What Business Owners Need to Know This Week
Week 37 (30 August–5 September 2026) delivered the first confirmed compromise of South African bulk water infrastructure this series has carried. Rand Water, which supplies more than 16 million people across Gauteng and parts of the Free State, North West and Mpumalanga, confirmed its network was breached and servers damaged — and it disclosed on 3 September because it has listed debt on the JSE and owes its bondholders a statement. In the same week the Information Regulator revealed it holds more than 8,000 security compromise notifications, and the FSCA and Prudential Authority switched on a 24-hour material incident notification clock for financial institutions.
The Bottom Line: This week’s board question is not which software you run — that was last week’s — but who is obliged to tell you when something breaks. Rand Water told the market because of its bonds. A public body without listed instruments owes no equivalent disclosure, because South African law compels notification only where personal information is involved. Three different disclosure regimes, one country, and only one of them produces anything a peer organisation can learn from. The absence of reported incidents in your sector is not evidence of their absence, and your assurance work cannot lean on it.
The Week in Numbers
- 16 million people — served by Rand Water, whose network breach was confirmed on 3 September; HIGH threat level for the 20th consecutive week.
- 8,000+ breach notifications — held by the Information Regulator to date, of which 1,220 arrived since April, on a trajectory the chairperson expects to exceed 3,000 for the year.
- 90 days — the deadline in the enforcement notice issued against the South African Bureau of Standards following its 2024 ransomware attack.
- 3,800+ complaints — received by the Regulator in the past year, about 10% concerning direct marketing; OUTsurance and MTN matters went to the Enforcement Committee.
- 10 new KEV additions — between 31 August and 4 September, five already past their remediation date at publication.
- CVSS 10.0 — SonicWall SMA 1000 CVE-2026-83548, pre-authentication SSRF, chainable with CVE-2026-83549 so the command injection is reachable without credentials.
- 52 days — how long the July SonicWall pair has been overdue. That is the third exploited SMA 1000 chain this report has tracked.
- 3 emergency patches — shipped for PaperCut NG and MF, because the first two were bypassed. A Metasploit module is public.
- 100 GB — claimed by DireWolf from Cartrack Holdings on 2 September, the group’s first South African victim. CLAIMED; no statement from Cartrack or parent Karooooo.
- 24 hours — the new FSCA and Prudential Authority material incident notification clock, effective 1 September, which runs over weekends.
Major Incidents: Who Was Hit and How
Rand Water — Bulk Water Infrastructure Confirmed Breached
Rand Water disclosed the incident on 3 September in a statement to holders of its listed debt on the JSE, saying it was responding to a cyber security incident affecting certain information technology systems while water treatment, water quality control and bulk supply remained fully operational. Its debt officer told ITWeb that the intrusion was detected at night, that attempts to block it came too late, and that the utility is now running from its disaster recovery site in Centurion while equipment at its main site is sanitised and replaced. No actor has been named and no ransomware family attributed. Two things are worth holding separately: the operational technology that treats and moves water was not reported affected, and the disclosure happened at all only because of a bondholder obligation.
SonicWall SMA 1000 — Re-Image, Do Not Patch
CVE-2026-83548 (CVSS 10.0, pre-authentication server-side request forgery) and CVE-2026-83549 (post-authentication command injection) can be chained, according to Rapid7, so that the command injection is reachable without credentials. Both were due 5 September. SonicWall’s own notice confirms active exploitation and — critically — tells customers who find indicators to re-image the appliance rather than patch it, contact Support for an indicator review, change every user and administrator password and reset TOTP tokens. Fixed builds are 12.4.3-03526 and 12.5.0-02952. If you still have the July pair (CVE-2026-15409 / CVE-2026-15410) outstanding, that appliance has been reachable and exploitable for 52 days and should be rebuilt regardless of what this week’s patch does.
PaperCut — Check Which Emergency Patch You Are On
PaperCut NG and MF entered the catalogue on 31 August with a pre-authentication chain, and the vendor has now shipped three successive out-of-band releases because the first two were bypassed. Rapid7’s guidance is explicit: an organisation running either the first or the second emergency patch is not fully protected and must apply the third. A Metasploit module for the chain is public, which moves this from targeted to commodity risk. Versions 23 and earlier have no patch at all and must be upgraded. Print management is chronically under-inventoried — check whether you run it before concluding you do not.
Cartrack Claimed by DireWolf
DireWolf listed Cartrack Holdings on 2 September, claiming 100 GB — the only new South African leak-site entry in the window and the group’s first South African victim. Neither Cartrack nor its parent Karooooo has made any public statement, and the Karooooo JSE SENS index carries nothing later than 28 July, so the item is rated CLAIMED.
POPIA and Regulatory
The Information Regulator held its briefing on 31 August and produced the most useful number South African breach reporting has had: more than 8,000 security compromise notifications to date, 1,220 of them since April. Chairperson Advocate Pansy Tlakula called the position very alarming and said the Regulator is not sure public and private bodies are as alarmed as it is. The enforcement content was substantial — and the framing matters for any board: the SABS enforcement notice was issued because an own-initiated assessment found compliance failures across several POPIA conditions, including excessive processing, inadequate consent mechanisms and insufficient safeguards, not because SABS was the victim of a cyberattack. What the assessment turns up afterwards is what carries the finding. Two direct-marketing matters involving OUTsurance and MTN went to the Enforcement Committee, and two Madlanga Commission referrals were disclosed. But checked on 6 September, the enforcement-notices register carries nothing later than 16 April 2025: the SABS notice was described at a press conference and is not on the public register, and no media statement, assessment report or guidance note was published. On an issuance reading the Regulator acted; on a publication reading it did not, and this report measures publication because the metric is what a peer organisation can read and learn from. Separately, the FSCA and Prudential Authority 24-hour material incident notification requirement took effect on 1 September — and it runs over weekends.
Full Intelligence Report
The complete Week 37 technical report covers the Rand Water disclosure and critical-infrastructure analysis, the full Information Regulator briefing including the SABS enforcement notice and Madlanga referrals, all ten catalogue additions with fixed versions, the SonicWall re-imaging guidance and 52-day carryover, the PaperCut patch-bypass chain, the new FSCA and Prudential Authority notification regime, structured hunt missions with IOC tables and the full source list.
What Your Business Should Do Right Now
- Deal with SonicWall SMA 1000 immediately, and treat patching as insufficient: CVE-2026-83548 and CVE-2026-83549 were due 5 September. Apply builds 12.4.3-03526 or 12.5.0-02952, contact SonicWall Support for an indicator review, and where indicators are found, re-image or re-deploy the appliance, change every user and administrator password and reset TOTP tokens.
- Rebuild any SMA 1000 still carrying the July flaws: If CVE-2026-15409 or CVE-2026-15410 is outstanding, that appliance has been reachable and exploitable for 52 days. Rebuild it regardless of what this week’s patch does — a patch does not evict an actor who is already inside.
- Check whether you run PaperCut, and which emergency patch you are on: Three successive out-of-band releases have shipped because the first two were bypassed. Running the first or second means you are not protected. A public Metasploit module makes this commodity risk. Versions 23 and earlier have no patch and need upgrading.
- Ask your utilities, medical schemes and outsourced administrators what they would actually tell you: Rand Water told the market because of its listed debt. Most third parties holding your data have no equivalent trigger, and POPIA compels notification only where personal information is involved.
- Add a contractual notification clause with a stated hour count to your next three supplier renewals: “Without undue delay” is not a deadline. For regulated financial institutions, align it with the FSCA and Prudential Authority 24-hour material incident template effective 1 September — outsourcing the function does not outsource the obligation.
- Note that the 24-hour clock runs over weekends: If your incident process depends on reaching a named individual during office hours, it will miss a Saturday detection. Test the out-of-hours path before you need it.
- Read the SABS notice as a warning about assessments, not attacks: The enforcement action followed an own-initiated assessment finding excessive processing, inadequate consent mechanisms and insufficient safeguards. Being breached invites the assessment; what the assessment finds is what carries the penalty. Review your own processing scope and consent mechanisms now.
- Stop treating sector silence as assurance: The Regulator holds over 8,000 notifications it does not publish. If your risk assessment says “no incidents reported in our sector”, that sentence is measuring publication, not safety.