TechNewsReel
Live

EasyEquities and Satrix Customers Exposed in RelyComply Regtech Breach

A cyberattack on South African regtech firm RelyComply has compromised data across multiple financial and telecom institutions.

TechNewsReel Newsroom · September 14, 2026

EasyEquities and Satrix customers have been alerted to a potential data breach stemming from a security failure at a third-party service provider. The incident underscores a growing vulnerability in the financial services supply chain, where a single point of failure can expose millions of users across unrelated platforms.

According to reports, the breach was not a direct intrusion into the internal systems of EasyEquities or Satrix. Instead, the vulnerability originated at RelyComply, a South African-founded regtech company. The cyberattack on RelyComply created a domino effect, affecting several other high-profile entities simultaneously, including Bidvest Bank and Cell C Fibre. Affected users across these platforms were advised to remain vigilant and adopt general security precautions to protect their personal information.

The Regtech Connection

EasyEquities, a prominent low-cost investment platform in South Africa, administers the Satrix platform. Like many modern fintech firms, it relies on specialized regtech providers like RelyComply to handle critical compliance and Anti-Money Laundering (AML) data. These providers are essential for ensuring that financial institutions meet strict regulatory requirements without building massive internal compliance infrastructures from scratch. However, by centralizing sensitive customer verification data in one place, these providers become high-value targets for cybercriminals.

Systemic Supply Chain Risk

This incident highlights the systemic risk posed by "supply chain" attacks within the fintech and telecommunications sectors. When a specialized service provider is compromised, the breach is not limited to one company but extends to every client using that provider's software or data services. In this case, the reliance on a single regtech firm for compliance data allowed a single attack to compromise the data of customers across banking, investment, and fiber internet services.

For the industry, this serves as a warning that security is only as strong as the weakest link in the vendor ecosystem. As financial institutions increasingly outsource core functions to cloud-based SaaS providers, the surface area for potential attacks expands, often beyond the direct control of the primary institution's security team.

Looking Ahead

While the origin of the breach has been identified as RelyComply, the full extent of the data exfiltrated remains a primary concern for the affected users. Industry observers will be watching to see if this leads to stricter auditing requirements for third-party regtech vendors in South Africa. For now, customers of EasyEquities, Satrix, Bidvest Bank, and Cell C Fibre are encouraged to monitor their accounts for suspicious activity as the fallout from the RelyComply attack continues to be assessed.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.