CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

Boston police tested Motorola and Axon readers as Flock exited

Cybersecurity

Leapmotor EVs carry cameras from a supplier Australia banned

Policy & Compliance

BYD rewrites Australian privacy policy after Four Corners questions

Cybersecurity

A passwordless port let a researcher command a moving BYD ute

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

Fleet tracker Cartrack draws a South African privacy probe after August ransomware

South Africa's Information Regulator is investigating how ransomware reached Cartrack's customer database in August, with a crew called Direwolf claiming 500GB.

CarThreat Staff
Last updated: September 19, 2026 1:36 am
By
ctadmin
2 Min Read
Anime illustration of a fleet van whose rooftop telematics signal breaks apart
SHARE

Cartrack has told South African regulators that intruders reached its customer records, turning an August ransomware event into a formal privacy case.

The vehicle tracking company said it spotted ransomware at about 2am on August 26 and had its platform running again by 7am. It alerted the Information Regulator that same day and published a notice on August 28. Deeper analysis showed the customer database had been opened. Contact details, bank account information and vehicle or driving data may all be involved.

Regulators are now involved. Cartrack filed a preliminary notification under Section 22 of the Protection of Personal Information Act, and the Information Regulator confirmed this week that an investigation is under way. Hangi Mbedzi, the office’s acting senior manager for compliance and monitoring, said the filing is still being studied. Notices of this kind are meant to record how many people a breach touched, and how it happened.

A crew calling itself Direwolf has claimed the intrusion on a dark web leak site, saying it took 500GB. Cartrack has not confirmed that figure. Its investigation, run with outside specialists, is still working out what left the network.

The timing puts two South African incidents in one news cycle. EasyEquities and Satrix both warned clients about a shared identity-verification supplier that was compromised, even though neither firm’s own systems were touched.

Craig Rosewarne of Wolfpack Information Risk called the pattern a hub-and-spoke attack. Rather than hitting many firms one at a time, criminals take one supplier that already holds data for all of them.

For drivers, the exposed mix is uncomfortable. A tracking account links a person to a vehicle, a home address and a payment method, which is enough to build a convincing phishing lure. Regulators can fine a company. They cannot put the data back.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Connected VehiclesCybersecurityData PrivacyRegulationsTelematics Control Units (TCU)Threat Intelligence
SOURCES:SABC NewsTimesLIVE
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

Hacker crew rips a Flock camera apart and unlocks its video

By
ctadmin
September 17, 2026
Cybersecurity

License plate camera firm locks down vehicle data after abuse reports

By
ctadmin
August 17, 2026
Cybersecurity

Boston police tested Motorola and Axon readers as Flock exited

By
ctadmin
September 21, 2026
Cybersecurity

Chinese lidar faces federal review as lawmakers push bans

By
ctadmin
August 23, 2026
Cybersecurity

First car head unit malware hides inside Android update channel

By
ctadmin
August 22, 2026
Policy & Compliance

BYD rewrites Australian privacy policy after Four Corners questions

By
ctadmin
September 21, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • Bluetooth Security
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Pwn2Own Automotive
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?