Security5.05.2026

Company behind every product barcode in South Africa denies it suffered a data breach

Ransomware gang Stormous has claimed that it breached GS1 South Africa, also known as the Consumer Goods Council of South Africa (CGCSA). However, the company said the claim was false.

Stormous said it stole a large amount of sensitive customer, staff, and executive data and gained full access to the SharePoint server that contains South Africa’s GS1 barcode database.

GS1 is the barcode standard that gives products sold in South Africa unique identifiers that can be scanned at point-of-sale machines. Such barcodes must be registered to ensure uniqueness.

GS1 is also a company, and South Africa’s only registered barcode supplier. “We invented the GTIN and innovate barcodes globally,” it said.

The CGCSA is an industry association representing over 9,000 member companies in the consumer goods, retail, and services sectors, which is one of the largest employers in South Africa.

Its barcodes are used not only in retail, but also in healthcare, transport, and logistics. Its partners include all of South Africa’s major retailers and food brands, as well as Netcare, Google, and Facebook.

Stormous said the exfiltrated data included corporate information such as names, emails, phone numbers, financial accounting records, and sales order reports.

Stormous also claimed to have gained access to one of GS1 South Africa’s SQL servers and Sage 200 Evolution SQL.

This included its full Sage 200 Evolution backups, including all transaction history, tax records, and payroll.

Stormous said it obtained operational security data, as well as CRM and legal archives with over 151,000 sensitive documents, contracts, and internal communications.

In addition, the group said it gained full access to GS1 South Africa SharePoint, including GDSN protocols and partnership data with several high-profile clients.

The breach also allegedly included a complete compromise of the personally identifying information of administrative and executive staff, including private emails and mobile numbers.

GS1 South Africa said attack failed

Zinhle Tyikwe, CEO of the The Consumer Goods Council of South Africa (CGCSA)

Contacted for comment about the reports of a breach at the CGCSA, GS1 South Africa told MyBroadband that the claims Stormous reportedly made were false.

“There was an attempted malicious intrusion, which was detected and contained, and it did not result in unauthorised access, data exfiltration, or operational compromise,” a spokesperson said.

“Our security controls and monitoring mechanisms functioned as designed, preventing access to internal systems and sensitive information.”

GS1 South Africa stated that there was neither evidence of a ransomware attack on its system nor of data exfiltration, and business operations have continued without disruption.

“We note the highly detailed and speculative nature of the information presented in your enquiry,” the spokesperson said.

“This level of detail is consistent with a malicious and deliberate attempt to create alarm or lend credibility to unsubstantiated claims, rather than reflecting an actual compromise of our systems.”

GS1 South Africa said it remained vigilant and proactive in managing cybersecurity risks, immediately investigating and responding to potential threats.

“Where appropriate, we cooperate fully with relevant stakeholders and authorities, in line with best practice and regulatory expectations,” it assured.

Questions about Stormous

Stormous’s claim of a data breach against CGCSA. Source: DarkNotify

Ransomware.live reported that Stormous was an Arabic-speaking, pro-Russian ransomware and hacktivist group active since at least 2022.

Stormous was known for politically motivated attacks across over 15 countries. It collaborated with GhostSec on the GhostLocker 2.0 RaaS platform and inherited GhostSec’s RaaS operations in mid-2024.

The group previously had a reputation for making exaggerated or outright false claims, raising questions about whether Stormous was actually a scamming operation, rather than a ransomware gang.

In 2023, SOCRadar reported that some of the data Stormous claimed to have stolen was found to be fake, raising doubts about the legitimacy of their claims and intrusions.

However, its partnership with GhostSec in 2024 put Stormous back on the map and repaired some of the group’s damaged reputation.

Show comments

Latest news

More news

Trending news

Poll

Which operating system do you have installed on your personal computer?

View Results

Loading ... Loading ...
Sign up to the MyBroadband newsletter