2 October 2026

RE: NOTIFICATION OF A SECURITY COMPROMISE IN TERMS OF SECTION 22 OF THE PROTECTION OF PERSONAL INFORMATION ACT, 2013 (“POPIA”) – CYBER INCIDENT THIRD PARTY SERVICE PROVIDER – DATASEED (PTY) LTD T/A RELYCOMPLY (“RELYCOMPLY”)

  1. Thelo Rolling Stock Leasing (Pty) Ltd (“Thelo”) is issuing this notification to inform data subjects who may be affected by a cybersecurity incident involving RelyComply, a third-party service provider used by Thelo for all its Anti-money Laundering / Know-Your-Customer / Know-Your-Business compliance obligations, and more in particular, identity verification, sanctions screening and politically exposed persons screening.

  2. Given the number of potentially affected data subjects and the ongoing work required to determine the impact on each person, Thelo is communicating this notice as a precaution and in the interest of transparency. Communicating this notice does not mean that every category of personal information listed below was affected in relation to every person, or that any person’s information has been misused.

  3. On 8 September 2026, RelyComply became aware that certain of its customers had received fraudulent emails from an unauthorised third-party impersonating RelyComply. This triggered an immediate activation of RelyComply’s incident response processes. Specialist legal advisors and Cyanre, a well-known South African digital forensics firm, were engaged to perform an independent forensic investigation and assist with incident response.

  4. On present information, the unauthorised access may have begun on or about 2 September 2026. RelyComply became aware of the incident on 8 September 2026. The forensic investigation is at an early stage and is working to establish the full nature, timeline and extent of the incident.

  5. The investigation is still underway to understand exactly what occurred. However, RelyComply can confirm that credentials were used by an unauthorised person gained access to some systems where data was stored.

  6. Based on the investigation to date, the categories of personal data potentially in scope include:

    • Identity and contact data;
    • Date and place of birth;
    • Nationality;
    • Screening results;
    • Case records; and
    • Bank account details (please note that from Thelo’s perspective, data subjects’ bank details have not been captured on the RelyComply platform); and
    • Where the customer’s service includes identity verification: identity documents and images (including copies of passports and national identity documents). and biometric data derived from facial recognition and liveness checks.
  7. RelyComply has taken the following steps in response to the incident:

    • Affected systems have been taken offline.
    • The environment has been reset and rebuilt before core services were restarted.
    • All access credentials have been rotated.
    • Customers have been asked to rotate their RelyComply API tokens.
    • RelyComply is co-ordinating a refresh of single sign-on (SSO) identity provider secrets.
    • IP addresses associated with the suspicious activity have been shared with customers so that their security teams can review their own logs and apply blacklisting at their discretion.
    • Independent forensic specialists are conducting threat hunting across the environment.
    • Enhanced monitoring, logging and alerting capabilities have been implemented.
    • Platform backups have been verified as not compromised, and additional backup replicas have been created.
  8. RelyComply has reported the incident to the Information Regulator of South Africa under reference number SC20263150. Thelo shall likewise report the incident to the Information Regulator of South Africa.

  9. RelyComply is supporting its customers with data-subject-level information and notification content to assist them in communicating with affected individuals.

  10. Individuals whose personal information may have been affected are advised to:

    • Remain vigilant against suspicious or unsolicited communications, including emails, telephone calls and SMS messages.
    • Not share passwords, PINs, one-time passwords (OTPs), or other security credentials in response to unsolicited contact.
    • Monitor bank accounts closely for any unusual or unauthorised activity.
    • Contact their bank to request enhanced monitoring of their accounts.
    • Consider registering with the Southern African Fraud Prevention Service (SAFPS) for free identity fraud protection at www.safps.org.za.
  11. The threat actor claiming responsibility identifies itself as “Direwolf”. It has claimed responsibility publicly on social media and has contacted some of RelyComply’s customers directly. Direct contact with customers is a known pressure tactic used by threat actors during incidents of this nature. It is possible there will be further attempts to contact customers.

  12. Do not engage with the threat actor directly. If you are contacted by the threat actor, please inform Thelo before taking any action.

  13. The RelyComply website notification relating to the incident can be accessed by clicking on the following link: https://relycomply.com/relycomply-cyber-incident-what-happened-and-what-you-can-do/.

  14. Frequently asked questions (FAQs) for impacted data subjects as provided by ReplyComply:

    1. What happened? A data security incident has occurred involving RelyComply, a technology company that provides regulatory compliance software and services. An unauthorised third party gained access to RelyComply’s systems and may have accessed personal information that was held by RelyComply. RelyComply has engaged independent legal advisors and specialist digital forensic investigators, and the matter is being thoroughly investigated.

    2. When did this happen? On present information, the unauthorised access may have begun on or about 2 September 2026. RelyComply became aware of the incident on 8 September 2026, when certain customers received fraudulent emails from the unauthorised third party. The investigation is at an early stage, and work is ongoing to establish the full timeline and extent of the incident.

    3. What personal information was affected? The categories of personal information that may have been affected include: relevant business information that may / may not be in the public domain; name and surname; identity / passport document and number; gender; date and place of birth date; residence (country); nationality; physical and postal address. The investigation is ongoing, and we will inform you if additional categories of information are identified.

    4. What risks do I face because my bank account details may have been compromised? Where bank account details have been compromised, there is a risk that the information could be used to attempt unauthorised transactions or to impersonate you when dealing with financial institutions. Threat actors may also use compromised information to craft convincing phishing communications (for example, emails or telephone calls that appear to come from your bank) to trick you into disclosing further information such as PINs, passwords, or one-time passwords (OTPs).

    5. What steps should I take to protect myself? We recommend that you take the following steps as a precaution:

      • Monitor your bank accounts closely for any unusual or unauthorised activity. Report any suspicious transactions to your bank immediately.
      • Contact your bank to inform them that your account details may have been compromised and request enhanced monitoring or additional security measures on your account.
      • Register with the Southern African Fraud Prevention Service (SAFPS) for free identity fraud protection. You can register at www.safps.org.za.
      • Be alert to suspicious communications. Be wary of any unsolicited emails, telephone calls, or SMS messages that ask for personal or financial information, particularly if they claim to be from your bank, RelyComply, or a government authority.
      • Do not share your PIN, passwords, or OTPs in response to any unsolicited communication. Legitimate organisations will never ask you for these details by email, SMS, or telephone.
      • Review your credit report for any unfamiliar accounts or enquiries.
      • Update your passwords on any accounts where you may have reused credentials.
      • Enable multi-factor authentication wherever it is available.
    6. Has anyone misused my information? At this time, we have no confirmed evidence that any personal information has been misused. However, as a precaution, we strongly recommend that you follow the protective steps we recommend and remain vigilant.

    7. What is RelyComply doing about this? RelyComply has taken immediate steps to respond to the incident, including: taking affected systems offline; resetting and rebuilding the environment before restarting core services; rotating all access credentials; engaging independent forensic specialists to conduct a thorough investigation; and implementing enhanced monitoring, logging and alerting capabilities. RelyComply is working with its legal advisors and forensic experts to take any further measures necessary.

    8. What is RelyComply doing to help me? RelyComply is providing the organisation that holds your account with the information it needs to notify you and support you, including details of the personal information held, the categories of data affected, and guidance on protective steps you can take.

    9. Has RelyComply reported this to the authorities? Yes. RelyComply has reported the incident to the Information Regulator of South Africa under reference number SC20263150.

    10. Who was the threat actor? The threat actor claiming responsibility identifies itself as “Direwolf”. It has claimed responsibility publicly and has contacted some organisations directly. This is a known pressure tactic used by threat actors during incidents of this nature.

    11. Why was my information with RelyComply? / Why did RelyComply have my data? RelyComply provides regulatory compliance technology and services, including anti-money laundering (AML), know-your-customer (KYC), and know-your-business (KYB) solutions, to financial institutions and other regulated organisations. The organisation that holds your account uses RelyComply’s platform to carry out certain regulatory compliance functions. In order to provide those services, RelyComply processes personal information on behalf of that organisation (acting as the “operator” or “processor” under data protection law). The processing of your information by RelyComply is governed by an agreement between RelyComply and the organisation that holds your account.

    12. Can I make a complaint? If you wish to make a complaint, you may direct it to the organisation that holds your account using their standard complaints process. You may also contact the Information Regulator of South Africa directly at: enquiries@inforegulator.org.za, or by telephone at 012 406 4818. Further information is available at www.justice.gov.za/inforeg.

    13. What should I do if I receive a suspicious email, SMS or phone call? Do not respond to any unsolicited communication that asks you to share personal or financial information, click on a link, or download an attachment. Do not share your password, PIN, OTPs, or security credentials. If you receive a communication that claims to be from RelyComply or from the organisation that holds your account and you are unsure whether it is genuine, contact that organisation directly through its official channels. Report any suspicious communications to your bank and, if appropriate, to the South African Police Service (SAPS).

    14. Will I receive identity monitoring or credit monitoring services? RelyComply is working with its customers to determine what additional support may be made available to affected individuals. In the meantime, we strongly encourage you to register with the Southern African Fraud Prevention Service (SAFPS) at www.safps.org.za, which provides free identity fraud protection. You should also monitor your bank accounts and credit report for any unusual activity.

    15. What should I do if I believe fraud has already occurred using my information? If you believe that your information has been misused or that fraud has occurred, you should take the following steps immediately:

      • Contact your bank to report the suspected fraud and request that they take protective action on your account.
      • Report the matter to the South African Police Service (SAPS) by opening a case at your nearest police station. Retain a copy of the case number for your records.
      • Register with SAFPS at www.safps.org.za if you have not already done so.
      • Contact the organisation that holds your account to inform them of the suspected fraud.
    16. How can I contact RelyComply with further questions? If you have further questions about this incident, you may contact RelyComply at incident@relycomply.com. You may also contact your service provider (the organisation that holds your account) directly using their usual contact channels.

    17. How can I exercise my data subject rights (e.g. access, correction, deletion)? Under POPIA, you have the right to request access to, correction of, or deletion of your personal information. Because RelyComply acts as the operator (processor), requests relating to your personal information should in the first instance be directed to the organisation that holds your account (the responsible party / controller). That organisation will co-ordinate with RelyComply as necessary.

    18. When will the investigation be complete? The forensic investigation is at an early stage and is ongoing. We are not yet in a position to provide a definitive timeline for its completion. We will provide further updates as and when material developments arise. We appreciate your patience and understanding.

    19. Will I be told if the investigation finds something new? Yes. If the investigation reveals any new information that materially affects the assessment of the data involved or the steps you should take to protect yourself, you will be informed through the organisation that holds your account. RelyComply is committed to keeping its customers informed of material developments so that they can in turn communicate with you.

  15. Please note that early indications are that Thelo’s own network and operating systems were unaffected by the incident, and these systems continue to operate as normal.

  16. Further information will be communicated once available. If you have any queries relating to the subject matter, please do not hesitate to contact us at compliance@thelo.africa.