Bidvest Bank, EasyEquities and Cell C: Cell C, EasyEquities,Bidvest Bank warn customers of data leak

Bidvest Bank, EasyEquities and Cell C: Cell C, EasyEquities,Bidvest Bank warn customers of data leak

South African Companies Hit by Third-Party Cybersecurity Breach Affecting Customer Data

South African telecom operator Cell C, investment platform EasyEquities, and Bidvest Bank have notified customers of a cybersecurity incident at an unnamed third-party service provider, potentially exposing sensitive personal information.

Cell C alerted customers of its subsidiary, Cell C Fiber, on September 9, 2026, after the service provider detected a breach involving compromised access credentials. The exposed data includes customer names, email addresses, mobile numbers, and account numbers, though the company stated that no financial or password details were affected. Cell C has activated its incident response protocols and is collaborating with cybersecurity specialists to contain the breach and investigate further.

EasyEquities confirmed that a third-party vendor responsible for regulatory verification checks may have compromised customer data. While the company’s trading and investing systems remain secure, it is working with the provider to assess the extent of the exposure. No evidence suggests that Purple Group Limited (EasyEquities’ parent company) or client accounts were directly impacted.

Bidvest Bank also disclosed a breach at a third-party service provider but did not specify the exposed data or the vendor involved. The bank confirmed that its data was stored in the affected environment and is treating it as potentially compromised. An independent forensic investigation is underway to determine the scope of the breach.

This incident follows a March 2026 data leak at Standard Bank, where client and company-related data was published online after a February cyberattack. Additionally, in 2025, both Cell C and MTN suffered breaches that exposed customer information, highlighting ongoing cybersecurity challenges in South Africa’s financial and telecom sectors.

Source: https://www.connectingafrica.com/cybersecurity/sa-s-cell-c-easyequities-and-bidvest-bank-warn-customers-of-data-leak

Cellnex Telecom cybersecurity rating report: https://www.rankiteo.com/company/cellnextelecom

Bidvest Bank Limited cybersecurity rating report: https://www.rankiteo.com/company/bidvest-bank-limited

EasyEquities cybersecurity rating report: https://www.rankiteo.com/company/easyequities

"id": "CELBIDEAS1789412546",
"linkid": "cellnextelecom, bidvest-bank-limited, easyequities",
"type": "Breach",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Telecommunications',
                        'location': 'South Africa',
                        'name': 'Cell C Fiber',
                        'type': 'Telecom Subsidiary'},
                       {'industry': 'Financial Services',
                        'location': 'South Africa',
                        'name': 'EasyEquities',
                        'type': 'Investment Platform'},
                       {'industry': 'Banking',
                        'location': 'South Africa',
                        'name': 'Bidvest Bank',
                        'type': 'Bank'}],
 'attack_vector': 'Compromised access credentials',
 'customer_advisories': 'Yes',
 'data_breach': {'personally_identifiable_information': 'Names, email '
                                                        'addresses, mobile '
                                                        'numbers, account '
                                                        'numbers',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': 'Personal Information'},
 'date_detected': '2026-09-09',
 'date_publicly_disclosed': '2026-09-09',
 'description': 'South African telecom operator Cell C, investment platform '
                'EasyEquities, and Bidvest Bank have notified customers of a '
                'cybersecurity incident at an unnamed third-party service '
                'provider, potentially exposing sensitive personal '
                'information.',
 'impact': {'brand_reputation_impact': 'High',
            'data_compromised': 'Customer names, email addresses, mobile '
                                'numbers, account numbers',
            'identity_theft_risk': 'High',
            'payment_information_risk': 'None (reported)'},
 'investigation_status': 'Ongoing',
 'references': [{'source': 'Incident disclosure by Cell C, EasyEquities, and '
                           'Bidvest Bank'}],
 'response': {'communication_strategy': 'Customer notifications',
              'containment_measures': 'Collaborating with cybersecurity '
                                      'specialists to contain the breach',
              'incident_response_plan_activated': 'Yes',
              'third_party_assistance': 'Cybersecurity specialists'},
 'title': 'South African Companies Hit by Third-Party Cybersecurity Breach '
          'Affecting Customer Data',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.