← Cartrack

2026 Cartrack — Aug ransomware; customer DB accessed; Dire Wolf 500GB claim; SA regulator notified

2026 Unknown records affected Share on X

Data compromised

Company/regulator context: customer database accessed — contact details, bank-account information, and vehicle data cited. Dire Wolf claimed ~500GB from servers (volume unverified as complete census). Affected-individual count not published in preliminary Section 22 notice coverage

Technical writeup

Verified company/regulator reporting — September 17, 2026. South Africa’s Information Regulator confirmed Cartrack filed a preliminary POPIA Section 22 notification after an August ransomware incident. Cartrack acknowledged its customer database was accessed; fields cited in press include contact details, bank-account information, and vehicle data. Ransomware group Dire Wolf listed Cartrack claiming ~500GB exfiltrated — actor volume remains unverified as a complete census and no public headcount of data subjects was published in preliminary coverage. recordsAffected 0 (no attested individual count yet); companyConfirmed true.

Root cause

August 2026 ransomware incident; Dire Wolf leak-site listing claimed ~500GB exfiltration

References