Open an investment account in South Africa and somebody has to prove that you are you. The Financial Intelligence Centre Act makes that the firm's job rather than yours, which is why a stockbroker wants your identity number, address and bank details before it takes a cent. Peregrine Capital, EasyEquities, Satrix and Bidvest Bank all bought that job in from the same supplier.
The supplier is RelyComply, a South African platform selling automated identity and money-laundering checks since 2020. On 9 September the ransomware group Dire Wolf listed it on a dark web leak site, and over the weekend that followed all four brands wrote to customers about a cyber incident at a third party. Every one of them said its own systems were untouched, and every one of them was telling the truth.
What the one supplier was holding
Peregrine Capital publishes a standing notice on its own site, and its list of what might be exposed reads like the form itself: name, identity, passport or company registration number, date of birth, contact details, residential address and bank account details. None of that can be reissued the way a card can. Peregrine has told the Information Regulator, stopped sending the provider client data, and now wants an extra check before changing anyone's banking details or paying a withdrawal.
Bidvest Bank told its customers only that its data was in the affected environment and should be treated as exposed, and that it would rather say so than wait for the full picture.
Concentrating the thing the law spread out
Buying the check in is ordinary, and until last week it was uncontroversial. Purple Group, which owns EasyEquities, moved to RelyComply in May precisely to replace a scattering of smaller compliance tools with one system that could carry millions of customers. EasyEquities alone has close to 2.9 million users.
Dire Wolf says it took 200GB out of RelyComply's production databases and cloud storage, covering 3.57 billion rows in all. Inside that, it claims 92 million rows of core customer data drawn from 23 organisations it has not listed.
The group's method is to encrypt a victim's systems and steal the data at the same time, then publish in stages if nobody pays. Its leak-site listing gives RelyComply 17 days before the full set goes up, and monitoring service Ransomware.live counts 135 victims worldwide since the group appeared in May 2025.
RelyComply's own newsroom has published nothing since 8 September, the day before the listing. The Information Regulator's most recent public statement is dated 27 August. No cyber-incident announcement from Purple Group, Sanlam, Bidvest Group or Karooooo had reached the exchange by Monday morning. Karooooo's Cartrack confirmed its own Dire Wolf attack on 28 August.
Correction, 15 September 2026: An earlier version of this article listed Cell C Fibre among RelyComply's clients and counted its customer notice among those arising from the RelyComply incident. Cell C has confirmed that the incident affecting its fibre customers involved a different third-party service provider and is unrelated to RelyComply. The article has been amended.