Rectron network offline for days and won't say if it was caused by a cyberattack

Just received... "Rectron regrets to inform you that we have become the latest victim of a cyberattack –an all-too-familiar phenomenon in South Africa and indeed around the world. The incident, identified on 15 July 2026, has affected certain of our information technology (IT) systems and operations.

Investigations are ongoing to determine the nature and extent of the information that may have been accessed, and we are taking all reasonable steps to restore normal operations as soon as practicable."
... continues ...

still sounds like speculation doesn't say what it is maybe they got infected and decided halt everything or breached or what ever it is.
 
Cybersecurity Compromise at Rectron (Pty) Ltd.

Mustek Limited
(Registration number 1987/070161/06)
(Incorporated in the Republic of South Africa)
Share code: MST
ISIN: ZAE000012373
(‘Mustek’ or ‘the Company’)

CYBERSECURITY COMPROMISE AT RECTRON (PTY) LTD

Shareholders are advised that Rectron (Pty) Ltd (‘Rectron’), a wholly-owned subsidiary of Mustek, recently identified and responded to a cybersecurity compromise affecting certain of its information technology systems and operations, in terms of which a third party unlawfully accessed certain data of Rectron, the extent of which is being determined.

Rectron became aware of the incident on 15 July 2026 and immediately activated its incident response and business continuity procedures. Rectron has engaged external forensic specialists to assist with the investigation, containment and recovery process.

The investigation remains ongoing and the Company is working closely with Rectron to establish the nature, scope and impact of the incident.

Rectron has notified the Information Regulator and will publish a notification to affected data subjects on its website in compliance with section 22 of the Protection of Personal Information Act, 2013 (a copy of which can be viewed in (ww.rectron.co.za).

The above mentioned compromise only affected Rectron. No other company within the Mustek Group has been compromised.

The board of the Company will continue to assess the situation and will communicate any material developments by way of a further SENS announcement if required.

Johannesburg
22 July 2026
 
One of Rectron's vendors called me earlier and we were speculating the issue and discussed the possibilities of a cyber attack.

Every so often, they (said vendor) get a cyber security test in the form of a "malicious" mail sent from within the company domain. If they click the link, they fail the test. If they report it, they pass. He has an extremely high pass rate, having failed only twice out of more than a dozen tests.

Assuming 100 people could get a 99% pass rate, statistically there's a breach on the very first attempt. The larger the company, the higher the chances of being hit like this.
 
still sounds like speculation doesn't say what it is maybe they got infected and decided halt everything or breached or what ever it is.
Whatever it is they, like many companies, figure out that their recovery for such an event usually relies on some system that some guy setup somewhere that runs something important and there's no backup or the last backup was 2015.

Total and utter projection ^. but it's usually how it goes.
 
Every so often, they (said vendor) get a cyber security test in the form of a "malicious" mail sent from within the company domain.
This was always amusing to me. If staff clicking on an email or link in an email can bring your business to its knees you need to reconsider your security posture. I remember one guy who received a suspicious email, submitted it to a security website for analysis and was flagged as needing training because he had “interacted” with the test.
 
If staff clicking on an email or link in an email can bring your business to its knees you need to reconsider your security posture
The thing is some of the real attacks are extremely sophisticated. They may involve compromising the mailbox of a senior, going through his sent items to get a "feel" for the way he writes, what's being discussed lately, who it's being discussed with, etc then copying that "feel" and including a link to a malicious file in a mail sent to subordinates - a completely believable mail which isn't out of place given the context.

No AV software or mail filtering is foolproof, and if the attack is new and unique enough, may very well slip through any security measures in place.
 
The thing is some of the real attacks are extremely sophisticated. They may involve compromising the mailbox of a senior, going through his sent items to get a "feel" for the way he writes, what's being discussed lately, who it's being discussed with, etc then copying that "feel" and including a link to a malicious file in a mail sent to subordinates - a completely believable mail which isn't out of place given the context.

No AV software or mail filtering is foolproof, and if the attack is new and unique enough, may very well slip through any security measures in place.
Sure and there are mitigations for almost everything if done correctly but sending fake phishing emails is scraping the bottom of the barrel if we're talking sophisticated...
 
sending fake phishing emails is scraping the bottom of the barrel if we're talking sophisticated...
Not really - I'm familiar with these. They often spend up to WEEKS learning how to send an email so believable that even the "sender" questions whether he sent it and has forgotten - especially if it contains technical terms that have to be used correctly and as would be used by the "sender."
 
The thing is some of the real attacks are extremely sophisticated. They may involve compromising the mailbox of a senior, going through his sent items to get a "feel" for the way he writes, what's being discussed lately, who it's being discussed with, etc then copying that "feel" and including a link to a malicious file in a mail sent to subordinates - a completely believable mail which isn't out of place given the context.

No AV software or mail filtering is foolproof, and if the attack is new and unique enough, may very well slip through any security measures in place.
agreed

forgot the TV shows name but the hacker explained sending phishing emails basically a easy way in.

remember your outlooks gonna open your browser and follow the link no AV basically allows it on any site that side may drop you a file that file is infected, infected PC gets breached and so on so forth what ever you or your PC has access to is vulnerable.

and nothing is perfect
 
Not really - I'm familiar with these. They often spend up to WEEKS learning how to send an email so believable that even the "sender" questions whether he sent it and has forgotten - especially if it contains technical terms that have to be used correctly and as would be used by the "sender."
Sure but in a large organization your security posture should never allow one email, no matter how convincing or senior to convince anyone, in isolation, to do anything that could compromise your systems. Heck, the AI voice calls using spoofed numbers are far more convincing and your processes should cater for such.
 
Sure but in a large organization your security posture should never allow one email, no matter how convincing or senior to convince anyone, in isolation, to do anything that could compromise your systems. Heck, the AI voice calls using spoofed numbers are far more convincing and your processes should cater for such.
dont they use minecast i know that thing is strict especially with attachments.

and then what ever they use for their pcs bitdefender/norton/avast which ever it is.

but i mean if your server is somewhat broadcasting its findable.

does remind me of that inside job a while back i read about. literally a flash drive inserted into a PC to infected an entire organisation forgot who it was.
 
dont they use minecast i know that thing is strict especially with attachments.

and then what ever they use for their pcs bitdefender/norton/avast which ever it is.

but i mean if your server is somewhat broadcasting its findable.

does remind me of that inside job a while back i read about. literally a flash drive inserted into a PC to infected an entire organisation forgot who it was.
I'm not familiar with what they have in place. I've spent far too much time in large corporates with very sophisticated postures that most of whats being raised is not even a possibility anymore, or if it was - it would have to be sophisticated to the extent that it would need to compromise multiple levels using multiple exploits against different vendors.
 
I'm not familiar with what they have in place. I've spent far too much time in large corporates with very sophisticated postures that most of whats being raised is not even a possibility anymore, or if it was - it would have to be sophisticated to the extent that it would need to compromise multiple levels using multiple exploits against different vendors.

i just know its mimecast (Not Timu lol) from email rejections ive had before. i dont use it myself i know my wife (the company she works for) uses it.

well until we know what it was we can all guess
 
Last edited:
dont they use minecast i know that thing is strict especially with attachments.

and then what ever they use for their pcs bitdefender/norton/avast which ever it is.

but i mean if your server is somewhat broadcasting its findable.

does remind me of that inside job a while back i read about. literally a flash drive inserted into a PC to infected an entire organisation forgot who it was.

Is Minecast the Temu version of Mimecast?
 
Top
Sign up to the MyBroadband newsletter
X