• Skip to main content
  • Skip to header right navigation
  • Skip to after header navigation
  • Skip to site footer
MyZA

MyZA

News, Directory, Events and Other Stuff

  • Social Media
  • Sport
  • World News
  • Home
  • Submit News
  • Directory
  • Events
  • Stratlec
  • TFSA
  • News
    • APO
    • Today’s Sport News
    • Todays Social Media and Tech Headlines
    • Today’s World News
    • Today’s SA Financial News
  • Contact
You are here: Home / News / New Bank Takes Swift Action After Groundup Alerts It to Data Breach

New Bank Takes Swift Action After Groundup Alerts It to Data Breach

24 April 2026 by Guest

But the Information Regulator is missing in action

To its credit eNL Mutual Bank took full responsibility and acted swiftly when GroundUp’s IT consultant discovered a data breach.

  • GroundUp’s IT consultant, Joel Cedras, discovered that eNL Mutual Bank had inadvertently made confidential customer information, including transactions, publicly available.
  • The bank, to its credit, responded swiftly, removing the public facing URL and taking full responsibility for the error.
  • But we also informed the Information Regulator, an institution that is funded with substantially more than R100-million a year. The process of informing the regulator was cumbersome and we’ve received no response from it.

A new bank, eNL Mutual (previously YWBN), took swift action to plug a data breach after an IT consultant contracted to GroundUp discovered it.

eNL was granted a banking licence by the Reserve Bank in January 2024. It operates online; there are no branches. The bank’s website explains that the “e” prefix denotes digital banking. NL are the initials of the bank’s founder, Nthabeleng Likotsi. The bank markets itself as the country’s “first black-owned, women-led mutual bank”.

Last Thursday (16 April), we realised the bank was making confidential customer data available on a public URL: enlsystembo.co.za and the corresponding IP address 102.131.62.58. It is important to emphasise that no cracking (hacking), password-guessing or any unlawful or legally grey activities were needed or used to access enlsystembo.co.za. Any person with an internet connection and a browser could access this URL’s file system and the data stored there.

The data leaked included personal information (full names, SA ID numbers, addresses, emails, phone numbers), bank account details (account numbers, balances) and full transaction histories. It also included unencrypted card information, as well as database credentials, which could potentially be used by an attacker to manipulate financial data.

We received legal advice that this was in breach of the Protection of Personal Information Act (POPIA) and that the Information Regulator (IR) was responsible for dealing with this.

Table of Contents

Toggle
  • Information Regulator does nothing
  • Swift response from the bank
  • Financial data
  • Internal Bank Operations
  • Bank System

Information Regulator does nothing

Informing the IR was onerous. We emailed the IR and received an automated response stating that complaints were no longer accepted via email. We had to use the IR’s content management system to file our “complaint” (we were less interested in complaining and more interested in alerting the IR to the problem, but the complaint mechanism appeared to be the only way to inform the IR of the problem).

After navigating the IR’s tedious, friction-filled system, we finally managed to lodge a complaint. We did not hear back from the IR despite the obvious urgency of the situation. The IR’s annual budget is well over R100-million.

We also notified the Reserve Bank and Financial Sector Conduct Authority. Other than a perfunctory, possibly automated, reply from the latter, we have not heard from either institution.

Swift response from the bank

On Friday noon we alerted the bank. Shortly thereafter the URL and corresponding IP address became inaccessible. eNL subsequently corresponded with us. To the bank’s credit it took full responsibility for the breach, is investigating it, notifying affected customers and taking steps to strengthen its security.

“We would like to acknowledge that a security misconfiguration in a non-production environment led to the unintended exposure of certain data through a publicly accessible endpoint,” the bank informed us.

“As a bank, we remain fully accountable for the protection of customer information, regardless of whether systems are managed internally or by third-party service providers. We are formally treating this as a data leakage incident and are following all required reporting and notification processes. This includes engagement with the Information Regulator (South Africa), the South African Reserve Bank and other relevant regulatory authorities. In line with our legal obligations, we will also notify affected customers directly.”

Read the bank’s full response.

On Thursday 16 April, based on the network requests made by eNL Mutual Bank’s mobile app, we noticed that the ISP being used was Village Operator.

Searching for this ISP on the internet search engine Shodan resulted in us finding a server belonging to eNL, hosted on IP address 102.131.62.58, and resolving to enlsystembo.co.za. We noticed that this host was flagged by the search engine as having an open directory, and upon further investigation, we confirmed this to be the case. This system has been crawled by the search engine Shodan since March, and their historic results show that the directory hosted on the server has been open since the initial crawl.

Here is a summary of the data that was open to the public:

Financial data

  • Personal information (full names, SA ID numbers, addresses, emails, phone numbers)
  • Account details (bank account numbers, balances, dates that accounts were opened)
  • ⁠Full transaction history spanning months for every account
  • ⁠Unencrypted Card Data (16 digit card numbers [PANs] as well as Track 1 and Track 2 magnetic stripe data, which can be used to directly clone cards) (this is a PCI-DSS violation, even though only a few cards appear to have been issued)

Internal Bank Operations

  • Bank Reconciliation Logs – internal EFTs, real time clearing (RTC) reports, and Bankserv Magtape and Settlement reports
  • ⁠Internal Accounting – General Ledger (Sage) exports showing daily transaction volumes, internal codes, and internal financial movement

Bank System

  • Hardcoded database password: the database IP, username, and password was sitting in plain text inside configuration files and scripts [also a database username and password for eZaga]
  • ⁠Hardcoded email/SMTP passwords: emails and their passwords scattered around processing scripts in plain text [belonging to [email protected]]
  • ⁠SMS Service login credentials (BulkSMS.com)
  • Proprietary Banking Logic including PHP source code and SQL statements responsible for sensitive operations like AVS, RTC, EFT, and internal debit routing

© 2026 GroundUp. This article is published under the GroundUp Republication Licence Version 1.0. Email [email protected] to request permission to republish.

Loss of biodiversity: Decline in plant and animal species.

Read More at the Source

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • Print (Opens in new window) Print
  • Email a link to a friend (Opens in new window) Email
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
Category: NewsTag: 2024, ACT, Africa, African, Alerts, App, Budget, CAN, Connection, customer, data, digital, Directory, Environment, GroundUp, Latter, Lodge, march, new, production, show, South Africa, Women

If you feel strongly about this article then feel free to send MyZA a ‘Letter to the Editor’ using the submission form below:


Letter to the Editor

This field is for validation purposes and should be left unchanged.
If this is in response to an article please include that article title here or as the lead in for the first paragraph of your Letter below.

Separate tags with commas

Localise your letter by naming the city your words are about. Add relevant words describing your subject. Single comma separated words of no more than 5
Your Name(Required)
Your Name will be linked to the website below.
Your personal, business or social media web site
Choose NO to not set up a user account on MyZA. User Accounts will allow you to submit letters under your own Author Name

3 Latest Letters to the Editor:

  • Fun South African fact

    Dear Editor Fun South African fact: towns like Franschhoek and Stellenbosch are home to world-class wine farms set in stunning, scenic surroundings. Regards Aressa Smith In Response to/From: Luxury Properties Seized in New Lottery Crackdown

    27 January 2026
  • Condolences on the Passing of Lusanda Dumke

    Statement by Leander Kruger MPL – DA Buffalo City Constituency Leader: The Democratic Alliance in Buffalo City Metropolitan Municipality mourns the passing of Springbok Women’s rugby player and Mdantsane trailblazer, Lusanda Dumke, who lost her battle with cancer at the age of 28. South Africa has lost an exceptional athlete, a leader, and a source…

    17 December 2025
  • Rape Kits Delivered, But…

    Statement by Nicholas Gotsell MP – DA NCOP Member on Security & Justice: The DA can confirm that 2 840 rape kits arrived in Cape Town on Monday, following sustained DA oversight and pressure after multiple police stations across the Western Cape were found to be without this critical forensic evidence tool. While this delivery…

    17 December 2025

About Guest

Previous Post:PanSALB and isiXhosa Bible Review Committee of the Bible Society of South Africa hands over revised isiXhosa Bible | SA News
Next Post:Blyde Chalet Development in Graskop Halted

Reader Interactions

Comments

  1. Icedog

    30 April 2026 at 2:55 pm

    Fun South African Fact: The Bloukrans Bridge, Western Cape, is the highest commercial natural bungee jump in the world.

  2. Drop Stone

    28 April 2026 at 11:04 am

    What do you call an Afrikaans guy that squeezes chickens?

    Hendrik.

Copyright © 2026 · MyZA · All Rights Reserved · Powered by Reach Trust