July 14, 2026: South African financial services group Sanlam confirmed that client personal data was exposed in a breach at a third-party project and task management provider — not inside Sanlam's own technology estate.
What happened
Sanlam uses external SaaS-style tools to coordinate internal projects. One of those vendors suffered a compromise; Sanlam learned client rows stored in that environment were reachable to unauthorized parties.
The insurer activated incident response with the provider, outside cybersecurity experts, and internal risk teams, and reported the event to South Africa's Information Regulator. At disclosure time Sanlam had not published a total affected-client count or the exact calendar date of the intrusion.
What data may be involved
Sanlam told reporters the exposed fields can include:
- Name and surname
- South African ID number
- Email address
- Contact phone number
That combination is enough for identity theft, policy impersonation, and convincing “verify your Sanlam policy” phishing. Sanlam said it had not seen evidence the data was published broadly or misused — a early-stage statement that can change as forensics matures.
Who is at risk
Sanlam corporate and retail clients whose information was synced into the affected project-management system. If you received a direct notice from Sanlam, treat it as authoritative; if you only saw social-media screenshots, verify through official Sanlam channels before responding.
Action items
- Contact Sanlam through sanlam.co.za if you believe you are affected and have not received guidance.
- Monitor credit and policy statements for unauthorized changes or new accounts.
- Ignore SMS or email asking for OTP codes, ID photos, or “policy verification fees.”
- Report suspected fraud to Sanlam and South African banking fraud lines promptly.
Canonical record: Sanlam 2026 third-party breach on BreachHistory.