What Business Owners Need to Know This Week
Week 34 (9–15 August 2026) produced three South African confirmations, all of them on a supply chain, and no ransomware listing against a South African victim at all. LEGO Certified Stores South Africa issued a section 22 notification on 14 August — and nobody broke into the shop. The flaw was two companies further down the chain: from the retailer, to Marsello as the POPIA operator running its loyalty programme, to Metabase, a reporting tool Marsello uses internally. None of the three companies’ own applications was breached. Toyota South Africa Motors confirmed customer data may have been exposed through a third-party bulk SMS provider, and Euphoria Telecom confirmed unauthorised access to its own cloud environment — and Euphoria is itself a supplier, holding the telephony credentials of the businesses that buy cloud PBX from it.
The Bottom Line: In the LEGO chain, Metabase fixed the flaw on 6 August, Marsello applied it immediately, and the data was gone anyway — because exploitation on 5 August preceded disclosure. A one-day patch cycle is faster than most South African organisations manage, and it was not enough. So the board question is not whether your own patching is adequate. It is which of your suppliers holds your customer data, what they run it on, and how quickly they are contractually obliged to tell you. POPIA makes the responsible party accountable for an operator’s processing — the regulatory exposure sits with you regardless of where the flaw was.
The Week in Numbers
- 3 SA confirmations, 0 ransomware listings — every confirmed incident sat on a supply chain; HIGH threat level for the 17th consecutive week (see corrections).
- CVSS 10.0 — Metabase CVE-2026-72898, unauthenticated SQL injection; in KEV from 11 August, due 14 August.
- 1 day — from exploitation (5 August) to vendor fix (6 August). The data went anyway.
- 84 Metabase instances — exposed in South Africa.
- 10 August — public proof-of-concept exploits open-sourced, closing the window in which only the original operator could exploit this.
- 16 July — the date of the Euphoria Telecom cloud compromise, disclosed this week; SIP credentials rotated and international dialling restricted.
- CVE-2026-20349 — Cisco ASA and FTD remote unauthenticated denial of service; KEV 11 August, due 14 August, overdue by three days at publication.
- Storm-1175 — the actor Microsoft attributes the N-central ransomware activity to, now moved from Medusa to a new strain called StormEncryptor.
- 92% → one vendor’s telemetry — the widely quoted INTERPOL ransomware figure is TrendAI detection data, not an incident count. Correction below.
- 76 days — since the Information Regulator’s last published statement.
Major Incidents: Who Was Hit and How
LEGO Certified Stores — Breached Two Suppliers Down the Chain
LEGO Certified Stores South Africa notified customers on 14 August that their email addresses and mobile telephone numbers had been accessed. The path runs retailer → Marsello (the POPIA operator running its loyalty programme) → Metabase (a reporting tool Marsello uses internally). None of the three companies’ own applications was breached. The flaw is CVE-2026-72898, an unauthenticated SQL injection with an NVD base score of 10.0, exploited on 5 August, fixed by Metabase on 6 August, applied immediately by Marsello, and confirmed to the retailer on 14 August. There are 84 Metabase instances exposed in South Africa. The technical lesson for SOC readers is the credential concentrator: a business intelligence tool holds standing connections to every database it reports on, so an administrative compromise of the reporting layer reaches data that layer was never meant to expose. Metabase’s own guidance is to rotate the credentials for every connected database — and that is the step teams skip.
Toyota South Africa — A Bulk SMS Account Turned Against the Brand
Toyota South Africa Motors confirmed that customer personal information may have been exposed through a third-party bulk SMS provider, after that provider’s account was used to push fraudulent messages advertising a gambling promotion the carmaker never authorised. The carmaker notified affected customers and stated that relevant authorities and regulators were engaged. Note the dual harm: a customer contact list is exposed and the brand’s own trusted messaging channel is used to deliver the fraud, which is materially harder for a recipient to detect than an unknown sender.
Euphoria Telecom — The Supplier Itself
Euphoria Telecom confirmed unauthorised access to its cloud environment on 16 July 2026, restricted international dialling against potentially exposed SIP credentials, rotated them, and reported the matter to the Information Regulator. This is the different case of the three: the compromise was of its own environment, and it matters because Euphoria is a supplier holding the telephony credentials of the South African businesses that buy from it — which is precisely why it restricted their international dialling before restoring it. Exposed SIP credentials mean toll fraud billed to the customer.
N-central and Cisco — Compromised, Not Merely Exposed
N-able’s own wording is that Hotfix 2 closes the way in but does not remove an actor already present, and that an environment hotfixed more than a few days late should be treated as potentially compromised. Microsoft attributes the ransomware activity to Storm-1175, which has moved from Medusa to a new strain called StormEncryptor, and assesses the intrusion likely involves CVE-2026-18577. Separately, Cisco ASA and FTD CVE-2026-20349 — a remote unauthenticated denial of service against the firewall itself — entered KEV on 11 August due 14 August, overdue by three at publication. No South African exposure figure is published for it, because the catalogue product string has no Shodan fingerprint; the 357 ASA WebVPN portals counted elsewhere in the full report are a different query and do not stand in for it.
POPIA and Regulatory
Three South African organisations exercised section 22 in three different ways within six days, and the contrast is instructive. LEGO Certified Stores issued a written notice to data subjects citing section 22(1)(b) by name, describing the compromise, the likely consequences, the measures taken and a named Information Officer as point of contact — a good working model of what the section asks for. Euphoria Telecom reported to the Regulator and notified customers, and said so on the record. Toyota notified affected customers and stated that relevant authorities and regulators were engaged — which is not the same statement. Section 22 requires notification both to the Regulator and to affected data subjects, and only Euphoria stated plainly that it had done the first. The Regulator’s own record deserves a fairer reading than this report has given it: its 2026 media statements index holds eleven entries, and the most recent — the 2 June enforcement notices — is an enforcement action, not an announcement. The Regulator does publish and does enforce. What it has not published is anything about the breaches confirmed in the past fortnight. Worth knowing separately: the Regulator is a compliance destination, not a responder. Identify which FIRST-registered CSIRT covers your constituency before you need it — the worst time to look up a telephone number is during an encryption event.
Corrections to Prior Editions
Correction 1, to W21–W33: the consecutive-week counter was wrong by three. The rolling metrics record shows the threat level HIGH without interruption from W18 onward, W17 having been the only CRITICAL week of 2026 — sixteen consecutive HIGH weeks to W33 and seventeen to W34. W32 printed a twelfth and W33 a thirteenth. The error was inherited forward without anyone recounting against the underlying record. Readers holding earlier PDFs should add three to any streak figure from W21 onward. Correction 2, to W33: the 92% ransomware figure is TrendAI telemetry, not INTERPOL’s own count. The report’s wording is “92 per cent of all ransomware detections in Africa by TrendAI”. A detection share measures where a vendor has sensors: Cabo Verde ranks second at 4%, which describes an install base rather than a ransomware problem. Leak-site counts put South Africa at roughly a fifth to a quarter of African listings. W33 attributed it to INTERPOL alone, as did most South African coverage — and this report helped spread it without saying so.
Full Intelligence Report
The complete Week 34 technical report covers the full LEGO, Marsello and Metabase chain analysis with compromise-check queries, the Toyota and Euphoria confirmations, the credential-concentrator problem in business intelligence tooling, Storm-1175 and StormEncryptor attribution, the Cisco ASA and FTD exposure, three documented corrections including the consecutive-week counter and the TrendAI attribution, South African CSIRT contact guidance, structured hunt missions with IOC tables and the full source list.
What Your Business Should Do Right Now
- Patch self-hosted Metabase, then assume compromise and rotate every connected database credential: Fixed builds are 63.5, 62.9, 61.11, 60.17, 59.21 and 58.24. Where patching must wait, block the /api/session/reset_password endpoint at the proxy. Public exploits were open-sourced from 10 August, so the window in which only the original operator could exploit this has closed.
- Run the vendor’s compromise check on Metabase: Look in application or ingress logs for a POST to /api/session/reset_password returning 400, followed by a GET to /api/user/current returning 200. If that pattern is present, delete all rows in the core_session table to revoke active sessions, audit API keys and administrator accounts, and rotate the credentials for every database the instance connects to.
- Ask your three largest data-handling suppliers three questions, in writing, this week: Which sub-processors and internal tools touch our records? What is your notification deadline to us in hours, rather than the phrase “without undue delay”? And will you tell us about an incident at your own supplier? Two of this week’s three incidents reached the victim through an operator or platform.
- Treat any Metabase or N-central instance left unpatched in the first fortnight of August as compromised rather than exposed: N-able’s own wording is that Hotfix 2 closes the way in but does not remove an actor already present. Storm-1175 is the attributed actor, now deploying StormEncryptor.
- Apply the Cisco ASA and FTD fix for CVE-2026-20349: Its KEV deadline of 14 August is already overdue. Do not use the 357 ASA WebVPN portal count as a proxy for your own exposure — that is a different query; check your own estate.
- Audit your BI and reporting tools as credential concentrators: Any tool holding standing connections to production databases reaches data it was never meant to expose if its administrative layer is compromised. Inventory them, take them off the public internet, and know which databases each one can reach.
- Use the LEGO notice as your section 22 template: It cites section 22(1)(b) by name, describes the compromise, states the likely consequences and measures taken, and names an Information Officer as the point of contact. Draft yours now, while nothing is on fire.
- Find your CSIRT before you need it: The Information Regulator is a compliance destination, not an incident responder. Identify which FIRST-registered South African team covers your constituency and store the contact details somewhere reachable during an outage.