RelyComply Security Compromise

Peregrine Capital Collective Investments (RF) (Pty) Ltd uses RelyComply, a third-party service provider, to verify client identities as required by the Financial Intelligence Centre Act. RelyComply is an established South African AML and KYC compliance platform used by several regulated financial services providers. RelyComply has informed us that it experienced a security incident and that some of its data has been compromised. Investigations are ongoing to determine the extent of the incident and to confirm whether our clients’ records were held in the affected environment. Peregrine’s own systems were not accessed or compromised and your investments are not impacted in any way. Investment values, account balances and online login credentials are held on Peregrine’s systems and were not involved or compromised.

The information affected may include the following: name, identity, passport or company registration number, date of birth, contact details, residential address and bank account details.

Measures we have taken

  • Notified the Information Regulator.
  • Paused the transfer of client information to RelyComply and have confirmation from RelyComply that the environment has been contained. We are still waiting for RelyComply to provide its forensic findings.
  • Introduced additional verification before acting on any instructions to change banking or contact details and/or process any withdrawals.

What you can do

You don’t need to take any action, but we recommend the usual precautions and remain vigilant. Information of this kind could be used for attempted identity theft or phishing, so be cautious of unexpected calls, emails or messages asking for personal or financial information, even if the sender appears to know your details. Peregrine will never ask you for a password or one-time codes. Keep an eye on your accounts and be vigilant against attempts at fraud.

Queries may be directed to: JP Hamman on +27 11 722 7406 or datasecurity@peregrine.co.za