Shoprite Group, 2022: extortion comes for Africa's largest retailer
In June 2022, Shoprite Group — the largest supermarket chain on the African continent, operating across more than a dozen countries — announced that it was investigating a suspected data compromise. Within days, an extortion group called RansomHouse claimed responsibility, making Shoprite one of the most prominent African retail names to face data-theft extortion.
What happened
Shoprite disclosed on 10 June 2022 that it had become aware of a suspected data compromise potentially affecting a subset of customers who had engaged in money transfers to and within Eswatini, Namibia and Zambia. The company said the data involved names and ID numbers, and that no financial information such as bank account or card details had been compromised.
RansomHouse — a group that describes itself as extorting organisations over stolen data rather than encrypting systems — claimed the attack on its leak site, asserted that it had obtained a large volume of data, and posted a sample said to contain customer information. The group taunted the retailer over its security posture. Shoprite said it had immediately locked down the affected systems, engaged forensic experts, notified regulators, and warned affected customers via SMS to be alert to fraud attempts. The company continued trading normally throughout.
How the attack worked
Shoprite did not publicly confirm how the attackers obtained access, and no verified technical account of the intrusion has been published. RansomHouse's own public statements blamed weak protection of the data rather than describing an exploit, but claims made by extortion groups serve their negotiating position and cannot be taken at face value.
What the case does illustrate cleanly is the shift in criminal tactics: data-theft extortion without encryption. There is no ransomware lock screen, no operational outage to detect — just quiet exfiltration followed by public pressure. This model makes the human and detection layers even more decisive, because the first visible sign of compromise may be the attacker's leak post rather than a system failure.
The impact
The immediate operational impact on shoppers was limited — stores and systems kept running — but the incident carried real consequences. Money-transfer customers in three countries had identity data exposed, with the fraud and phishing risk that follows. Shoprite had to run cross-border notification and regulatory engagement in multiple jurisdictions, including under South Africa's POPIA regime, and absorb the reputational cost of an extortion group publicly parading its name. For the wider region, the incident signalled that pan-African retail and financial-services hybrids — companies holding identity data across many countries — are now squarely in extortion groups' sights.
Lessons for African organisations
- Data-theft extortion needs no ransomware. Monitor for exfiltration — unusual outbound transfers, bulk queries, staging archives — not only for encryption events.
- Minimise what you keep. The exposed data came from money-transfer services. Retaining only what regulation requires, for as short a time as required, directly shrinks the blast radius.
- Cross-border operations mean cross-border obligations. A single incident can trigger notification duties in several jurisdictions at once; map them before an incident, not during one.
- Customer warning is damage control. Shoprite's rapid SMS alerts helped customers defend themselves against follow-on fraud — the harm from identity data appears downstream, in phishing that exploits it.
- Expect to be taunted. Extortion groups weaponise publicity. A communications plan that assumes hostile public claims keeps the organisation factual and calm.
Sources
- Shoprite Group public statement on the suspected data compromise, June 2022
- BleepingComputer reporting on the RansomHouse claim and leak-site posts, 2022
- ITWeb and South African media coverage, 2022
- Regulatory notification coverage under POPIA, 2022
Quiet exfiltration is caught by alert people and tested processes — see how ready yours are with the free Human Risk Maturity Assessment.