2026 Bidvest Bank — third-party provider incident; customer data potentially affected (count TBD)
Data compromised
Bank said the provider held certain categories of Bidvest data that should be treated as potentially affected; specific field list and census not published at notice time
Technical writeup
Verified Bidvest Bank customer notification — mid-September 2026 (Connecting Africa / Geekhub reporting). Bank said a third-party service provider confirmed Bidvest data was in the affected environment and should be treated as potentially affected; independent forensic investigation continuing; extent of access not yet established. Same weekend notices from EasyEquities and Cell C; MyBroadband/Peregrine reporting has pointed at RelyComply as a possible shared IDV/compliance vendor (not confirmed by Bidvest in sources reviewed). recordsAffected 0; companyConfirmed true.
Root cause
Cybersecurity incident at a third-party service provider that held Bidvest Bank data; extent of access still under forensic investigation