{"id":667519,"date":"2026-09-14T17:31:32","date_gmt":"2026-09-14T15:31:32","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=667519"},"modified":"2026-09-14T17:50:30","modified_gmt":"2026-09-14T15:50:30","slug":"cartrack-warning-after-hackers-access-sensitive-data","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/667519-cartrack-warning-after-hackers-access-sensitive-data.html","title":{"rendered":"Cartrack warning after hackers access sensitive data"},"content":{"rendered":"\n<p>Cartrack has confirmed that customer data, including names, email addresses, physical addresses, phone numbers, and bank account information, may have been exposed during a recent cyberattack.<\/p>\n\n\n\n<p>In an email sent to customers, the company said attackers accessed its customer database and details that may relate to customers.<\/p>\n\n\n\n<p>These included personal contact information, bank account information, and certain vehicle and driving-related data.<\/p>\n\n\n\n<p>&#8220;Our investigation remains ongoing. If we identify additional information that materially changes the potential impact on you, we will notify you as appropriate,&#8221; Cartrack said.<\/p>\n\n\n\n<p>It warned that the exposed personal information could be misused by malicious actors and recommended that customers take precautions.<\/p>\n\n\n\n<p>&#8220;The information could potentially be used to support scammers, including phishing attempts,&#8221; Cartrack said.<\/p>\n\n\n\n<p>&#8220;For example, you may receive calls, emails, or SMS messages from someone pretending to represent Cartrack, your bank, or another trusted organisation.&#8221;<\/p>\n\n\n\n<p>It added that there was also a risk of identity theft or impersonation. It encouraged customers to be wary of unexpected communications that request sensitive information or ask them to log in to fake websites.<\/p>\n\n\n\n<p>Cartrack, which had over 2.2 million subscribers as of 31 May 2026, was the victim of a cyberattack in August 2026.<\/p>\n\n\n\n<p>On 2 September 2026, the ransomware group Dire Wolf listed the company on its dark web leak site, claiming it had exfiltrated 500GB of data from Cartrack&#8217;s servers.<\/p>\n\n\n\n<p>At the time, Cartrack said it wasn&#8217;t in a position to determine the extent of the data access and that its investigations were ongoing.<\/p>\n\n\n\n<p>&#8220;We immediately took steps to secure our technical environment and mitigate the impact of this incident,&#8221; the company said.<\/p>\n\n\n\n<p>&#8220;An investigation into the source, extent, and implications of the incident is underway, conducted by our technology teams, with support from cybersecurity experts.&#8221;<\/p>\n\n\n\n<p>The company said it had notified the relevant authorities, including the Information Regulator, and would continue to cooperate with them and notify affected parties.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Data leaks on the dark web<\/h2>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/09\/Cartrack-Direwolf-leak.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1600\" height=\"900\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/09\/Cartrack-Direwolf-leak.jpg\" alt=\"\" class=\"wp-image-666363\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/09\/Cartrack-Direwolf-leak.jpg 1600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/09\/Cartrack-Direwolf-leak-600x338.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/09\/Cartrack-Direwolf-leak-1200x675.jpg 1200w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/09\/Cartrack-Direwolf-leak-768x432.jpg 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/09\/Cartrack-Direwolf-leak-1536x864.jpg 1536w\" sizes=\"(max-width: 1600px) 100vw, 1600px\" \/><\/a><\/figure>\n\n\n\n<p>Dire Wolf&#8217;s Cartrack listing on its dark web site said the leaked data included financial documents, source code, customer profile data, non-disclosure agreements, and backups.<\/p>\n\n\n\n<p>It uploaded several folders, displayed across two pages of documents, as a sample and proof of the exfiltrated data.<\/p>\n\n\n\n<p>A review of the data revealed that a large portion of it belonged to users and companies based in the United States, where Cartrack launched in 2016.<\/p>\n\n\n\n<p>However, it may simply be that the threat actor cherry-picked information related to American companies, as it may be viewed as more valuable than information from South African companies and users.<\/p>\n\n\n\n<p>Dire Wolf is a relatively new ransomware operation, first documented in 2025. It is linked to targeted, financially motivated attacks on companies.<\/p>\n\n\n\n<p>The group leverages double extortion by both encrypting important files and threatening to leak them online to pressure victims into paying ransoms.<\/p>\n\n\n\n<p>Cybersecurity blog Provendata showed that Dire Wolf had publicly claimed 135 victims, including dozens of new victims in the last 30 days.<\/p>\n\n\n\n<p>These included companies from at least 36 countries, with concentrations in healthcare, technology, and manufacturing.<\/p>\n\n\n\n<p>The group&#8217;s <em>modus operandi<\/em> suggested campaign-driven extortion activity, where numerous actors work together to take down certain targets.<\/p>\n\n\n\n<p>Dire Wolf deliberately selected victims, targeting companies where downtime and data exposure could result in immediate costs for the victim.<\/p>\n\n\n\n<p>It also opens direct communication channels with victims to apply more pressure and, hopefully, extort a payment.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cartrack has started notifying customers in South Africa whose data may have been exposed in a recent cyberattack.<\/p>\n","protected":false},"author":341076,"featured_media":658386,"comment_status":"open","ping_status":"closed","sticky":true,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"failed","_sma_x_autopost_error":"Threads publishing failed: Threads returned HTTP 400: The requested resource does not exist","_sma_x_post_id":"2099521564165238942","_sma_facebook_post_id":"120850204637381_1500699365415375","_sma_instagram_post_id":"18158327146507843","_sma_threads_post_id":"","_sma_x_attempts":1,"footnotes":""},"categories":[27],"tags":[66088,44160,107518,69535,30150],"class_list":["post-667519","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-cartrack","tag-cyberattack","tag-dire-wolf","tag-karooooo","tag-ransomware"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/667519"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341076"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=667519"}],"version-history":[{"count":3,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/667519\/revisions"}],"predecessor-version":[{"id":667526,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/667519\/revisions\/667526"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/658386"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=667519"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=667519"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=667519"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}