Reports

CarTrack Breach Puts POPIA Enforcement Back on Air

South African talk radio spent mid-September working through the implications of a cyberattack on vehicle tracking giant CarTrack, after the ransomware group Dire Wolf listed the company on its dark web leak site and claimed to have exfiltrated 500 gigabytes of customer data. Presenters focused on what the leaked trove reportedly contains — names, contact details, bank account information and vehicle data — and what that means for the millions of motorists whose profiles sit inside CarTrack's platform.

The story quickly widened beyond CarTrack itself. SAfm and Power FM used the incident to interrogate the Information Regulator's growing caseload under POPIA, while Cape Talk and 702 folded it into a broader on-air conversation about banking app fraud, social engineering and the weakness of South Africa's cybercrime enforcement. The unresolved questions on air: whether CarTrack had adequate safeguards, how affected customers will be notified, and what regulators can realistically do about a breach of this scale.


The CarTrack story broke onto the airwaves via SAfm's early bulletins, which reported that the ransomware group Dire Wolf had listed CarTrack on its dark web leak site and claimed to have exfiltrated 500 gigabytes of data. Presenters relayed CarTrack's own account: that its customer database was accessed and may include contact details, bank account information and vehicle data, that the platform was restored within hours, and that the Information Regulator had been notified.1

SAfm then went to the Regulator directly, and the on-air exchange set the tone for the week's coverage. The Regulator's spokesperson stressed that the immediate priority was establishing the exact categories of personal information caught up in the breach — including names and possibly account numbers — before data subjects could be properly advised.2 That framing, of a regulator still trying to scope the damage, ran alongside a wider Power FM interview in which officials confirmed they had received more than eight thousand security compromise notifications since POPIA's enforcement powers took effect in July 2021, with a sharp rise in serious cyber incidents.3

Much of the airtime focused on what CarTrack is now legally obliged to do. Power FM's guest was categorical: the responsibility sits with the organisation to notify both the Information Regulator and every data subject whose personal information has been compromised — the same standard applied when a bank suffers a breach.4 Presenters returned repeatedly to that dual-notification duty as the yardstick by which CarTrack's remediation would be judged.

The risk analysis on air was unusually detailed. Power FM's cyber guest explained that individual breaches rarely hand attackers a complete profile — one leak might yield an ID number, another a cell number — but that aggregation across breaches is where the real harm sits, enabling identity fraud downstream.5 SAfm extended the point, describing how stealer logs harvest browsing history, passwords and account names, which criminals then combine with breach data to build full consumer profiles for resale.6 Cape Talk's Moneyweb slot reminded listeners this is not new territory, invoking the Pick n Pay Bottles app leak as a cautionary precedent for how quickly exposed data becomes ammunition for scammers.7

Stations then connected the CarTrack disclosure to the banking fraud epidemic already dominating consumer coverage. Cape Talk and Power FM both carried the SABRIC finding that banking app fraud accounted for roughly 89% of digital banking crime cases in 2025, driving R1.7 billion in client losses.89 SAfm's banking segment put the number of reported incidents at around 110,000 for the year, with the caveat that many go unreported.10 The link presenters drew was direct: a CarTrack-scale trove of names, numbers and bank details is precisely the raw material that fuels the social engineering behind those banking losses.11

Customer risk was framed practically. SAfm's banking guest urged listeners that the moment money moves without authorisation, they must stop cards, open a case with SAPS and lodge a claim — without a police case number, insurers have little to work with.12 Cape Talk widened the lens to phishing calls impersonating SARS or banks, noting that attackers often lean on information sourced from prior data breaches to make their approaches convincing.13

Enforcement scepticism was the sharpest note. 702's guest argued bluntly that South Africa has a "non-existing serious cybercrime unit" and lacks the specialised tracing platforms needed to pursue actors like Dire Wolf, making prosecutions extremely difficult even when breaches are formally reported.14 That gap between the Regulator's notification regime and the state's investigative muscle was the throughline connecting SAfm, Power FM and 702's coverage.

Cape Talk's later week coverage broadened the debate into a principled one about data protection itself, with presenters noting how routinely personal information is harvested — at complex gates, by retailers, by apps — and how little control consumers ultimately retain.15 A separate Cape Talk interview with an organisation that had itself been knocked offline for seven days by a cyberattack gave listeners a visceral sense of what a targeted digital assault looks like from the inside.16

What remains unresolved on air: the precise categories of personal information exposed in the CarTrack breach, whether the company's security safeguards will be found adequate under a Regulator investigation, how and when affected customers will be individually notified, and whether the R500GB claim by Dire Wolf will be independently verified. Presenters across all five stations flagged that the story will be judged less by CarTrack's initial statement than by what the Information Regulator finds — and by whether affected motorists start seeing their data surface in the fraud economy already dominating consumer radio.

Mentions per day, by station
0123403 Sept07 Sept09 Sept11 Sept14 Sept17 Sept
  • 702
  • Cape Talk
  • Moneyweb@Midday
  • Power FM
  • SAfm
Coverage built steadily from early September and peaked on 8–10 September as SAfm, Power FM and Cape Talk simultaneously ran banking-fraud segments, before a second spike on 17 September when the Dire Wolf leak-site claim and Regulator response hit the bulletins.
Share of mentions by station
024681011Power FM10SAfm9Cape Talk37021Moneyweb@Midday
Power FM and SAfm led the conversation with 11 and 10 chunks respectively, Cape Talk followed on 9, while 702 and Moneyweb@Midday carried lighter but still substantive coverage.

Citations

  1. 1.

    Group Dire Wolf listed CarTrack on its dark web leak site, claiming that it exfiltrated 500 gigabytes of data. CarTrack says its customer database was accessed, which may include contact details, bank account information, and vehicle data. Car Track says its platform was restored within hours and the information regulator was notified. For more on this, we joined on the line by

    SAfmFirst Take SADiscuss in chat ↗

  2. 2.

    That may have been subject to this breach. As you mentioned, it includes names and may include account numbers. Now we need to establish the type of personal information that was subject to this breach so that we are able to advise data subjects accordingly. As the regulator, what investigation will you undertake whether CarTrack had adequate security safeguards in place before the attack? Yeah, when we receive notifications.

    SAfmFirst Take SADiscuss in chat ↗

  3. 3.

    continue to see the continued rise in security compromises and not just minor compromises, but we are also seeing a very sharp increase in serious security compromises or cyber security incidents. To date, you would remember that our enforcement powers came into effect on the first of july twenty twenty one. From that date, we have received over eight thousand security compromises.

    Power FMPOWER TalkDiscuss in chat ↗

  4. 4.

    So, the responsibility is for the organization to notify one, the information regulator, but two, data subjects, those whose personal information has been compromised. So, if you bank with Bank X and they suffer a security compromise, they are required to notify the regulator, but they are also required to notify you as their customer that your information has been compromised or has been the subject of a security compromise.

    Power FMPOWER TalkDiscuss in chat ↗

  5. 5.

    Specific moment. There have been many data breaches in the past, and it's not always where they will get a complete profile of you. In one data breach, you might find that they only have your ID number. In another breach, they get your cell phone number. When all of this information is put together, it can give a profile of you. It can allow for hackers to do a lot more with the information that they have. So, that is one of the potential harms that there could be issues of identity.

    Power FMPOWER TalkDiscuss in chat ↗

  6. 6.

    Could even capture the device, type of device that you're accessing from, what type of items are you searching for. And if you combine that with Steeler logs, where the Steeler logs will also harvest your browsing history, and in that, they can find passwords and account names. So, if you combine that information, they can utilize that to form a whole profile of you as a consumer or a potential victim to crime if they sell it onto a

    SAfmThe Daily DiscourseDiscuss in chat ↗

  7. 7.

    Yes, we are definitely paying for it with our personal information. And no, I don't think we quite realize what it's worth as everyday consumers. And the other issue, of course, is data security. And, you know, we saw with the Pick and Pay Bottles app, you know, it's a legacy app, it's been long since replaced, but there was a major data leak. And all of the information that everybody on that app had shared then became useful to hackers and scammers. So that's one of the big red flags.

    Moneyweb@MiddayDiscuss in chat ↗

  8. 8.

    News Pretoria. A new report by the South African Banking Risk Information Center has revealed the banking apps are now the primary target for digital banking crime in South Africa. The report shows banking app-related fraud accounts for nearly 89% of reported digital banking crime cases in 2025, contributing to 1.7 billion Rand in client losses. Total losses from digital banking crime reached 2.41 billion.

    Cape TalkLunch with Pippa HudsonDiscuss in chat ↗

  9. 9.

    Rand in reported client claims, with banking apps alone accounting for 89% of all reported cases and 1.7 billion in losses. While these figures paint a frightening picture for everyday users, security experts emphasize a crucial distinction: the apps and underlying bank systems are not being hacked. Instead, the modern wave of digital fraud is heavily driven by sophisticated social engineering. Let's learn more.

    Power FMPOWER BreakfastDiscuss in chat ↗

  10. 10.

    Welcome. How many incidents of banking app-related crime occurred in the last year? Good morning, Joanne. Yes, approximately 110,000 crime incidents were reported by clients in 2025. And I repeat, reported because we know that a great number of these crimes are not reported by the clients for various reasons. Tell me, how did most of these crimes occur?

    SAfmThe Daily DiscourseDiscuss in chat ↗

  11. 11.

    Sabrik, that's the South African Banking Risk Information Center, has reported that South Africans lost 1.7 billion rand to digital banking crimes. And these are mainly via banking apps. That is where people are most vulnerable. Not just the violent nature of crimes that are committed against people, where you are made to open up your app and they clean out your bank account at gunpoint. This is now where you are hacked, or somebody

    Power FMPOWER BreakfastDiscuss in chat ↗

  12. 12.

    Being compromised, or your card is being skimmed or stabbed. It is impossible, of course, to know which one of these occurred in this particular instance. But again, the moment you realize that money has been transferred, contact your bank, stop your cars, have it investigated, put in a claim, make a case with the local police because without that, you will not have a leg to stand on in terms of any claim that you may have.

    SAfmThe Daily DiscourseDiscuss in chat ↗

  13. 13.

    Your bank, or sometimes as well, do social engineering and phishing, pretending to be a you know, from SARS as well, to collect that particular information. And some of the information, where they get them, it can also be from a previous data breach as well. And that's basically how they take some of the information from, or where they get the information from. I can understand my banking app, I can understand maybe a personal shopping app, but all apps I can understand my email.

    Cape TalkGood Morning Cape TownDiscuss in chat ↗

  14. 14.

    This is also there, but they've got much more sophisticated cybercrime units. South Africa has got a non-existing serious cybercrime unit with the technology like gravis and highly specialized equipment that can do the cyber track tracing platform profile investigations. So it's very, very difficult. And then you must understand number three, these people gave the money willingly. It's a very difficult case to.

    702Afternoon DriveDiscuss in chat ↗

  15. 15.

    To do as they wish with your personal information. And that is what is driving data protection globally. I mean, so many people still complain, and I get them all the time, of spam calls, you know, direct to your cell phone. They seem to get cleverer and cleverer. They phone all the time. You must get so many complaints about that. And I know you've tried to deal with some of them. Yeah, because our personal information is all over the place. When you enter a complex, you know what happens. Yeah.

    Cape TalkThe Money ShowDiscuss in chat ↗

  16. 16.

    Our digital infrastructure was attacked. We were blacked out for seven days. We could not have access to our website. We could not have access to our emails. And the attack came after a series of conversations that we, not demands, not conversations, but demands from a group of people.

    Cape TalkDiscuss in chat ↗