Cartrack warning after hackers access sensitive data
Cartrack has confirmed that customer data, including names, email addresses, physical addresses, phone numbers, and bank account information, may have been exposed during a recent cyberattack.
In an email sent to customers, the company said attackers accessed its customer database and details that may relate to customers.
These included personal contact information, bank account information, and certain vehicle and driving-related data.
“Our investigation remains ongoing. If we identify additional information that materially changes the potential impact on you, we will notify you as appropriate,” Cartrack said.
It warned that the exposed personal information could be misused by malicious actors and recommended that customers take precautions.
“The information could potentially be used to support scammers, including phishing attempts,” Cartrack said.
“For example, you may receive calls, emails, or SMS messages from someone pretending to represent Cartrack, your bank, or another trusted organisation.”
It added that there was also a risk of identity theft or impersonation. It encouraged customers to be wary of unexpected communications that request sensitive information or ask them to log in to fake websites.
Cartrack, which had over 2.2 million subscribers as of 31 May 2026, was the victim of a cyberattack in August 2026.
On 2 September 2026, the ransomware group Dire Wolf listed the company on its dark web leak site, claiming it had exfiltrated 500GB of data from Cartrack’s servers.
At the time, Cartrack said it wasn’t in a position to determine the extent of the data access and that its investigations were ongoing.
“We immediately took steps to secure our technical environment and mitigate the impact of this incident,” the company said.
“An investigation into the source, extent, and implications of the incident is underway, conducted by our technology teams, with support from cybersecurity experts.”
The company said it had notified the relevant authorities, including the Information Regulator, and would continue to cooperate with them and notify affected parties.
Data leaks on the dark web

Dire Wolf’s Cartrack listing on its dark web site said the leaked data included financial documents, source code, customer profile data, non-disclosure agreements, and backups.
It uploaded several folders, displayed across two pages of documents, as a sample and proof of the exfiltrated data.
A review of the data revealed that a large portion of it belonged to users and companies based in the United States, where Cartrack launched in 2016.
However, it may simply be that the threat actor cherry-picked information related to American companies, as it may be viewed as more valuable than information from South African companies and users.
Dire Wolf is a relatively new ransomware operation, first documented in 2025. It is linked to targeted, financially motivated attacks on companies.
The group leverages double extortion by both encrypting important files and threatening to leak them online to pressure victims into paying ransoms.
Cybersecurity blog Provendata showed that Dire Wolf had publicly claimed 135 victims, including dozens of new victims in the last 30 days.
These included companies from at least 36 countries, with concentrations in healthcare, technology, and manufacturing.
The group’s modus operandi suggested campaign-driven extortion activity, where numerous actors work together to take down certain targets.
Dire Wolf deliberately selected victims, targeting companies where downtime and data exposure could result in immediate costs for the victim.
It also opens direct communication channels with victims to apply more pressure and, hopefully, extort a payment.