
Cartrack Data Breach: Customer Information Published on Dark Web
Cartrack has confirmed that information stolen during its August ransomware attack has been published on the dark web, potentially exposing sensitive customer details including bank account information, contact details, physical addresses and vehicle-related data.
Cartrack customers are now being warned to remain alert for phishing, impersonation and fraud attempts after the company confirmed that information accessed during a ransomware attack on its platform has been published by the attackers.
In a notification sent to affected customers, Cartrack said the original incident occurred at approximately 2am on 26 August 2026. The company says it took immediate steps to contain the attack and had restored its platform to full operation by 7am that same morning.
But the incident has since developed into a potentially much more serious data-security event.
Cartrack confirms data was published on the dark web
Cartrack says its investigation has established that on 8 September 2026, some of the information accessed during the August attack was published on the dark web by the purported threat actors.
The company believes the ransomware attack was carried out by a group known as Direwolf.
Cartrack stressed that the investigation is still ongoing and said it will provide further updates if it discovers additional information that materially changes the potential impact on customers.
That means the full scope of the breach is not yet known.
What Cartrack says may have been exposed
According to the notification sent to customers, attackers accessed information contained within Cartrack’s customer database.
The information may include:
- Customer names
- Email addresses
- Telephone numbers
- Physical addresses
- Bank account holder names
- Bank names
- Branch codes
- Bank account numbers
- Certain vehicle information
- Certain driving-related information
Cartrack has not said that every affected customer had all of these categories of information exposed.
That distinction matters.
The company says the database information accessed by the attackers may include some or all of the categories above, while its investigation continues.
Why this could become a bigger problem for customers
The immediate concern isn’t necessarily that criminals can simply empty a customer’s bank account.
The bigger risk is social engineering.
Someone with access to a customer’s name, address, vehicle information and banking details could potentially make a phishing message look far more convincing.
A scammer could claim to be from Cartrack, a bank, an insurance company or another organisation the customer already deals with.
That’s why Cartrack is warning customers to be especially careful with unexpected calls, SMS messages and emails requesting passwords, payments, personal information or banking credentials.
Knowing your Cartrack details does not mean the person contacting you is actually from Cartrack.
Cartrack customers should be especially careful with fake payment requests
Cartrack has specifically addressed the possibility of fraudulent communications following the incident.
The company says it will never ask customers to disclose their Cartrack password.
It has also identified its official WhatsApp account as +27 11 250 3000, which should display the official blue verification tick.
Cartrack says official emails can come from addresses ending in @cartrack.com, including examples such as noreply@cartrack.com and accounts@cartrack.com.
Customers should therefore be extremely cautious about messages from different numbers or email domains claiming to represent Cartrack.
What Cartrack says it has done
Cartrack says it moved quickly after detecting the ransomware attack.
Its response included isolating affected servers, restoring the platform, strengthening access controls and security monitoring, engaging independent cybersecurity specialists and beginning a forensic investigation.
The company says it also:
- Prompted customers to update their Cartrack passwords
- Reviewed its technical and organisational security measures
- Notified the Information Regulator of South Africa
- Notified and continues to cooperate with law-enforcement authorities
- Engaged independent cybersecurity experts to investigate the incident
The fact that the platform was restored within approximately five hours demonstrates the speed of Cartrack’s operational response.
However, restoring the platform is only one part of dealing with a ransomware incident.
The publication of customer information on the dark web means the potential consequences can continue long after the original systems have been restored.
What customers should do right now
Cartrack is advising affected customers to take several precautions.
Monitor your bank account. Check statements regularly and report unfamiliar transactions to your bank immediately.
Contact your bank. Cartrack recommends informing your bank that your information may have been affected and asking whether additional fraud monitoring or protective measures are available.
Change reused passwords. If your Cartrack password was also used on another service, change that password there too.
Check your credit profile. Customers can obtain their credit reports and monitor for unfamiliar credit applications.
Consider SAFPS Protective Registration. Cartrack recommends considering the free Protective Registration service offered by the Southern African Fraud Prevention Service.
Be suspicious of unexpected communications. Don’t click links or provide passwords, banking credentials or other sensitive information simply because a message appears to know details about you.
The dark web publication changes the situation
The most significant development isn’t that Cartrack suffered a ransomware attack.
Ransomware attacks are unfortunately increasingly common.
The significant development is that Cartrack has now confirmed that information accessed during the attack has been published on the dark web.
That potentially moves the situation from an internal cybersecurity incident to an ongoing customer-protection issue.
Information that has been published online can potentially be copied, redistributed and used by different criminals long after the original attackers have disappeared.
And because the exposed information may include banking and personal details, customers could face targeted scams rather than the generic phishing attempts most people are accustomed to.
Cartrack says the investigation is still underway
Cartrack has not yet provided a final assessment of exactly how many customers were affected or precisely which information belonging to each customer was published.
The company says its investigation remains ongoing.
It has promised to notify customers if additional findings materially change the potential impact.
For now, affected customers should treat the notification seriously without assuming that every piece of their personal information has been exposed.
The safest approach is straightforward: monitor your finances, change reused passwords, watch your credit profile and treat unexpected Cartrack communications as potentially fraudulent until verified through an official channel.
The ransomware attack may have been contained in hours.
The data exposure could be a much longer story.