EasyEquities data at third-party hacked and customer information compromised
EasyEquities has notified customers that their data was compromised in a recent breach at a third-party. It confirmed that the provider is RelyComply, an identity verification and compliance platform.
This comes after the online trading platform told clients late on Saturday evening that a third-party service provider had suffered a cybersecurity incident which may affect them.
“As part of our client verification process, EasyEquities uses a third-party service provider to conduct verification checks in line with regulatory obligations,” EasyEquities explained.
In an email sent to customers on Wednesday, 16 September 2026, EasyEquities confirmed that its customer data was indeed impacted.
EasyEquities said categories of information that may have been affected include full names, identity information, date of birth, gender, nationality, country of residence, and account number.
“We want to assure you, upfront, that this incident does not involve any breach or unauthorised access to EasyEquities’ or Purple Group’s own systems,” it said.
“Your account and investments, as well as your ability to invest with us, remain fully secure.”
EasyEquities confirmed to MyBroadband that the third party in question was RelyComply, which was recently attacked by the threat actor Dire Wolf.
Bidvest Bank and Peregrine Capital issued similar notifications to the one EasyEquities sent to customers on Saturday. Peregrine Capital identified RelyComply as the responsible party.
“RelyComply is an established South African AML and KYC compliance platform used by several regulated financial services providers,” Peregrine Capital said.
Similar to the others, Peregrine assured that its systems were not accessed or compromised and that customers’ investments were not affected in any way.
“Investment values, account balances and online login credentials are held on Peregrine’s systems and were not involved or compromised,” it said.
Dire Wolf is a relatively new but prolific financially motivated threat actor. Leak site monitoring service Ransomware.live said it had claimed 135 victims worldwide since emerging in May 2025.
RelyComply is not the first South African company that Dire Wolf has attacked. In the past week, it also claimed to have breached Cartrack, which is owned by the Nasdaq- and JSE–listed Karooooo.
Dire Wolf ransomware gang claimed attack on RelyComply

In a post dated 9 September 2026, Dire Wolf claimed to have breached RelyComply’s production databases and Amazon S3 cloud storage.
It said the exfiltrated data was used for identity verification, transaction monitoring, compliance screening, and credential management.
The ransomware gang said it stole 200GB of data comprising 3.57 billion rows, ranging from transactional information to personally identifying information.
Dire Wolf uses a double-extortion model, encrypting compromised systems and stealing data. They then demand payment for recovery and non-publication of the stolen information.
If the organisation refuses, Dire Wolf lists it on its Tor leak site and can release sample data, followed by the full dataset.
Based on the listing on its leak site on the dark web, RelyComply has 14 days to pay before the full 200GB data set is leaked online.
EasyEquities said it did not know if Dire Wolf is extorting RelyComply or how much it was asking for. It also said that it was RelyComply’s decision whether to pay.
“We can’t talk on their behalf. They need to decide based on what is best for their business,” EasyEquities told MyBroadband.
Regarding whether EasyEquities would continue to use RelyComply after this incident, the company said it would do whatever was in its clients’ best interests.
“As always, we monitor and engage with all suppliers and service providers to ensure we help our clients grow and to protect their wealth. We are closely watching how the situation unfolds,” EasyEquities said.
EasyEquities and RelyComply conducting investigations

Contacted for comment previously, RelyComply said it was currently investigating the incident with the utmost priority.
The compliance company said it was unable to provide further details and would give an update as soon as it was in a position to do so.
EasyEquities said in its statement to clients that it immediately activated its incident response process upon being informed of the possible breach.
“We completed a full internal investigation into any potential exposure arising from the incident, and no evidence or indicators of compromise have been identified,” it said.
“The third-party service provider’s own forensic investigators have confirmed that there is no evidence of any further access to, or movement into, EasyEquities’ or Purple Group’s own systems.”
As a precaution, EasyEquities said it disabled its integration with the third-party service provider on Friday, 11 September 2026.
As a precaution, EasyEquities encouraged customers to be extra vigilant for social engineering attempts which may use the stolen data.
These could include unsolicited contact from parties falsely claiming to represent EasyEquities or other trusted organisations.
EasyEquities warned that such phishing attempts could come via email, SMS, or scam calls seeking passwords or other sensitive account credentials.
Additionally, EasyEquities advised customers to enable two-factor authentication and use a unique username and password.
“This notice is based on the information available to us at this point in time. Should our investigation identify any change to this position, we will notify you promptly,” it assured.
Pictured in article thumbnail: Charles Savage, EasyEquities CEO.