Dear Enhanced Wallet user,
Vodacom Payment Services (Pty) Ltd ("VPS") is writing to you regarding a cybersecurity incident that may affect certain users of the VodaPay Enhanced Wallet.
Bidvest Bank Limited ("Bidvest"), the sponsor bank for the VodaPay Enhanced Wallet, informed VPS that it suspected a cybersecurity incident involving DataSeed (Pty) Ltd, trading as RelyComply ("RelyComply"). RelyComply is a service provider appointed by Bidvest to support Bidvest's legal and regulatory obligations as the accountable institution in terms of the Financial Intelligence Centre Act 38 of 2001 ("FICA"). Bidvest is responsible for the RelyComply relationship and for the processing activities performed under that relationship. VPS did not appoint RelyComply and does not control the relevant RelyComply processing environment.
What happened
Bidvest previously advised VPS that it suspected that an unauthorised third party may have accessed information held in an environment operated by RelyComply. At that time, Bidvest had not provided VPS with evidence or substantive information confirming that a security compromise had occurred or establishing that personal information relating to Enhanced Wallet users had been accessed or acquired by an unauthorised person.
VPS has not identified any compromise of its own systems, network or VodaPay platform arising from this incident, and the VodaPay service continues to operate normally. Bidvest has advised VPS that Bidvest's own systems were not affected either.
Bidvest has advised VPS that RelyComply's appointed specialists are investigating the suspected incident. VPS has requested that Bidvest provide verified information concerning the nature and extent of any unauthorised access, the personal information involved, the affected individuals and the containment and remediation measures taken. Because VPS had not been given information establishing reasonable grounds to believe that Enhanced Wallet users' personal information had been accessed or acquired, VPS did not issue a section 22 notification to Enhanced Wallet users at that stage. VPS nevertheless issued precautionary fraud-awareness communications while it continued to seek further information from Bidvest.
On 1 October 2026 the suspected threat actor published a list of data sets that were exfiltrated from the RelyComply environment. Based on Bidvest and VPS' assessment that the published material contains or is reasonably believed to contain personal information relating to VodaPay Enhanced Wallet users, VPS is issuing this precautionary notification on behalf of Bidvest to enable potentially affected users to take protective measures.
Personal information that may have been affected
Bidvest have relayed that the affected environment contained information such as client name, contact details, identity or passport information, address information, client-reference information and certain transaction information collected to meet Bidvest's legal and regulatory requirements. Not all information was necessarily populated in every record and the nature and extent of the information potentially affected therefore varies from person to person.
Possible consequences
If personal information was accessed or acquired unlawfully, it may be used on its own or together with information obtained elsewhere to attempt:
As at the date of this notice, VPS has not identified evidence that personal information relating to Enhanced Wallet users has been misused as a result of this incident. To limit potential misuse, however, VPS and Bidvest recommend the below precautions.
Precautions You Can Take
To help protect yourself, we recommend that you take the following precautionary measures:
These measures may reduce the risk of identity fraud, phishing, social engineering and other cybercrime. Please remain vigilant even if you have not noticed suspicious activity.
What has been done
Both VPS and Bidvest takes the privacy and security of personal information seriously.
Since Bidvest informed VPS of the suspected incident, VPS has assessed the potential impact on Enhanced Wallet users, sought supporting information from Bidvest, activated its internal legal, privacy, cybersecurity, fraud and communications processes, issued precautionary fraud-awareness messaging and monitored the VodaPay environment for suspicious activity on an enhanced basis.
To date:
Bidvest have confirmed that it has notified the appropriate regulatory authorities, including the Information Regulator, the Financial Sector Conduct Authority and the Prudential Authority.
If the ongoing investigation produces material new information that changes Bidvest's understanding of the incident or the potential risks, Bidvest will work with VPS to provide further updates where appropriate.
Contact us
If you have questions about this notice or wish to report suspicious activity relating to the incident, please contact either Bidvest or VPS directly through the following official channels:
Bidvest Bank Customer Contact Centre:
Email: [email protected]
Telephone: 0860 11 11 77
OR
alternatively you can contact VPS directly on 082 17800 or email us at [email protected]