Wednesday 9 September
Donation
SurgeZirc Media
...
Business

Cartrack Confirms Ransomware Attack As Direwolf Claims 500GB Data Theft

Vehicle tracking company Cartrack has confirmed that it suffered a ransomware attack and is investigating what information was accessed after the Direwolf group claimed it stole 500GB of data.

Share:
Cartrack Confirms Ransomware Attack As Direwolf Claims 500GB Data Theft
Cartrack Confirms Ransomware Attack As Direwolf Claims 500GB Data Theft

Vehicle tracking company Cartrack has confirmed that it suffered a ransomware attack and is investigating the extent and consequences of the incident.

Cartrack, which is owned by Nasdaq- and JSE-listed Karooooo, said it immediately took steps to secure its technical environment and limit the impact of the attack.

The company had more than 2.2 million subscribers as of May 31, 2026, according to the latest financial results published by Karooooo.

YOU MAY ALSO LIKE: FlySafair Confirms Jet Fuel Supply Disruptions At OR Tambo

The incident became public on September 2, when ransomware group Direwolf listed Cartrack on its dark web leak site and claimed to have exfiltrated about 500GB of data from the company's servers.

Direwolf alleged that the stolen information included personal and customer data.

Cartrack said it was not yet able to determine exactly what information had been accessed.

“We immediately took steps to secure our technical environment and mitigate the impact of this incident,” the company said in a statement.

“An investigation into the source, extent and implications of the incident is underway, conducted by our technology teams, with support from cybersecurity experts.”

Cartrack Says Platform Has Been Restored

Despite the ransomware incident, Cartrack said its platform remained operational and that its systems had been restored.

The company also said it had informed the relevant authorities, including South Africa's Information Regulator.

“We have notified relevant authorities, including the Information Regulator in South Africa,” Cartrack said.

YOU MAY ALSO LIKE: FlySafair Confirms Jet Fuel Supply Disruptions At OR Tambo

“We will continue to cooperate with the authorities in this regard and will provide notifications to affected parties once we have more certainty of what data was accessed.”

Cartrack said the investigation would establish the extent of the compromise before any affected customers or other parties were formally notified.

Picup Platform Not Affected

The ransomware disclosure came on the same day that Pick n Pay's ASAP! on-demand delivery platform experienced a prolonged technical disruption.

ASAP! uses Cartrack's Picup cloud services platform, raising questions about whether the two incidents were connected.

Cartrack said they were not.

In its response, the company said the Picup platform was not affected by the ransomware incident and that the event was limited to Cartrack South Africa.

Picup is also used to support delivery and logistics operations for companies including Dis-Chem, OneCart, Avo by Nedbank and Michelin.

Pick n Pay advised customers to use Mr D to place orders while its ASAP! service was experiencing problems.

Direwolf Publishes Alleged Cartrack Data

Direwolf has published folders on its dark web leak site that it claims contain information taken from Cartrack.

The ransomware group said the material included financial documents, source code, customer profile documents, non-disclosure agreements, database backups, customer information and personal data.

It has uploaded several folders as purported samples of the stolen information.

A review of the material cited by MyBroadband indicated that a significant amount of the information appeared to relate to users and companies in the United States, where Cartrack expanded in 2016.

However, the publication of material by a ransomware group does not independently establish the full extent or authenticity of the alleged data theft. Cartrack has said its own investigation is still under way.

The company has also not confirmed that the full 500GB claimed by Direwolf was accessed or removed from its systems.

New Ransomware Group Uses Double Extortion

Direwolf is described as a relatively new ransomware operation, first documented in 2025 and associated with financially motivated attacks on targeted organisations.

Its reported tactics follow the double-extortion model commonly used by ransomware groups. This involves compromising or encrypting systems while also threatening to publish stolen information unless a ransom is paid.

YOU MAY ALSO LIKE: Durban Human Trafficking Case: Businessman And Co-Accused Granted Bail As Explosive Claims Emerge

Cybersecurity research cited in the source material indicates that Direwolf had publicly claimed more than 100 victims on its leak site, with organisations across dozens of countries appearing on the list.

The group has reportedly targeted businesses in sectors including healthcare, technology and manufacturing.

Its leak site and direct communication with victims are intended to increase pressure on organisations facing operational disruption or potential exposure of confidential information.

For Cartrack, however, the full impact remains subject to the company's ongoing investigation.

Until that process is completed, it remains unclear what data, if any, was accessed, how much information was removed and whether customers or other third parties were affected.

Topics:Cartrack ransomware attackCartrack data breachDirewolf ransomwareKaroooooSouth Africa cybersecurity