Cartrack has told South African regulators that intruders reached its customer records, turning an August ransomware event into a formal privacy case.
The vehicle tracking company said it spotted ransomware at about 2am on August 26 and had its platform running again by 7am. It alerted the Information Regulator that same day and published a notice on August 28. Deeper analysis showed the customer database had been opened. Contact details, bank account information and vehicle or driving data may all be involved.
Regulators are now involved. Cartrack filed a preliminary notification under Section 22 of the Protection of Personal Information Act, and the Information Regulator confirmed this week that an investigation is under way. Hangi Mbedzi, the office’s acting senior manager for compliance and monitoring, said the filing is still being studied. Notices of this kind are meant to record how many people a breach touched, and how it happened.
A crew calling itself Direwolf has claimed the intrusion on a dark web leak site, saying it took 500GB. Cartrack has not confirmed that figure. Its investigation, run with outside specialists, is still working out what left the network.
The timing puts two South African incidents in one news cycle. EasyEquities and Satrix both warned clients about a shared identity-verification supplier that was compromised, even though neither firm’s own systems were touched.
Craig Rosewarne of Wolfpack Information Risk called the pattern a hub-and-spoke attack. Rather than hitting many firms one at a time, criminals take one supplier that already holds data for all of them.
For drivers, the exposed mix is uncomfortable. A tracking account links a person to a vehicle, a home address and a payment method, which is enough to build a convincing phishing lure. Regulators can fine a company. They cannot put the data back.