Legal News

Alexforbes: RelyComply Data Breach Raises POPIA Concerns

South Africa·Briefly Analysis⏱️ 5 min read

Summary

  • Multiple prominent South African firms, including Alexforbes, EasyEquities, and Cell C, have recently experienced data breaches linked to third-party service providers.
  • Alexforbes's incident involved its supplier RelyComply, leading to potential access of client identity-related information by a malicious actor.
  • EasyEquities reported a security incident at a third-party verification provider, potentially exposing client personal data such as names, identity details, and account numbers.
  • Both Alexforbes and EasyEquities took immediate action, including suspending operations with the affected third parties and notifying regulatory authorities under the Protection of Personal Information Act (POPIA).
  • These incidents highlight a growing trend where the cyber attack surface for South African entities extends beyond their own systems to their external vendors.

Third-Party Breaches Hit South African Firms

The series of recent cyber incidents underscores a critical shift in the threat landscape for South African organizations, demonstrating that the attack surface now extends significantly beyond their internal infrastructure to encompass third-party service providers.

A series of recent cyber incidents has brought the escalating risk posed by third-party vendors into sharp focus for several prominent South African financial and telecommunications entities. Companies such as EasyEquities, Satrix, and Cell C have alerted their customers to potential exposures of personal information, with each incident traced back to external service providers. This trend highlights a significant expansion of the cyber attack surface, indicating that organizations' vulnerabilities are no longer confined solely to their own internal systems and infrastructure.

Among the affected, Alexforbes confirmed a data security incident involving RelyComply, a third-party supplier that provides specialized services including anti-money-laundering, customer screening, and risk assessment. Preliminary investigations revealed that a malicious threat actor may have accessed identity-related information belonging to Alexforbes's clients. The financial services group clarified that its own internal IT systems, financial platforms, and networks remained secure and uncompromised, with the incident occurring exclusively within RelyComply's IT environment.

Upon learning of the breach, Alexforbes promptly mobilized its incident response team, suspending all data sharing and operations with RelyComply to contain and manage the situation. Screening services were subsequently reinstated only after a thorough forensic sign-off, completion of a required security checklist, and the replacement of access credentials. Alexforbes has formally notified the relevant regulatory authorities and remains in close communication with RelyComply, which has appointed independent forensic specialists to investigate the matter further.

EasyEquities and Cell C Incidents

Investment platform EasyEquities also disclosed a security incident at a third-party service provider responsible for parts of its client identification and verification processes. The company assured customers that its own systems, as well as those of its parent company Purple Group, were not subject to unauthorized access. The third-party provider confirmed on September 10 that an unauthorized party had gained access to its environment, prompting EasyEquities to activate its incident response protocol and disable the integration the following day.

The personal information potentially affected in the EasyEquities incident includes clients' full names, identity information, dates of birth, gender, nationality, country of residence, and account numbers. EasyEquities' internal investigation found no evidence of compromise within its systems, and a 30-day retrospective threat hunt identified only reconnaissance activity that was successfully blocked by perimeter controls. In response, the company rotated affected keys and API tokens, engaged independent cybersecurity specialists, and increased monitoring.

Separately, telecommunications provider Cell C reported a potential customer-data exposure that also originated within the environment of a third-party service provider, not within its own systems. These incidents collectively underscore the pervasive nature of third-party cyber risks across diverse sectors in South Africa.

Regulatory Context and Customer Advisories

The incidents have triggered necessary regulatory responses, particularly under South Africa's Protection of Personal Information Act (POPIA). EasyEquities, for instance, reported its incident to the Information Regulator, fulfilling its obligations under POPIA. Alexforbes similarly notified relevant regulatory authorities, demonstrating adherence to data breach reporting requirements in South Africa.

In light of the potential data exposure, EasyEquities issued a warning to its affected customers, advising them to be vigilant against phishing, impersonation attempts, scam calls, and other fraudulent activities that might exploit their personal information. The company also cautioned customers against sharing credentials or personal information with anyone claiming to represent EasyEquities, emphasizing the importance of robust personal security practices in the wake of such cyber incidents. This proactive communication is crucial for mitigating the downstream impact on individuals whose data may have been compromised.

Why It Matters: Expanding Attack Surface

The series of recent cyber incidents underscores a critical shift in the threat landscape for South African organizations, demonstrating that the attack surface now extends significantly beyond their internal infrastructure to encompass third-party service providers. This reality means that even companies with robust internal security measures can be vulnerable through their supply chain, highlighting the importance of stringent POPIA third-party vendor risk management.

The responses from Alexforbes and EasyEquities — including immediate suspension of operations with affected vendors, engagement of forensic specialists, and enhanced security protocols — illustrate the urgent need for organizations to implement comprehensive strategies for managing external cyber risks. These incidents serve as a stark reminder for businesses to critically evaluate their third-party contracts, ensuring that data security clauses, incident response protocols, and due diligence processes are robust enough to withstand sophisticated cyber threats originating from outside their direct control.

Practical Implications

This series of incidents underscores the critical need for South African legal and compliance teams to urgently review and strengthen their organisations' third-party vendor contracts and data processing agreements. Lawyers should advise clients on ensuring robust data security clauses, clear incident response protocols, and stringent due diligence are in place to mitigate POPIA compliance risks and potential liability stemming from supplier-originated data breaches.

Source

Source: Reporting based on recent industry disclosures.

Get Deeper AI analysis

How does this affect you?

Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.

Finish Reading the Full Story and the Expert Analysis.

Get the latest legal & regulatory intelligence in South Africa

Instant access to full analysis, cited statutes & expert commentary
Customize your dashboard to track what matters to your business operations

Already have an account? Log in

Wansom is AI and can make mistakes.