The ransomware crew INC Ransom says it has stolen 500 GB of data from BCX, the South African IT services company owned by Telkom, and what it is advertising is source code rather than the usual spreadsheets. The post, recorded on 29 September by the independent tracker ransomware.live on its victim page for the claim, lists 4,224,088 files across 596,613 folders, including six business applications, more than 15 integration libraries and technical documentation.
BCX was not alone. In the seven days to 1 October our incident tracking recorded six leak-site claims against South African organisations, against 17 across the previous twelve weeks combined. Three of the six came from one crew, The Gentlemen.
Code that reads like municipal software
The application names in INC's post are the most telling part. They include a cemetery management system called Cemres, an "mSCOA Posting Level Creator", a receipting module and a single sign-on portal. mSCOA is the Municipal Standard Chart of Accounts, the classification National Treasury requires every South African municipality to use, so a tool built around it points to local government finance. If the claim is genuine, the exposure could reach councils that run BCX software, not just BCX itself.
INC also asserts that "numerous vulnerabilities" exist in current versions of those applications. It offers no detail, and the line is a pressure tactic as much as a finding, but stolen source code is exactly what an attacker would study to look for such flaws. The same tracker page carries Hudson Rock infostealer data counting 152 BCX employees whose credentials have appeared in stealer logs. That describes exposure built up over time. It does not show how this intrusion began.
INC is a long-running operation, profiled on our INC Ransom actor page, and it has recently started threatening victims with press releases to raise the stakes.
A legal insurer and a retailer that no longer trades
On 30 September The Gentlemen added two more South African names to its site. One is LegalWise, a legal-expenses insurer that the tracker's profile credits with more than 350,000 members. The other is Edcon, once the owner of Edgars, Jet and CNA. Edcon entered business rescue in April 2020 and its chains were sold off, and the tracker's profile notes that the holding company no longer trades and that its website now serves as a notice board for creditors. That makes it an odd extortion target, and the listing says nothing about what, if anything, was taken.
The same crew had already listed the insurance group Guardrisk on 26 September, which we covered in our look at African financial firms on leak sites. The Gentlemen has five South African claims in our data over the past 90 days, and three of them landed in the last five days.
Claims, not confirmed breaches
Every listing here was written by the gangs themselves. We found no public statement from BCX, LegalWise or Edcon confirming an incident at the time of writing, and crews do exaggerate, recycle old data and name firms they only touched at the edges. The leak sites sit on .onion addresses, which we do not link. One further listing filed under South Africa the same week, a fertility clinic network, appears to be Indonesian and is excluded from the count above.
Councils using BCX tools should rotate shared access now
Municipalities and other BCX customers do not need to wait for confirmation to take cheap precautions: rotate credentials, API keys and service accounts shared with BCX integrations, review single sign-on logs for unfamiliar access, and track the affected applications closely for vendor fixes. Any organisation that confirms a compromise of personal information must notify the Information Regulator under POPIA. South Africa's wider threat picture is on our South Africa country page.
Six claims in a week is a small number in absolute terms. What sets this week apart is the kind of data on offer: source code from a supplier to local government is a theft whose consequences tend to arrive months later, through whoever studies it next.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.