A Domestic Address
On 9 September the Dire Wolf ransomware group claimed to have taken 200 gigabytes of data from RelyComply, a South African provider of identity-verification and anti-money-laundering checks to regulated financial firms – “production databases and Amazon S3 cloud storage”, in the attackers’ own words, some 3.57 billion rows. RelyComply confirmed an incident and an investigation.
Within days, several regulated institutions were writing to their customers – and, where the law required it, to the Information Regulator – each able to say, truthfully, that its own systems had not been breached. One of the country’s largest banks was investigating whether the identity checks it runs at account opening were in scope. A fortnight earlier the same group had hit a vehicle-tracking company with more than two million subscribers; that data was on the dark web by 8 September.
The month’s third case reached further down the chain. A policy-administration provider to the life insurers disclosed that a June intrusion – an employee’s password reused on an unrelated site, a support-ticket system the provider was decommissioning – had exposed, by its own count, some 400,000 records belonging to the customers of around forty-five insurers. The policy databases were untouched; the data left in files. A ransom was paid for a promise to destroy it, and by 7 September the first insurer was on the leak site. The regulators then said the same thing twice. Under POPIA, the Information Regulator noted, the obligation “rests on the responsible party” – the insurer, not its supplier. Under Joint Standard 2, said the Prudential Authority, “the obligation, again, lies with the insurers”: the 24-hour clock is theirs, whichever server the data left from.
Craig Rosewarne of Wolfpack calls these “digital supply chain” or “hub-and-spoke” attacks: one provider, many clients. I would put it more plainly. In the identity-verification case the institutions had a South African supplier under a South African contract. Where the copy itself sat is another matter – the supplier’s own privacy notice, quite properly, allows processing in South Africa, the United Kingdom, the European Economic Area, the United States “or other countries” – and I doubt many of its clients could have said which. What none of them had was control over a copy of their own customers’ identities, and the difference arrived as a breach notification.
One thing follows. The way in varies – a reused password, a zero-day in a supplier’s application – but what leaves is always the same: the database, or, as in the administrator’s case, a copy of it in transit – an export, a transfer file, an attachment on a support ticket. The perimeter is where the attacker starts. It is not where the data is.