What Business Owners Need to Know This Week
Week 40 (20–26 September 2026) answered the question W39 left open: the regulators have said the insurer owes the notification whatever the supplier did. The Information Regulator confirmed it has received only MIP’s section 22 notification for a breach touching roughly 45 insurers, that the duty rests on the responsible party, and that paying a ransom neither establishes nor resolves compliance. In the same week The Gentlemen listed Guardrisk, a second South African insurer in three weeks, and Bidvest Bank’s section 22 notice surfaced — naming the provider, naming the actor and listing three regulators told. For the first time a South African board has both halves of the standard: what the duty is, and what discharging it looks like on the page.
The Bottom Line: Technically the week is the network edge again, with Check Point joining Cisco, Citrix, Fortinet and MikroTik in the overdue column. Check Point, F5, Arista and Cisco each shipped a one-line compromise check a South African SOC can run today. So the question for a CISO this morning is narrow: does anyone in the organisation own the list of edge appliances those checks must be run against? Nine appliance families from seven vendors have been added to the catalogue since 8 September.
The Week in Numbers
- 132 cumulative SA ransomware victims — up 4 from 128; HIGH threat level for the 23rd consecutive week.
- 3 of 4 — SA-tagged claims surviving the nationality check; Morula IVF is an Indonesian fertility network. The aggregator’s country field has now invented a South African victim five times and hidden one.
- 888 victims — The Gentlemen’s index, up from 867 in seven days; second most prolific group worldwide in NCC Group’s August count.
- 10 new CISA KEV additions — between 21 and 25 September, seven already past their remediation date at publication.
- 5 of 10 — sit on the network edge: two Check Point flaws, an F5 BIG-IP APM heap overflow, a second Arista VeloCloud flaw in two months, and the second half of the MikroTik chain.
- 5,252 MikroTik RouterOS instances — exposed in South Africa, 4,285 of them on the API port.
- 823 SharePoint instances — exposed on-premises; Microsoft recorded reliable evidence of attacks on CVE-2026-65660 on 25 September.
- 180,000+ downloads — of the Gauteng e-Panic app whose database could be read without authentication, on a contract the DA put at R269 million.
- 495 passwords — in the infostealer panel on Guardrisk’s aggregator record, 35 marked critical.
- 16 weeks — since the Information Regulator’s last substantive publication.
Major Incidents: Who Was Hit and How
Guardrisk — A Second Insurer, and a Question That Matters to Every Other One
Guardrisk Group, the Sandton cell-captive insurer owned by JSE-listed Momentum Group, was indexed at 08:48 UTC on Saturday 26 September with an estimated attack date of 21 September. The listing carries no data volume, no sample and no deadline, and Guardrisk had published nothing by the close of the window. Rated CLAIMED. Two things are known and one is not. It is known that The Gentlemen has now listed two South African insurers in three weeks and published Hollard’s data after Hollard refused a demand; it is also known that the group’s own leaked guidance to affiliates was to avoid India and Africa-style targets — which nine South African listings since January now contradict. What is not known is whether this is a compromise of Guardrisk’s own estate or a second downstream extortion from the MIP data set, and those have very different implications for every other insurer in the country. Guardrisk’s cell-captive model means the records at issue belong, in POPIA terms, to as many responsible parties as there are cells — the same structure that turned the MIP breach into 45 notifications.
Telkom / BCX — An Incident in a Legacy Testing Environment
Telkom disclosed on 25 September an incident identified within a limited area of a legacy testing environment at BCX, its IT services subsidiary, since contained and isolated from live production systems. It says there is no evidence to date that customer data was compromised, that customer operations were not affected, and that relevant customers were notified as a precaution. Not disclosed: the incident date, the actor, any ransomware family, whether a demand was received, or whether any regulator was notified. The significance is structural — BCX runs infrastructure and applications for a large share of South African corporate and public estates, so a testing environment at BCX is a supplier environment for its customers. Telkom’s decision to notify customers as a precaution follows exactly the pattern the regulators described this week.
Gauteng e-Panic App — Live OTPs in an Open Database
GroundUp reported on 23 September that the Gauteng panic-button app’s database could be reached without authentication: names, gender, age, phone numbers, email addresses, vehicle registrations, crime reports including domestic violence and assault, uploaded images, GPS coordinates and location histories back to the 2024 launch — and one-time PINs stored against cellphone numbers. The developer fixed the exposure within a day of being told. This is the second Gauteng provincial data exposure of 2026, and the first in a public-safety application whose entire value depends on users trusting it with their position. The stored OTPs are the detail that matters to a SOC: an unauthenticated read of a table holding live login codes and the numbers they belong to is account takeover without phishing. GroundUp’s email to the Information Regulator drew an automated response directing it to the online portal.
Check Point, F5 and the Overdue Edge
CVE-2026-93616 is a pre-authentication directory traversal and file upload
allowing arbitrary script execution on Check Point Management servers, exploited in a handful of
targeted attacks since 23 July. CVE-2026-85102 is an authentication bypass in
VPN certificate handling, exploited on Spark firewalls since 12 September. Both were overdue on
25 September. F5 BIG-IP APM CVE-2026-94127 is a heap overflow F5 says has been
exploited. Each vendor published a log check — and the useful discipline here is to
run them before the patch and again after it, because a patch closes the way in
without evicting anyone already through it. Restrict TCP/19009 and the management
planes to trusted addresses while you work.
POPIA and Regulatory
The Information Regulator confirmed it had received a section 22 notification from MIP only, that it is engaging MIP to establish the number of responsible parties and data subjects affected, and that the obligation rests on the responsible party in respect of the processing concerned. On the ransom: payment should not be understood, in itself, as either establishing or resolving compliance with POPIA. On the Hollard publication: an earlier notification does not, as a general proposition, provide a blanket exemption from subsequent obligations. The Prudential Authority said third-party providers are not required to report to it, that supervised institutions must report material incidents within 24 hours under Joint Standard 2 of 2024, that a ransom payment does not conclude an incident or relieve an institution of its governance and customer-protection responsibilities, and it declined to confirm MIP’s account that the breach was assessed as not systemic. Neither regulator would say which insurers had reported, or when. So as of 25 September the only notification for a 45-insurer breach came from the operator. A ransomware event at a regulated financial institution now has three clocks: 24 hours to the Prudential Authority under Joint Standard 2, 72 hours to SAPS under section 54 of the Cybercrimes Act, and as soon as reasonably possible to the Information Regulator under section 22. The Regulator’s own register still carries nothing later than 10 June.
Correction to Week 39
W39 stated that Bidvest Bank had not named the provider behind its 12 September customer notice, and left the Bidvest half of the shared-provider question open. That was wrong at the time of publication. Bidvest Bank published a Notification of a Security Compromise in terms of section 22 of POPIA on its website dated 17 September 2026, inside the W39 window, naming DataSeed (Pty) Ltd trading as RelyComply as the provider, describing the intruder as understood to be affiliated with DireWolf, and recording notification to the Information Regulator, the Financial Sector Conduct Authority and the Prudential Authority. The page is script-rendered and returned only metadata to the W39 collection. The W39 count of nine organisations confirming exposure in that window should have been ten.
Full Intelligence Report
The complete Week 40 technical report covers the Guardrisk listing and its cell-captive implications, the full regulator answers on the MIP breach, the Telkom, BCX and Gauteng e-Panic incidents, all ten catalogue additions with vendor log checks for Check Point, F5, Arista and Cisco, South African exposure counts across the appliance panel, credential-exposure analysis around the week's victims, eight structured hunt missions with IOC tables, the correction to Week 39, and the full source list.
What Your Business Should Do Right Now
- Run the Check Point compromise checks before the patch and again after it: On every Security Management, Multi-Domain, Log and SmartEvent server, grep cpm.elg for a login request whose username exceeds 1,000 characters and for the ReflectionUtils error naming a path with
../sequences. A hit with a matching FWM or MDS core dump is Check Point’s own definition of an exploitation attempt. - Check VPN certificate logins on every gateway and Spark firewall: Search Mobile Access logs after 12 September for certificate logins and inspect any subject reading
CN=vpn,CN=vpn-userorCN=vpnuser. Restrict TCP/19009 and the management planes to trusted addresses while you patch. - Check BIG-IP APM OAuth authorisation servers: Count repeated
01990004:3 invalid_tokenfailures from one address in /var/log/apm, checktmctl global_oauth_statfor an unexplained rise in total_failed, and treat a TMM core file in the same window as a reason for human review. - If you are an insurer, policy administrator or cell-captive participant, ask today whether Guardrisk or MIP holds your customers’ records — and prepare the section 22 notice before anyone asks you for it. The Regulator has now said in public that the duty sits with the responsible party and that an earlier notification is no blanket exemption when the same data is later published.
- Use Bidvest Bank’s 17 September notice as your template: name the provider, name the actor as far as it is known, list the data classes, state which regulators were told, and give a contact channel. Where a cell captive or underwriting manager sits between you and the insurer, agree in writing this week who issues the notice.
- Finish the MikroTik work the catalogue has now dated twice: The second half of the MikroTrick chain fell due fifteen days after the first. Upgrade to 7.24.2, 7.23.4 or 6.49.21, check
/userfor an account namedopsand the logs for a login attempt with the username-2, and close SSH and the API to the internet. - Confirm the August SharePoint update is actually installed: Subscription Edition 16.0.19725.20522, 2019 16.0.10417.20198, 2016 16.0.5565.1001. Microsoft recorded reliable evidence of attacks on CVE-2026-65660 on 25 September, and it chains with the June authentication bypass.
- Run GroundUp’s test against your own contractor-built apps: Take the API endpoints from the app’s own traffic and call them without a token. If anything comes back, you have the Gauteng problem. Any public body or business running a citizen- or customer-facing app through a contractor should do this before someone else does.
- Know which CSIRT to call before you need it: South Africa has six teams in the FIRST directory — the Cybersecurity Hub for government and the private sector, ECS-CSIRT at the SSA for government and military, SA NREN and UCT CSIRT for research and education, and the Standard Bank and Vodacom teams for their own constituencies. The Information Regulator is a compliance destination, not a responder.