
South African Firms Face Data Breaches From Third-Party Cyber Incidents
Several companies are blaming third-parties for data breaches. (Image source: iStock) The growing third-party cyber risk has been brought into sharp focus by a fresh wave of incidents involving some of South Africa’s best-known financial and telecommunications brands. EasyEquities, Satrix and Cell C have all warned customers about potential exposure of personal information following incidents involving third-party providers, while Alexforbes has also disclosed a cyber incident affecting its environment. The incidents show the attack surface facing South African organisations is no longer confined to their own infrastructure. EasyEquities and Satrix have said their investment platforms were not compromised, with the exposure linked to a third-party verification provider. Cell C, meanwhile, says its potential customer- data exposure relates to a separate third-party. “Alexforbes can confirm a data security incident involving one of the company’s third-party suppliers, RelyComply, which provides Alexforbes with specialist services relating to anti-money-laundering, customer screening and risk assessment,” says the company in a statement to ITWeb. “Regrettably, preliminary investigations confirm that some identity-related information of Alexforbes’s clients may have been accessed by a malicious threat actor as a result of this cyber incident.” According to the company, its own internal IT systems, financial platforms and networks remain secure and uncompromised. It adds that this incident occurred exclusively within the third-party supplier’s IT environment. It says from the moment Alexforbes was alerted to this situation, it mobilised its incident response team to contain and manage the incident. Alexforbes says it immediately suspended all data sharing and operations with third-party supplier RelyComply following the incident. The financial services group points out that screening services were subsequently reinstated after forensic sign-off, completion of the required security checklist and replacement of access credentials. Alexforbes adds it has formally notified the relevant regulatory authorities about the incident. Meanwhile, RelyComply has appointed independent forensic specialists to investigate what happened and remains engaged in an ongoing investigation. Alexforbes notes it remains in close contact with the supplier and is monitoring developments as further information emerges. In a note to customers, investment platform EasyEquities says a security incident at a third-party service provider that supports parts of its client identification and verification processes did not involve unauthorised access to its own or parent company Purple Group’s systems. The provider confirmed on 10 September that an unauthorised party had gained access to its environment, prompting EasyEquities to activate its incident response process and disable the integration the following day. According to EasyEquities’ note to customers, personal information potentially affected includes clients’ full names, identity information, dates of birth, gender, nationality, country of residence and account numbers. The company says its internal investigation found no evidence of compromise within its systems, while a 30-day retrospective threat hunt identified only reconnaissance activity that was blocked by perimeter controls. EasyEquities adds that it rotated affected keys and API tokens, engaged independent cyber security specialists, increased monitoring and reported the incident to the Information Regulator under the Protection of Personal Information Act. It warns affected customers to be alert to phishing, impersonation, scam calls and other fraudulent attempts using their personal information, and advised customers not to share credentials or personal information with anyone claiming to represent the company. According to Cell C, the incident did not originate within its systems. “It occurred within the environment of a third-party service provi
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Finish Reading the Full Story and the Expert Analysis.
Get the latest legal & regulatory intelligence in South Africa
Wansom is AI and can make mistakes.
