak site. Dire Wolf, which emerged in May 2025 and has claimed 135 victims across 13 countries, claimed to have breached RelyComply’s production databases and Amazon S3 cloud storage, alleging the exfiltration of 200 gigabytes of data comprising 3.57 billion rows spanning transactional information and personally identifying information.
These claims are made by the threat actor and remain unverified. RelyComply has confirmed it is investigating a cyber incident, that cybersecurity experts are involved, and that additional security and monitoring measures have been implemented. The investigation is ongoing. RelyComply has not confirmed that attackers accessed or compromised the platform’s functionality, including any risk-rating thresholds, screening criteria, transaction-monitoring logic or information relating to specific compliance decisions. The volume and nature of data alleged by Dire Wolf has similarly not been confirmed as part of the investigation.
RelyComply has 17 days from the posting date to respond before Dire Wolf threatens to publish the full dataset.
What is confirmed and what remains under investigation.
The facts confirmed at the time of writing are as follows. Cell C, EasyEquities and Bidvest Bank all issued breach notifications citing a third-party provider. The timeline of those notifications aligns with the Dire Wolf listing on 9 September 2026. RelyComply has confirmed a cyber incident is under investigation. Ransomware.live, the independent tracking platform that monitors dark web leak sites, confirmed the listing.
Cell C disclosed that, based on information available, the affected records were limited to customer names and identity numbers. EasyEquities and Bidvest Bank did not specify the categories of data potentially affected in their initial notifications. What data belonging to South African customers is specifically included in the claimed breach, and the full scope and impact of the incident, remain subject to RelyComply’s ongoing investigation.
The broader implications of a breach of this nature, should the investigation confirm material data exposure, would depend entirely on what was actually accessed. We flag these possibilities not as confirmed outcomes but as the risk considerations that the financial sector should be examining in parallel with the investigation itself.
Why a regtech breach raises distinctive risk questions.
Most data breaches expose customer records. Names, contact details, ID numbers, account information. The consequences are serious: identity theft, phishing, financial fraud and SIM-swap attacks targeting executives.
A confirmed breach of a compliance and identity verification platform would, if material data exposure is established, raise a different category of risk question. RelyComply provides AML screening, transaction monitoring and identity verification services. Should the investigation confirm that data was accessed, the question of what categories of compliance and identity data were in scope would carry implications beyond those of a conventional customer data breach.
We make this observation not to pre-empt the investigation’s findings but to identify the framework within which organisations using third-party compliance platforms should be assessing their own exposure as the investigation develops.
The third-party risk lesson that keeps arriving and keeps being missed.
The RelyComply incident is the most direct illustration yet of a pattern that has defined South Africa’s breach landscape throughout 2026.
The Liberty breach entered through a third-party connection. Profmed was compromised via PPS Healthcare Administrators. The August ransomware cluster targeted Babcock Africa and The Courier Guy. Now a single regtech platform has simultaneously triggered breach notifications from a mobile operator, an investment platform and a bank through contracts and data-sharing relationships that are entirely routine in the financial services sector.
In each case, the primary organisation’s perimeter defences are not what failed. A trusted third-party relationship was the entry point. The data exposed was data the affected organisations had entrusted to that third party in the ordinary course of doing business.
The 2026 Verizon Data Breach Investigations Report found that third-party involvement appeared in 48% of confirmed breaches globally, up from 30% the prior year and 15% three years ago. The root causes identified consistently across those breaches were insecure authentication, missing or misconfigured MFA, improper credential rotation and lack of least-privilege enforcement. These are not exotic technical vulnerabilities. They are foundational access controls that most organisations apply to their own environments and assume their third-party providers are applying with equal rigour.
That assumption is the gap. And the RelyComply incident, regardless of what the investigation ultimately confirms, has already demonstrated the gap’s practical consequences: three financial services brands issuing breach notifications on the same weekend because of a single third-party event they did not control and, initially, could not fully explain to their own customers.
What POPIA requires that the three affected organisations are now navigating.
Under POPIA’s section 22, a responsible party that becomes aware of a security compromise must notify the Information Regulator and affected data subjects as soon as reasonably possible after discovering the compromise. The duty arises on reasonable grounds to believe a compromise has occurred, not on confirmation of what was specifically taken.
All three organisations that received notifications from RelyComply now face the obligation to assess what data they had with RelyComply, whether that data was in scope of the incident, what data subjects may be affected, and whether they have notified the Regulator within a timeframe it would consider reasonable.
The Information Regulator confirmed at its August 2026 media briefing that it has received 1,220 breach notifications in the current financial year with a projected 3,000 by year end. The SABS enforcement notice published the same month established explicitly that the Regulator will assess the pre-breach compliance posture of organisations it investigates, not only their post-breach response.
For Cell C, EasyEquities and Bidvest Bank, the compliance question extends beyond what the investigation ultimately finds. It includes what contractual and governance controls they had in place with RelyComply, how they verified those controls were functioning, and whether their third-party risk management frameworks would satisfy a regulatory assessment of whether they exercised appropriate oversight of a provider holding sensitive data on their behalf.
The question every South African financial institution should be asking today.
The RelyComply incident did not require a sophisticated attack on three separate financial services organisations. It required a single intrusion into one third-party platform. The downstream exposure reached a mobile operator, an investment platform and a bank simultaneously, through data-sharing relationships that are entirely routine in the financial services sector.
Every South African financial institution that uses a third-party provider for AML screening, identity verification, transaction monitoring or compliance screening should be asking one question today: if that provider experienced a confirmed incident this morning, how quickly would we know, what data do we have with them, and what would we do in the next 48 hours?
The answer to that question is the true measure of a third-party risk management programme. Not the questionnaire sent at onboarding. Not the contract clause assigning data protection responsibility. The operational answer to what happens when a trusted provider is compromised.
South Africa’s financial sector now has a live case study developing in real time. Three brands. One weekend. One shared third-party provider. The investigation is ongoing. The governance questions it raises are not waiting for it to conclude.
SS-Consulting works with South African financial institutions and enterprises to build third-party risk governance programmes that close the gap between contractual assurance and operational verification. www.ss-consulting.co.za

