What Business Owners Need to Know This Week

Week 33 (2–8 August 2026) is the week the domestic and international pictures said the same thing from two directions. Two South African organisations confirmed breaches: DC Partner, one of only four NCR-accredited payment distribution agencies in the country, and Fidelity Services Group, whose mid-July claim resolved when RansomHouse published the data. Meanwhile INTERPOL released its African Cyberthreat Assessment Report 2026, putting South Africa at 92% of all ransomware detections in Africa, and SABRIC put 2025 digital banking crime losses at R2.4 billion. What is new is not the shape of the finding but its source: it is now evidenced by an international law enforcement body rather than inferred from a leak-site count.

The Bottom Line: A payment distribution agency holds identity numbers, bank details, debit order mandates and creditor schedules for people already in financial distress — consumers under debt review are an unusually exploitable group, because they already expect unfamiliar parties to contact them about money and are least able to absorb a loss. If you are a credit provider, debt counsellor or bank with debit order exposure to a PDA, act now rather than waiting for the section 22 notification to reach you. And note what this week did not produce: two victim confirmations and not one regulatory statement.

The Week in Numbers

  • 92% of Africa’s ransomware detections — South Africa’s share per INTERPOL; also 70% of business email compromise, 43.6% of Shadowserver vulnerability detections and nearly 40% of phishing detections.
  • 213,523 DDoS attacks — recorded against South Africa, one peaking at 312 Gbps.
  • 55% / USD 484 million — share of African cybercrime cases involving AI in 2025, and continental losses, more than double the USD 192 million of 2024.
  • R2.4 billion — SABRIC’s 2025 digital banking crime losses, up from ~R1.9bn; banking-app-related crime is over 70% of that. Card fraud rose 18% to R1.7bn.
  • 4 PDAs in South Africa — DC Partner (NCRPDA02, George, 65 staff) is one of them; HIGH threat level for the 13th consecutive week.
  • 3 Krybit claims in six days — DC Partner, Buzz Trading 104 (Master Products) and Serengeti Estates; before this week Krybit had claimed a single SA victim, in April.
  • 6 new CISA KEV additions — five expired before this report reached a reader, two of them the same N-able N-central weakness patched twice.
  • 28.6% — of reachable self-hosted N-central servers still unpatched during the window, per Huntress.
  • 776 vs 32 — internet-facing Apache Tomcat instances in South Africa versus exposed Langflow instances; the smaller number is the more urgent one.
  • 10 weeks — since the Information Regulator last published anything.

Major Incidents: Who Was Hit and How

DC Partner — A Regulated Payment Distribution Agency Confirms

DC Partner (Pty) Ltd confirmed on 7 August that it was the victim of a ransomware attack, after the Krybit group listed it on 2 August. This is a confirmed breach, not a leak-site claim. The company says its systems remain fully operational, that its primary concern is discharging its regulatory obligations, that it is issuing notifications under POPIA section 22, and that its investigation continues. DC Partner is one of only four National Credit Regulator accredited payment distribution agencies in South Africa, based in George with 65 employees. A PDA receives one monthly payment from a consumer under debt review and distributes it to that consumer’s creditors — so the estate holds identity numbers, bank details, debit order mandates and creditor schedules. Krybit claims to have already published the data but has not said where, how much, or what it contains, so the scope of any disclosure is unverified. Krybit also listed Buzz Trading 104 (trading as Master Products) and Serengeti Estates in the same six days; both remain CLAIMED.

Fidelity Services Group Confirms — and RansomHouse Publishes

Fidelity chief executive Wahl Bartmann confirmed on 7 August that the company had suffered a cyber incident, that it had isolated affected systems and engaged specialists, and that it had notified the Information Regulator under section 22. He also said no third-party or customer information was breached. RansomHouse, which listed the company in mid-July, has since published data it says it took, reportedly including private documents belonging to the chief executive. This resolves the carryover W32 rated CLAIMED. The company’s position that no customer data was affected and the actor’s publication of a dataset cannot be reconciled from open sources, and both are recorded here rather than one being chosen.

N-able N-central — Patch Twice, Then Hunt

N-able observed exploitation from 1 August, published Hotfix 1 on 2 August, then a second hotfix on 6 August. Huntress measured 28.6% of reachable self-hosted servers still unpatched during the window. Patch to Hotfix 2, build 2026.3.1.10, and treat any unpatched instance as compromised. Hunt for a Windows service named Cloudflared, an svchost.exe running under a user’s Documents folder, and Take Control sessions logged as MSP Support in Windows Application Event IDs 4102, 8192 and 8193. Two of the ten addresses N-able published are commercial VPN exit nodes, so correlate rather than block and forget. If you buy IT services from an MSP, ask them in writing this week whether they run N-central and whether Hotfix 2 is applied.

Tomcat and Langflow — Where the Exposure Numbers Mislead

There are 776 internet-facing Tomcat instances in South Africa, but CVE-2026-34486 is not reachable through the web port. It is reachable through the Tribes clustering receiver on TCP 4000, and only where clustering is enabled with the EncryptInterceptor configured and deserialisation gadget classes on the classpath. Hunt for exposed 4000 rather than treating all 776 as vulnerable, and upgrade to 11.0.21, 10.1.54 or 9.0.117. Langflow is the opposite case: CVE-2026-9198 needs no credentials and works against default deployments, only 32 instances are exposed in South Africa, and 650 exploitation attempts from 244 addresses have been recorded since 6 July. Upgrade to 1.10.1 and take it off the public internet. The smaller number is the emergency.

POPIA and Regulatory

INTERPOL’s assessment carries three governance findings beyond the headline numbers. 89% of surveyed countries cite underreporting as a pervasive challenge, and only Nigeria, Kenya, South Africa and Mauritius mandate breach disclosure within 72 hours — South Africa’s POPIA regime is among the stricter frameworks on the continent, which makes the Regulator’s silence harder to read. Seventeen countries enacted or amended cybercrime legislation during 2025, and four INTERPOL operations produced more than 1,500 arrests and over USD 100 million recovered, with Operation Serengeti 2.0 spanning Angola, South Africa and Uganda to dismantle more than 1,200 malicious servers and arrest 120 people. Domestically, the Information Regulator has now published nothing for ten weeks — a period that this week spans two organisations that confirmed breaches and stated they had notified it under section 22. The practical consequence is unchanged: regulatory publication is not a reliable early-warning channel, and breach awareness has to come from elsewhere.

Corrections to Prior Editions

This edition carries four corrections, recorded because the method matters as much as the finding. W32 reported no SA leak-site claim inside its window; that was wrong — DC Partner and Buzz Trading 104 were indexed on 2 August, seven and eight hours after that edition’s collection run completed. The window now runs Sunday to Saturday. The corrected W32 figures are two claims inside the window and a cumulative total of 118, not 116. Second, the claim in W30–W32 that the country feed lagged postings by two to three weeks is retracted: measurement on 8 and 9 August returned identical records and timestamps, and the collection defect above is the better explanation. It was asserted across three editions without a measurement capable of distinguishing a feed delay from a collection defect. Third and fourth, SuppCenter Global Services and Recsa are not South African — SuppCenter is a Latin America regional partner with a Costa Rican number, and Recsa is a Latin American collections group tagged Costa Rica; the SA attribution came from a single secondary article confusing it with a Nairobi-based body of which South Africa is not a member.

Full Intelligence Report

The complete Week 33 technical report covers the DC Partner and Fidelity confirmations in full, the Krybit victim set, the INTERPOL African Cyberthreat Assessment findings and SABRIC banking crime statistics, N-able N-central exploitation detail with attacker infrastructure, the Tomcat and Langflow exposure analysis, four documented corrections to prior editions with methodology, threat-actor profiles, structured hunt missions with IOC tables and the full source list.

What Your Business Should Do Right Now

  • Patch N-able N-central to Hotfix 2 (build 2026.3.1.10) on the first working day, and treat any unpatched instance as compromised: Exploitation was observed from 1 August and two hotfixes shipped in five days. Hunt for a Windows service named Cloudflared, an svchost.exe under a user’s Documents folder, and Take Control sessions logged as MSP Support in Application Event IDs 4102, 8192 and 8193.
  • Ask your MSP in writing whether they run N-central and whether Hotfix 2 is applied: Nearly 29% of reachable self-hosted servers were still unpatched during the window. Two of the ten published attacker addresses are commercial VPN exit nodes, so correlate rather than block and forget.
  • If you have debit order exposure to a payment distribution agency, act on DC Partner now: Review debit order instructions originating from PDA files, raise the threshold for changes to banking details communicated by email, and warn consumers under debt review that they may receive convincing approaches quoting their real payment arrangements.
  • Find the Tomcat cluster port before assuming exposure: CVE-2026-34486 is not reachable through the web port — it needs the Tribes clustering receiver on TCP 4000, with clustering enabled, EncryptInterceptor configured and gadget classes on the classpath. Hunt for exposed 4000, then upgrade to 11.0.21, 10.1.54 or 9.0.117.
  • Treat Langflow as the actual emergency: CVE-2026-9198 needs no credentials and works against default deployments, with 650 exploitation attempts from 244 addresses since 6 July. Upgrade to 1.10.1 and take it off the public internet.
  • Re-read your own supplier assurance against the Fidelity contradiction: A victim stating no customer data was affected and an actor publishing a dataset cannot both be verified from outside. When a supplier tells you a breach did not touch your data, ask what evidence supports that statement and when the forensic investigation concludes.
  • Use the INTERPOL numbers in your next board paper: South Africa at 92% of Africa’s ransomware detections and 70% of BEC detections is a sourced, citable figure from an international law enforcement body — materially stronger than a leak-site count for justifying control investment.
  • Brief finance on the SABRIC shift: Digital banking crime losses at R2.4 billion with banking-app crime over 70% of the total, while ATM attacks fell 46% and bank robberies fell to two. The fraud has moved to the app; the controls and the staff training should follow it.