Standard Bank probes RelyComply breach after Dire Wolf claims 200GB
The bank's FICA identity checks run through a third party that a ransomware group listed on 9 September, and SA Home Loans has already told customers an unauthorised party was inside the same environment on 2 September.
Standard Bank has told customers its services remain operational after a data incident at RelyComply, the identity verification platform that runs background FICA checks when a person opens an account on the bank’s app.
The bank said its specialist teams are working with the service provider to establish the scope of the incident and any potential impact on Standard Bank and its clients. It said it had activated enhanced monitoring across its operating environments as a precaution.
As MyBroadband reported on 18 September, the bank confirmed it was aware of a data incident at a third-party service provider. That reporting is the origin of this account, and the facts below are drawn from it.
What Dire Wolf says it took
On 9 September 2026, a ransomware group calling itself Dire Wolf listed RelyComply on its dark web leak site, claiming it had stolen 200GB of data from the company.
The data allegedly includes information used for identity verification, transaction monitoring, compliance screening and credential management.
RelyComply is not a household name. It sits behind the app screens of banks, asset managers and home loan providers, doing the work that the Financial Intelligence Centre Act requires before a new account is opened. In South Africa, that process is known as FICA, and it is the reason a new client is asked to photograph an identity document and take a selfie.
RelyComply’s chief technology officer, James Saunders, told MyBroadband in July that the company’s systems form part of the FICA process when a user opens a new account in the apps of the companies it works with. He said digital identity verification had become essential in app-based banking in South Africa because of the rise in deepfakes and other AI-based fraud.
“You want to make sure the customers are who they say they are,” he said at the time. “Basically, you take pictures of yourself, and we check it’s not a synthetic identity.”
The checks RelyComply runs in the background include name matching, identity document verification, adverse media checks and political exposure checks.
Other South African firms in the same chain
Based on recent data exposure notices from companies, RelyComply also provided services to Bidvest Bank, EasyEquities, Peregrine Capital, Satrix and SA Home Loans.
SA Home Loans issued a notification to customers on Wednesday saying an unauthorised party had gained access to RelyComply’s environment on 2 September 2026. Files accessed by that party included information compiled by RelyComply on behalf of SA Home Loans. The company said there was no evidence yet that its customer data was exfiltrated during the Dire Wolf attack, but that it could not rule it out.
That is the detail a South African reader should hold on to. The question is not only whether Dire Wolf’s 200GB claim is accurate. It is that an unauthorised party was inside the same environment a week before the leak site listing, and at least one lender has already written to customers about it.
What the bank has said, and what it has not
Standard Bank’s spokesperson said protecting clients and their information remained its top priority and that the bank would continue to work closely with RelyComply.
The bank did not say how many clients may be affected, and it has not said whether any customer data has been confirmed as exfiltrated. Those are the two facts that matter most to an account holder, and neither is established.
This is the second time this year that Standard Bank has had to answer questions about its data. In March 2026, a threat actor calling themselves Root Boy claimed to have had access to the bank’s internal systems for more than three weeks and exfiltrated 1.2TB of confidential data, including limited credit card information, which was later leaked online after the bank refused to pay a 1 Bitcoin ransom.
At the time, the bank said its transactional banking and core operating systems were not accessed, remained secure and were available to all clients and employees. Chief executive Sim Tshabalala later described the March breach as one of the toughest moments of his career.
“What happened, essentially, was that cybercriminals managed to enter our systems and steal data, but fortunately, we were able to stop them,” he said. “They were not able to enter the operating systems, in other words, the payment systems and so forth, but they managed to get data.”
He said the bank communicated directly with affected clients and proactively replaced affected bank cards, even though card verification numbers were not exfiltrated.
Why this lands differently here
The FICA chain is a South African one, and it is regulated. Banks are required by the Financial Intelligence Centre Act to know who their customers are, and most of them now do that work through a small number of specialist platforms rather than building it in-house. That concentration is efficient and it is also the risk. When one verification provider is compromised, the exposure reaches every institution that leans on it, and the customer finds out from a letter rather than from the app.
For an ordinary account holder, the practical steps have not changed. Watch for phishing that references a bank, a home loan or an identity check, because a breach of verification data hands criminals exactly the personal details a convincing message needs. Treat any request for an OTP, a PIN or a card verification number as a fraud attempt, whatever number it appears to come from.
The Information Regulator is the body that receives breach notifications under the Protection of Personal Information Act, and affected companies are required to inform it. The Enquirer has asked Standard Bank how many clients may be affected, whether any data has been confirmed as exfiltrated, and when the assessment with RelyComply will conclude. We have also asked the Information Regulator whether notifications have been filed by the companies named in this report. Their answers will be carried in this paper when they arrive.
Source: MyBroadband, Standard Bank investigates 200GB data breach

