RelyComply cyber incident: what happened and what you can do
Published 16 September 2026. Last updated 16 September 2026. We will update this page as the investigation progresses.
On 8 September 2026, RelyComply became aware of a cyber incident affecting part of the environment where it processes data for some of its customers. RelyComply provides regulatory compliance technology and services to its customers, including financial institutions.
This notice is for anyone whose personal information may have been affected. It sets out what we know, what we have done, and the steps you can take to protect yourself.
What happened?
RelyComply has identified through investigations to date that an unauthorised third party appears to have exploited a zero-day vulnerability in a third-party application to gain access to certain RelyComply systems that hold customer data. RelyComply immediately activated its incident response processes and engaged independent legal advisors and a specialist digital forensics firm to investigate and assist with the response.
What has RelyComply done in response?
We can confirm the following steps have been taken:
- Affected systems were immediately taken offline, and the environment was fully reset and rebuilt before core services were brought back online.
- All access credentials across the environment have been rotated.
- Customers were asked to rotate their RelyComply API tokens, and a refresh of single sign-on identity provider configurations was coordinated.
- Enhanced monitoring, logging, and alerting capabilities have been implemented across the environment.
- The zero-day vulnerability in the third-party application has been patched.
- Vulnerability monitoring has been implemented across the environment, and all identified vulnerabilities have been addressed.
- Additional security controls have been implemented for credential management and the external attack surface, rendering the original attack path unusable.
- Independent forensic specialists continue to conduct a thorough review, and further security enhancements are being implemented in consultation with them and our security advisors.
Has the incident been contained?
Based on the evidence reviewed to date, the measures implemented by the RelyComply team have stopped the unauthorised access. Continuous monitoring since those measures were put in place has not shown any unauthorised activity.
The forensic investigation is ongoing, and we will update this notice if that position changes.
Was my bank’s or my service provider’s own system affected?
This incident affected a part of RelyComply’s environment only, the investigation has not shown any evidence of impact on or movement into any customer’s own network environment.
Who was responsible?
As is common with cyber incidents of this nature, it is not possible to identify the individuals behind this attack.
Have RelyComply’s customers been notified?
RelyComply has notified all affected customers so that they can, in turn, inform their own customers, partners, and data subjects who may have been impacted. If your service provider has notified you that you may have been affected by this incident, the steps below can help you protect yourself.
Has the breach been reported to the Information Regulator?
RelyComply has reported the incident to the Information Regulator of South Africa under reference number SC20263150 and is cooperating fully with the authorities.
What should I do?
Whether or not you have been notified by your service provider that your personal information may have been affected, we encourage you to take the following protective steps as a precaution:
- Monitor your bank accounts closely for any unusual or unauthorised activity. Report any suspicious transactions to your bank immediately.
- Contact your bank to inform them that your details may have been compromised and to request enhanced monitoring or additional security measures for your account.
- Register with the Southern African Fraud Prevention Service (SAFPS) for free identity fraud protection at www.safps.org.za.
- Be alert to suspicious communications. Be wary of any unsolicited emails, telephone calls, or SMS messages that ask for personal or financial information.
- Do not share your PIN, passwords, or OTPs in response to any unsolicited communication. Legitimate organisations will never ask you for these details by email, SMS, or telephone.
- Review your credit report for any unfamiliar accounts or enquiries.
- Update your passwords on any accounts where you may have reused credentials.
- Enable multi-factor authentication wherever it is available.
Nobody has contacted me. Could I still be affected?
The investigation is still underway, and affected customers are in the process of carrying out notifications. Please be aware that, in terms of applicable law, a notice may be posted on your service provider’s website rather than you receiving direct communication.
What happens next?
Protecting the data entrusted to us is a responsibility we take seriously. The independent forensic investigation is ongoing, and we will continue to work with our legal advisors and forensic experts to take all necessary measures. We will provide further updates as appropriate.
If you have questions about this incident, please contact your service provider directly or us at incident@relycomply.com.