Latest white paper on evolving regulations and emerging technologies

  • Industry perspective: The key forces driving AML reform in 2025 and beyond.

  • Operational insight: How automation is reshaping onboarding and accuracy.

  • Strategic value: Where collaboration is unlocking the next era of compliance.

Access White Paper
relycomply whitepaper

Get updates that matter

Stay connected with:

  • Industry insights - Reports on trends, threats, and regulatory shifts shaping the financial services world.

  • Customer highlights - See how businesses like yours are closing AML gaps and protecting their customers.

  • Feature releases - Discover the latest products and AI-powered capabilities in our platform.

relycomply whitepaper

RelyComply data breach: what happened and what affected users should know

Published 16 September 2026. Last updated 16 September 2026. We will update this page as the investigation progresses.

RelyComply recently became aware of a data security incident affecting part of its environment where it processes data for its customers. RelyComply provides regulatory compliance technology and services to its customers, including financial institutions. 

We understand this may cause concern, and we want to provide you with clear, factual information about what we know, what we have done, and steps you can take to protect yourself if your personal information may have been affected. 

What happened?

On 8 September 2026, RelyComply became aware of a data breach affecting part of the environment where it processes data for its customers. RelyComply provides regulatory compliance technology and services to its customers, including financial institutions. POPIA refers to such an incident as a security compromise.

This notice is for anyone whose personal information may have been affected, whether or not you have received a notification from a bank, insurer or other organisation. It sets out what we know, what we have done, what information may have been involved, and the steps you can take to protect yourself.

What has RelyComply done in response?

The following steps have been completed since the incident was identified:

  • Affected systems were immediately taken offline, and the environment was fully reset and rebuilt before core services were brought back online.
  • All access credentials across the environment have been rotated.
  • Customers were asked to rotate their RelyComply API tokens, and a refresh of single sign-on identity provider configurations was coordinated.
  • Enhanced monitoring, logging, and alerting capabilities have been implemented across the environment.
  • The zero-day vulnerability in the third-party application has been patched.
  • Vulnerability monitoring has been implemented across the environment, and all identified vulnerabilities have been addressed.
  • Additional security controls have been implemented for credential management and the external attack surface, rendering the original attack path unusable.
  • Independent forensic specialists continue to conduct a thorough review, and further security enhancements are being implemented in consultation with them and our security advisors.

Has the breach been contained?

The investigation confirms that the measures implemented by the RelyComply team have contained the threat. Continuous monitoring following the remedial actions has not shown any active exploitation beyond the initial point of containment. There is no evidence suggesting lateral movement or direct access to any RelyComply client’s network environment.

Have RelyComply’s customers been notified?

RelyComply has notified all affected customers so that they can, in turn, inform their own customers, partners, and data subjects who may have been impacted. If your service provider has notified you that you may have been affected by this incident, the steps below can help you protect yourself.

The incident has been reported

RelyComply has reported the incident to the Information Regulator of South Africa under reference number SC20263150 and is cooperating fully with the authorities.

What should I do?

Whether or not you have been notified by your service provider that your personal information may have been affected, we encourage you to take the following protective steps as a precaution:

  • Monitor your bank accounts closely for any unusual or unauthorised activity. Report any suspicious transactions to your bank immediately.
  • Contact your bank to inform them that your details may have been compromised and to request enhanced monitoring or additional security measures for your account.
  • Register with the Southern African Fraud Prevention Service (SAFPS) for free identity fraud protection at www.safps.org.za.
  • Be alert to suspicious communications. Be wary of any unsolicited emails, telephone calls, or SMS messages that ask for personal or financial information.
  • Do not share your PIN, passwords, or OTPs in response to any unsolicited communication. Legitimate organisations will never ask you for these details by email, SMS, or telephone.
  • Review your credit report for any unfamiliar accounts or enquiries.
  • Update your passwords on any accounts where you may have reused credentials.
  • Enable multi-factor authentication wherever it is available.

What happens next?

Protecting the data entrusted to us is a responsibility we take seriously. The independent forensic investigation is ongoing, and we will continue to work with our legal advisors and forensic experts to take all necessary measures. We will provide further updates as material developments arise.

If you have questions about this notice or the incident, please contact us at incident@relycomply.com.