October 2026

Precautionary Notification Regarding a Potential Security Compromise in terms of Section 22 of the Protection of Personal Information Act, 2013 (POPIA)

Dear Enhanced Wallet user,

Vodacom Payment Services (Pty) Ltd ("VPS") is writing to you regarding a cybersecurity incident that may affect certain users of the VodaPay Enhanced Wallet.

Bidvest Bank Limited ("Bidvest"), the sponsor bank for the VodaPay Enhanced Wallet, informed VPS that it suspected a cybersecurity incident involving DataSeed (Pty) Ltd, trading as RelyComply ("RelyComply"). RelyComply is a service provider appointed by Bidvest to support Bidvest's legal and regulatory obligations as the accountable institution in terms of the Financial Intelligence Centre Act 38 of 2001 ("FICA"). Bidvest is responsible for the RelyComply relationship and for the processing activities performed under that relationship. VPS did not appoint RelyComply and does not control the relevant RelyComply processing environment.

What happened

Bidvest previously advised VPS that it suspected that an unauthorised third party may have accessed information held in an environment operated by RelyComply. At that time, Bidvest had not provided VPS with evidence or substantive information confirming that a security compromise had occurred or establishing that personal information relating to Enhanced Wallet users had been accessed or acquired by an unauthorised person.

VPS has not identified any compromise of its own systems, network or VodaPay platform arising from this incident, and the VodaPay service continues to operate normally. Bidvest has advised VPS that Bidvest's own systems were not affected either.

Bidvest has advised VPS that RelyComply's appointed specialists are investigating the suspected incident. VPS has requested that Bidvest provide verified information concerning the nature and extent of any unauthorised access, the personal information involved, the affected individuals and the containment and remediation measures taken. Because VPS had not been given information establishing reasonable grounds to believe that Enhanced Wallet users' personal information had been accessed or acquired, VPS did not issue a section 22 notification to Enhanced Wallet users at that stage. VPS nevertheless issued precautionary fraud-awareness communications while it continued to seek further information from Bidvest.

On 1 October 2026 the suspected threat actor published a list of data sets that were exfiltrated from the RelyComply environment. Based on Bidvest and VPS' assessment that the published material contains or is reasonably believed to contain personal information relating to VodaPay Enhanced Wallet users, VPS is issuing this precautionary notification on behalf of Bidvest to enable potentially affected users to take protective measures.

Personal information that may have been affected

Bidvest have relayed that the affected environment contained information such as client name, contact details, identity or passport information, address information, client-reference information and certain transaction information collected to meet Bidvest's legal and regulatory requirements. Not all information was necessarily populated in every record and the nature and extent of the information potentially affected therefore varies from person to person.

Possible consequences

If personal information was accessed or acquired unlawfully, it may be used on its own or together with information obtained elsewhere to attempt:

  • identity fraud or identity theft;
  • phishing or social-engineering attacks;
  • impersonation;
  • fraudulent account applications or attempted account takeovers; or
  • attempts to obtain passwords, PINs, one-time passwords, banking information or other confidential information.

As at the date of this notice, VPS has not identified evidence that personal information relating to Enhanced Wallet users has been misused as a result of this incident. To limit potential misuse, however, VPS and Bidvest recommend the below precautions.

Precautions You Can Take

To help protect yourself, we recommend that you take the following precautionary measures:

  • Be alert to suspicious communications. Carefully review emails, SMSs, telephone calls or other messages claiming to be from Bidvest, VPS, VodaPay, Vodacom or another organisation. Do not click links, open attachments or disclose personal information unless you have independently verified the sender.
  • Protect confidential authentication information. Never disclose your password, PIN, card security code, one-time password or other authentication information in response to an unsolicited communication. Neither VPS nor Bidvest will ask you to provide this information by email, SMS, WhatsApp or telephone.
  • Monitor your accounts. Review your bank, payment and other financial accounts regularly, activate transaction alerts where available, and report any unrecognised transaction or change immediately.
  • Review your credit profile. Consider obtaining a credit report from a recognised credit bureau and checking for unfamiliar accounts, applications or enquiries. Report suspicious activity promptly to the relevant credit provider and credit bureau.
  • Strengthen account security. Use strong, unique passwords for online accounts and enable multi-factor authentication wherever available.
  • Secure your email account. Use a unique password and enable multi-factor authentication because email accounts may be used to reset passwords for other services.
  • Verify identity-document requests. Do not provide copies of identity documents, proof of address, banking details or similar records unless you have independently confirmed the recipient and the reason for the request.
  • Report approaches relating to the incident. If anyone claiming to possess VodaPay or Bidvest information contacts you, do not engage, make payment or follow their instructions. Preserve the communication and report it using the official contact details below.
  • If you reasonably suspect identity theft or impersonation, contact the Southern African Fraud Prevention Service on 011 867 2234 or visit www.safps.org.za for guidance on protective registration.

These measures may reduce the risk of identity fraud, phishing, social engineering and other cybercrime. Please remain vigilant even if you have not noticed suspicious activity.

What has been done

Both VPS and Bidvest takes the privacy and security of personal information seriously.

Since Bidvest informed VPS of the suspected incident, VPS has assessed the potential impact on Enhanced Wallet users, sought supporting information from Bidvest, activated its internal legal, privacy, cybersecurity, fraud and communications processes, issued precautionary fraud-awareness messaging and monitored the VodaPay environment for suspicious activity on an enhanced basis.

To date:

  • VPS requested that Bidvest provide verified information sufficient to determine whether Enhanced Wallet users are affected and, if so, the nature and extent of that impact.
  • VPS implemented enhanced monitoring for suspicious activity within the VodaPay environment and continues to assess any information received from Bidvest.
  • Bidvest has advised VPS that it is engaging RelyComply and relevant legal and forensic specialists regarding investigation, containment and remediation. These activities are being managed by Bidvest in relation to its service-provider relationship.
  • Both VPS and Bidvest conduct daily monitoring for any indication that personal information connected with VodaPay Enhanced Wallet user and / or Bidvest has been misused, unlawfully disclosed or published.

Bidvest have confirmed that it has notified the appropriate regulatory authorities, including the Information Regulator, the Financial Sector Conduct Authority and the Prudential Authority.

If the ongoing investigation produces material new information that changes Bidvest's understanding of the incident or the potential risks, Bidvest will work with VPS to provide further updates where appropriate.

Contact us

If you have questions about this notice or wish to report suspicious activity relating to the incident, please contact either Bidvest or VPS directly through the following official channels:

Bidvest Bank Customer Contact Centre: 
Email: [email protected] 
Telephone: 0860 11 11 77 

OR 

alternatively you can contact VPS directly on 082 17800 or email us at [email protected]