ransomware Credible South Africa (ZA) technology

CGC SA listed by the Stormous ransomware group

CGC SA

📅 03 May 2026
CompanyCGC SA
CountrySouth Africa (ZA)
Sectortechnology
Breach date2026-05-03
People affectedNot disclosed
Ransomware groupstormous
Data typesvendor and corporate data, financial accounting records, sales order reports, database systems, Sage 200 backups, CRM and legal archives

Overview

The Stormous ransomware group has listed CGC SA (cgcsa.co.za), a South African company, on its leak site. The listing appeared on 3 May 2026 and includes a detailed inventory of the claimed data.

What was published

The group's post describes a broad set of exfiltrated material:

  • Vendor and corporate data (names, emails, phone numbers, PMS names)
  • Financial accounting records and sales order reports
  • Database systems including SQL Server and Sage 200 Evolution
  • Operational security data
  • Full Sage 200 Evolution backups including transaction history, tax records and payroll
  • CRM and legal archives with over 151,000 sensitive documents and contracts

Risks for affected individuals

  • Vendor and customer contact data may be exposed.
  • Payroll and tax records contain sensitive employee information.
  • The volume of documents increases the risk of targeted fraud.

What remains unknown

  • The total size of the exfiltration.
  • Whether the data has been published or is for sale.
  • The duration of the attackers' access.

What affected people should do

Vendors and employees should monitor their accounts and be alert to phishing referencing the company. CGC SA should notify affected parties, engage cybersecurity experts, and coordinate with South African authorities on the response.