What Business Owners Need to Know This Week

Week 28 (28 June–5 July 2026) was a consolidation week whose real signal is downstream impact. On 2 July Capitec began notifying clients that their card details were exposed in the Pick n Pay legacy Bottles/Asap! breach, advising card replacement — a bank remediating a retailer’s legacy-app failure. The mystery ~200,000-member medical-aid breach from W27 was identified as Profmed, administered by PPS Healthcare Administrators (PPSHA) — and PPSHA administers five schemes including the defence-adjacent SANDF Regular Force Medical Continuation Fund, making scope expansion credible. On the vulnerability front, patch pressure rotated to two short-fuse KEV deadlines — SharePoint CVE-2026-45659 (deadline lapsed 4 July) and SimpleHelp RMM CVE-2026-48558 (due 7 July, exploited to chain the TaskWeaver loader into Djinn Stealer through MSP deployments) — while the most dangerous item is not even in the KEV yet: Oracle EBS Payments CVE-2026-46817 (CVSS 9.8, unauthenticated) has been exploited in the wild since 27 June with ~950 exposed instances.

The Bottom Line: The 30 June hacktivist flashpoint passed without observed escalation and no new SA victim appeared on leak sites — but a bank is replacing cards because of a retailer’s decommissioned app, a medical-aid breach resolved to a third-party administrator with a five-scheme blast radius, and Oracle EBS is being exploited faster than the KEV catalogue can track it. Third-party and legacy-system risk is this week’s theme. Expect card-not-present fraud against affected customers through July, and brief staff on the tax-season fake-eFiling lures now circulating.

The Week in Numbers

  • 109 cumulative SA ransomware victims — net +1 from a restored listing, not a new victim; HIGH threat level for the 8th consecutive week.
  • 2 July — Capitec begins notifying clients and replacing cards exposed in the Pick n Pay Bottles/Asap! breach; fees reportedly waived.
  • 5 medical schemes — administered by PPSHA (Profmed, KeyHealth, SEDMED, De Beers Benefit Society, SANDF RFMCF); Profmed members notified 25 June.
  • ~2 million guest records — lost by hotel-PMS provider Hospitality Technology International (NebulaPMS) in a March intrusion.
  • CVSS 9.8 — Oracle EBS Payments CVE-2026-46817, exploited in the wild since 27 June and still not KEV-listed as of 5 July; ~950 exposed instances per Shadowserver.
  • 2 short-fuse KEV entries — SharePoint CVE-2026-45659 (three-day fuse, deadline lapsed 4 July) and SimpleHelp RMM CVE-2026-48558 (due 7 July).
  • 1 ransomware flag — CISA marked Defender LPE CVE-2026-33825 (BlueHammer) as ransomware-exploited on 29 June.
  • R100,000 — FICA cross-border cash conveyance declaration threshold, live from 1 July.
  • ~6 July — TransUnion SA and Experian SA responses due on the IR’s 10-day notices; no public development this week.

Major Incidents: Who Was Hit and How

Pick n Pay Breach Escalates — Capitec Orders Card Replacements

On 2 July Capitec began notifying a subset of clients that their card details were exposed in the breach of Pick n Pay’s legacy Bottles / Asap! delivery platform, advising card replacement. Pick n Pay confirmed the 2022-era database held names, emails, phone numbers, delivery addresses, encrypted passwords, card type, last-four digits and expiry dates — the retailer states full card numbers and valid CVVs were not stored, disputing the seller’s Breach Forums claim. Reported dataset pricing of ~R37,600 rests on a single outlet. Expect card-not-present fraud against affected customers through July.

Profmed via PPSHA — Mystery Medical-Aid Breach Identified

The unnamed ~200,000-member medical-aid breach flagged in W27 is Profmed, administered by PPS Healthcare Administrators. Members were notified on 25 June that an unauthorised party used compromised credentials to access third-party service-provider systems, potentially removing names, ID numbers, contact details, membership numbers and scheme options; PPSHA says its own systems were unaffected and the Information Regulator is being notified under POPIA s.22. PPSHA’s client listing confirms five administered schemes — Profmed, KeyHealth, SEDMED, De Beers Benefit Society and the SANDF Regular Force Medical Continuation Fund — so scope expansion is credible, with the defence-adjacent RFMCF the most sensitive extension. Separately, hotel-PMS provider Hospitality Technology International (NebulaPMS) lost ~2 million guest records in a March intrusion.

Short-Fuse KEVs — SimpleHelp RMM and SharePoint

CISA added SimpleHelp RMM CVE-2026-48558 (KEV 29 June, due 7 July) — exploited since ~29 June to chain the TaskWeaver loader into Djinn Stealer through MSP deployments, with CISA instructing forensic triage, not just patching: stolen cloud/SCM/SSH/AI-assistant tokens remain valid after patching. SharePoint CVE-2026-45659 (deserialization RCE, CVSS 8.8) got a three-day fuse that lapsed on 4 July — any authenticated user with Site Member permissions can achieve RCE. CISA also flagged Defender LPE CVE-2026-33825 (BlueHammer) as ransomware-exploited.

Oracle EBS Payments — Exploited Before the KEV

The most dangerous item of the week is NOT in the KEV catalogue: CVE-2026-46817 (CVSS 9.8, unauthenticated file read via the /OA_HTML/ibytransmit Payments endpoint, reaching DB credentials and payment API keys) has been exploited in the wild since 27 June, with ~950 exposed instances per Shadowserver. Do not wait for the catalogue — apply the May 2026 CPU, hunt for POST requests to /OA_HTML/ibytransmit, and treat any unpatched exposed instance as potentially compromised. Nissan’s 29 June disclosure confirmed hundreds of companies may have lost personnel records via the related PeopleSoft CVE-2026-35273, now 20 days overdue.

POPIA and Regulatory

The Profmed/PPSHA notification adds another POPIA s.22 case centred on third-party administrator risk — scheme principals should demand written scope confirmation. TransUnion SA and Experian SA responses to the IR’s 10-day notices are due approximately 6 July, with no public development this week. The FICA cross-border cash conveyance regime went live on 1 July with a R100,000 declaration threshold and no grace period; no first-week seizures were reported. AVBOB remains without leak-site claim or attribution roughly five weeks post-incident, and the 30 June #OpSouthAfrica flashpoint passed without observed cyber escalation in open sources.

Full Intelligence Report

The complete Week 28 technical report covers the Pick n Pay/Capitec downstream-impact analysis, the Profmed/PPSHA five-scheme exposure assessment, the SimpleHelp forensic-triage playbook, the SharePoint and BlueHammer KEV guidance, the Oracle EBS Payments hunt mission, the FICA go-live summary, tax-season phishing lure warnings, and structured hunt missions with full IOC tables.

What Your Business Should Do Right Now

  • Clear the two short-fuse KEVs: Apply Microsoft’s SharePoint fix immediately if not already done (CVE-2026-45659 — the CISA deadline has already lapsed; any authenticated Site Member can achieve RCE). For SimpleHelp RMM (due 7 July), patch AND perform forensic triage per CISA’s instruction — stolen cloud/SCM/SSH/AI-assistant tokens remain valid after patching. MSPs and their customers must rotate credentials issued through SimpleHelp-managed environments.
  • Treat internet-facing Oracle E-Business Suite as under attack: CVE-2026-46817 (CVSS 9.8) has been exploited since 27 June and is not yet KEV-listed — do not wait for the catalogue. Apply the May 2026 CPU, hunt for POST requests to /OA_HTML/ibytransmit, and if unpatched and exposed, treat the instance as potentially compromised. Complete the overdue PeopleSoft CVE-2026-35273 remediation.
  • Card-fraud response for the Pick n Pay dataset: Banks and issuers should tighten card-not-present fraud rules for flagged customers; affected consumers should replace cards and reset any reused passwords from the legacy Bottles/Asap! platform.
  • PPSHA-administered scheme response: Members of Profmed, KeyHealth, SEDMED, De Beers Benefit Society and the SANDF RFMCF should be treated as at elevated phishing and identity-fraud risk; scheme principals should demand written scope confirmation from PPSHA.
  • Verify BlueHammer patching: Defender LPE CVE-2026-33825 is now confirmed ransomware-exploited — verify the fix is deployed across every endpoint.
  • Brief staff on tax-season phishing: Fake-eFiling lures are circulating as tax season opens. Combine the warning with FICA awareness for finance and treasury teams now that the cross-border cash regime is live.