CSIDB logo
Incident

Qsure

Incident posture

Attack window
Jun 2021
Location
South Africa
Status
Historical
CIA posture
Available to members
Updated
2026-08-28 14:53

Linked entities

Victim
Qsure
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jun 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A South African insurance provider suffered a major data breach involving unauthorized access to its IT infrastructure, compromising sensitive financial information including banking details. The organization promptly isolated its network and shut down systems upon detecting the intrusion, though the exact number of affected records was not disclosed. The incident resulted in exposure of personal and financial data, with the company confirming the breach impacted critical customer information without providing further specifics on the scope or remediation measures.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 9, 2021, South African insurance provider QSure detected unauthorized access to its IT infrastructure, prompting immediate containment measures. The company isolated its IT network and shut down all systems upon discovering the intrusion, according to statements by Chief Operating Officer Ian du Toit to TechCentral. The breach resulted in the compromise of sensitive customer data, including banking information, though QSure did not disclose the exact number of affected records or the duration of unauthorized access prior to detection. No additional technical details regarding the attack vector, threat actor identity, or specific compromised systems were released publicly. The incident represented a significant operational disruption, necessitating full system shutdowns to prevent further data exfiltration or damage.

The data breach exposed financially sensitive information, creating potential risks for customer fraud and identity theft, though QSure did not quantify these risks or confirm any malicious use of stolen data. Public reporting by Brett Venter indicated the breach qualified as a "major" incident based on the sensitivity of the compromised banking details. QSure's communications emphasized the illegal nature of the access but provided no forensic timeline beyond the June 9 detection date. The company did not release information regarding third-party forensic investigations, regulatory notifications, or customer remediation efforts such as credit monitoring. Media coverage highlighted public skepticism through social media commentary, including sardonic remarks about the insurer's own need for cyber insurance coverage following the breach.

Sources

Sources available to members: 1 source.

CSIDB