South Africa reports cyber incidents at EasyEquities, Satrix and Cartrack
In South Africa, investment platforms EasyEquities and Satrix warned customers about a cyber incident at a third-party verification service provider, while vehicle tracking company Cartrack confirmed a ransomware attack on part of its systems. As TimesLIVE reports, in Cartrack's case, unauthorized persons gained access to information from the customer database.
Incident at the verification provider
EasyEquities said that its own systems and those of Purple Group had not been compromised. Unauthorized access was obtained by a third party that the platform uses to verify customers in line with regulatory requirements. The potentially affected data is limited to information for KYC identity verification that was provided to this supplier.
The company reported the launch of a forensic investigation, the replacement of API keys and tokens related to integration with the third-party service, and enhanced monitoring. EasyEquities said it had not detected a successful or active threat in its own systems, although its security tools blocked reconnaissance activity. Data on investment assets, trading transactions and account balances are stored separately, and there is no evidence that they were accessed. The company is directly notifying customers who may have been affected by the incident and reporting it to the Information Regulator in accordance with the Popia law.
Satrix also informed users, as EasyEquities is its outsourced provider for the SatrixNOW platform and engages RelyComply for verification procedures. Satrix said there were no signs that SatrixNOW had been compromised, and that account security and the ability to invest had not been affected. The investigation is ongoing, and the final report is not yet available.
More current news is available on the UA.News Telegram channel Telegram.
Attack on Cartrack
Cartrack detected a ransomware incident on August 26 at approximately 02:00. The company said it isolated the affected servers and restored full platform operations by 07:00 on the same day. The Information Regulator and other relevant authorities were notified on August 26, and on August 28 Cartrack issued a public notice following a preliminary investigation.
Further analysis established that information in the customer database had been accessed. It may contain contact details, banking information, as well as certain information about vehicles and driving. The company continues to determine the nature and scope of information that may have been exfiltrated from its systems, has engaged independent cybersecurity specialists, strengthened access controls and asked customers to update their passwords. Cartrack believes the Direwolf ransomware group may have been involved in the attack.
Craig Rosewarne, managing director of Wolfpack Information Risk, called such cases an attack on the digital supply chain: attackers can gain access on a large scale by compromising one supplier that works with several companies. He advised people whose data may have been exposed to monitor bank accounts, enable transaction alerts, regularly check statements, update passwords and use app-based multi-factor authentication.