TechNewsReel
Live

Cell C Confirms Massive Data Breach Claimed by RansomHouse

The South African telecom provider admitted unauthorized access to its IT environment, exposing sensitive personal and banking details.

TechNewsReel Newsroom · September 14, 2026

Cell C has confirmed a significant cybersecurity breach that exposed the personal information of its customers. The company disclosed the incident in January 2025, warning users that sensitive data had been accessed without authorization.

The breach was claimed by the RansomHouse hacking group, which subsequently published the compromised data on the dark web. According to confirmed reports, the stolen information is highly sensitive, including full names, contact details, ID numbers, banking details, driver's license numbers, and passport details. While Cell C initially suggested that only a limited number of individuals were affected, subsequent investigations revealed the breach was more extensive than first assessed. Some external reports indicate the leak may have involved up to 2TB of data and impacted as many as 7.7 million customers.

Internal System Failure

Contrary to early reports suggesting the breach originated from a third-party service provider in September, Cell C's official statements clarify that the incident involved unauthorized access to unstructured data within parts of its own IT environment. The company specifies that this intrusion occurred toward the end of 2024. This correction shifts the narrative from a supply-chain vulnerability to a direct compromise of the provider's internal infrastructure.

Industry Implications

This incident underscores the critical security challenges facing South African telecommunications providers. The nature of the stolen data—specifically the combination of banking details and government-issued identification—significantly elevates the risk of identity theft and sophisticated phishing attacks for millions of users. For Cell C, the breach arrives at a precarious time, posing severe regulatory risks under data protection laws and threatening its reputation in a highly competitive domestic market.

The Path Forward

As the full scale of the leak becomes clearer, the focus shifts to how the company will mitigate the damage for affected users. While the RansomHouse group has already publicized the data, the long-term impact will depend on the effectiveness of Cell C's remediation efforts and the regulatory response from South African authorities. It remains to be seen if further vulnerabilities in the IT environment will be uncovered as forensic audits continue.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.