DATA BREACH: Hungry Lion latest victim in concerning rise of cyberattacks
You know the cybersecurity situation in SA is getting bad when not even Hungry Lion is safe. The threat group is asking for $50k ransom, and it’s the same crowd that got The Courier Guy. It’s getting bad.
A dark web threat intelligence sweep has identified a new listing targeting the prominent fast-food franchise Hungry Lion. The attack has been claimed by the MeduzaLocker ransomware group, the same threat actor responsible for the high-profile cyberattack on logistics provider The Courier Guy.
The listing identifies Hungry Lion as a major quick-service restaurant chain operating 111 locations across South Africa, Botswana, Angola, Namibia, Zambia, Zimbabwe, Lesotho and Mauritius.
Our friends in the threat intelligence business, Dark Notify, did the analysis and indicated to Daily Maverick that core customer privacy remains intact: “After manually analysing the data they put up as evidence, it doesn’t seem like any PII [read: personally identifiable information] was breached...”
Rather than a database of personal credentials, the compromised files are structural Point of Sale system outputs.
Standard Bank CIO Jorg Fischer was quick to write off a similar data breach as nothing more than Microsoft SharePoint data, but that one was a cache of ID and passport numbers, active credit card numbers and driver’s licences.
Both breaches reveal that corporate networks remain vulnerable to unstructured and decentralised systems. Standard Bank’s leak originated in its unstructured (Excel sheets and PDFs), while Hungry Lion’s leak highlights the vulnerability of localised branch-level POS import logs.
But it’s the timing that is most concerning, as well as the acceleration of these kinds of attacks – fake or not.
South Africa made significant progress when it was officially removed from the Financial Action Task Force (FATF) grey list on 24 October 2025, following a gruelling 32-month monitoring period.
However, we are still undergoing an 18-month mutual evaluation process scheduled to conclude in October 2027, with a critical on-site assessment scheduled for March 2027.
A rising tide of uncontained corporate and public data breaches – such as Standard Bank, Liberty, and Hungry Lion – directly threatens to slide South Africa back on to the grey list.
Why? Because the FATF, in partnership with Interpol and the Egmont Group, has identified the proceeds of cyber-enabled fraud as one of the fastest-growing illicit financial flows globally.
A surge in major data breaches provides the raw material (names, IDs, credit cards, transaction habits) to feed what Check Point’s local head of security consulting Hendrik de Bruin calls an “assembly line built on personal information”.
This stolen data is used to conduct highly convincing, automated financial fraud, multiplying the volume of untraceable, illicitly laundered capital moving through South African banks.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.dailymaverick.co.za — the content belongs to Daily Maverick.