VIRGIN ACTIVE SOUTH AFRICA
RelyComply Incident — Frequently Asked Questions
Last updated: 22 September 2026
This FAQ explains a cybersecurity incident at RelyComply, a service provider used by Virgin Active's payment provider, Peach Payments. It covers what is known, the information involved, the action taken and what members should do. The investigation is continuing, so this page will be updated as material new facts are confirmed.
Important If Virgin Active has sent you a direct notification, our checks show that information linked to one or more of your payment transactions was in the affected data. That does not mean every field relating to you was viewed, copied, or misused. |
Key points
|
1. Understanding the incident
1.1 What happened?
RelyComply became aware on 8 September 2026 that an unauthorised party had accessed part of the environment where it processes some customer data. Its statement says the attacker exploited a zero-day flaw in a third-party application. Independent forensic specialists are investigating.
Peach Payments then told Virgin Active that transaction-monitoring data for certain Virgin Active payments may have been accessed. The two are working together to identify the members and information involved.
1.2 Who are Peach Payments and RelyComply, and why did RelyComply hold my transaction data?
Peach Payments processes payments for Virgin Active and used RelyComply for compliance and transaction monitoring. Limited transaction and customer information was supplied to RelyComply so that fraud and payment-risk patterns could be detected. RelyComply did not receive the full card data needed to authorise a transaction.
1.3 What is the incident timeline?
Date | Event |
Around 2 September 2026 | Unauthorised access may have begun around this date. |
8 September 2026 | RelyComply detected the incident and notified affected customers, including Peach Payments. |
9 September 2026 | End of the transaction-data period identified in Peach Payments' notice. |
12 September 2026 | RelyComply confirmed indicators that transaction-monitoring data supplied by Peach Payments may have been accessed. |
15 September 2026 | Virgin Active received Peach Payments' section 22 notice and began validating affected members. |
16 September 2026 | RelyComply published its incident statement and protective guidance. |
22 September 2026 | This FAQ was last updated. The forensic investigation remains ongoing. |
1.4 Was Virgin Active's own network or membership system compromised?
No. There is no evidence that Virgin Active's systems were accessed, and RelyComply found no evidence of movement into any customer network. The affected data sat in RelyComply's environment after being supplied through Peach Payments.
1.5 Who was responsible, and has the incident been contained?
A group calling itself 'Direwolf' has claimed responsibility. RelyComply says it cannot identify those behind the attack, so Virgin Active treats the claim as unverified and relies on the forensic evidence.
RelyComply reports that the access has stopped, the vulnerability is patched, the affected environment has been rebuilt and monitoring shows no further unauthorised activity. This remains subject to forensic verification, and Virgin Active will update affected members if the position changes.
2. Who may be affected and why notices are being sent
2.1 Who may be affected, and how will I know?
Members whose payment transactions were included in the transaction-monitoring data supplied to RelyComply during the identified period. Peach Payments' notice covers Virgin Active transaction data from 7 May to 9 September 2026. Not every member, and not every transaction in that period, was affected.
Virgin Active is sending a direct section 22 notification to the members identified. A genuine notice explains the incident, the information relevant to you and the precautions to take. If you are unsure about a message, do not use its links or contact numbers — reach Virgin Active through its official website.
2.2 Why am I being notified before the investigation is finished?
Section 22 of POPIA requires notification as soon as reasonably possible once there are reasonable grounds to believe personal information has been accessed by an unauthorised person. The Information Regulator's guidance is not to wait for a final forensic conclusion, but to issue updates as facts are confirmed.
2.3 Why is there a website notice as well as a direct notice?
POPIA allows notice by email, post, or prominent website publication. This FAQ supplements the direct notices, carries updates, and gives members a way to check what is genuine.
3. Information involved and possible consequences
3.1 What information may have been affected?
The fields depend on what was linked to the relevant transaction, and may include:
- name, email address, mobile number, country and shopper or customer identifier;
- billing and delivery address;
- transaction date and time, amount, currency, payment method, card brand, and transaction outcome;
- order, reference and merchant identifiers, and recurring-payment, mail-order/telephone-order or 3-D Secure indicators;
- the IP address of the device used for the transaction; and
- limited card information: the first six and last four digits, expiry date, cardholder name, card country of issue and whether the card was international.
Not every field was populated for every affected transaction or member.
3.2 What information was not included?
Peach Payments has confirmed that it did not share full card numbers, PINs, CVV codes, passwords, or banking credentials. The affected data also excludes Virgin Active health and fitness records, club-access history, and identity documents. If the investigation identifies further categories, Virgin Active will tell affected members.
3.3 Does inclusion mean my information was copied or misused?
Not necessarily. The evidence supports a reasonable belief that the attacker may have accessed systems holding the data, but the investigation may never establish whether an individual record was viewed or copied. No misuse of member information has been confirmed. Virgin Active is notifying affected members as a precaution, as POPIA does not require it to wait for evidence of misuse.
3.4 What could someone do with this information?
Targeted phishing or social engineering. A criminal could quote a real payment amount, date, contact detail, or partial card number to make a fake call, email or message look genuine or combine the data with information from elsewhere to attempt fraud or impersonation. Partial card details alone cannot usually authorise a transaction but should still be treated as confidential.
3.5 Do I need to replace my card, cancel my debit order, or change my password?
Not on what is currently known: full card numbers, PINs and CVVs were not supplied to RelyComply, and Virgin Active passwords were not part of the affected data. Keep checking your statements and contact your bank on an official number if you see an unfamiliar transaction. Do not cancel a Virgin Active payment instruction without arranging an alternative, as this may affect your membership. As a general precaution, change any password you reuse elsewhere and switch on multi-factor authentication.
4. What the organisations are doing
4.1 What has RelyComply said it has done?
In its statement of 16 September 2026, RelyComply said it:
- appointed independent legal advisers and forensic investigators and activated its incident-response process;
- took the affected systems offline, rebuilt the environment, and patched the zero-day and other vulnerabilities found during the investigation;
- rotated credentials, required customers to rotate API tokens, refreshed single sign-on, and tightened logging, monitoring and attack-surface controls; and
- notified affected customers, reported the incident to the Information Regulator under reference SC20263150, and continued its forensic investigation and monitoring.
4.2 What has Peach Payments done?
Peach Payments' section 22 notice to Virgin Active states that it:
- suspended all transmission of data to RelyComply and moved the affected services to an alternative provider;
- rotated credentials, API tokens, and integration secrets, and reviewed its systems for indicators of compromise;
- instructed external legal counsel, engaged RelyComply's forensic representatives, and assessed its legal and regulatory obligations; and
- notified affected customers and reported the incident to the Information Regulator under reference SC20263231.
4.3 What is Virgin Active doing, and has the Information Regulator been notified?
Virgin Active has escalated the incident to its Privacy, Legal and Information Security teams, worked with Peach Payments to validate the affected members and data fields, begun direct notification, and continues to assess latest information from Peach Payments and RelyComply.
RelyComply has reported the incident to the Information Regulator under reference SC20263150 and Peach Payments under SC20263231. Virgin Active has begun its own notification. Each organisation notifies separately because their roles and affected data subjects differ.
4.4 Is anyone monitoring my bank account or credit report?
No. Virgin Active cannot access or monitor a member's bank account, credit-bureau file, or credit applications. The incident measures — forensic investigation, containment, credential rotation, system review, enhanced monitoring, and member notification — are not personal credit or identity-theft monitoring. For that extra layer, review your credit report from a registered bureau and consider the Southern African Fraud Prevention Service's free protective registration at www.safps.org.za.
4.5 Will I be told if material added information is discovered?
Yes. Virgin Active will issue a further update if the investigation materially changes the information in your notice, the consequences for you or the precautions you should take. Routine technical developments will simply be reflected here.
5. What members should do
5.1 What precautions should I take now?
- Be wary of unexpected calls, emails, messages, or social-media contact about Virgin Active, Peach Payments, RelyComply, a recent payment or this incident.
- Never share a password, PIN, CVV, one-time password or authentication code. Neither Virgin Active nor your bank will ask you to.
- Do not open links or attachments in an unexpected message. Go to the official Virgin Active or bank website or app yourself.
- Check your bank and card statements regularly and report anything unfamiliar to your bank immediately on an official number.
- Review your credit report for unfamiliar enquiries or accounts, especially after an unexpected credit-application message.
- Change any password you have reused elsewhere and switch on multi-factor authentication where available.
- Keep suspicious messages — sender details, date, time, and screenshots — and report them to SAPS Crime Stop on 08600 10111.
- Consider free protective registration with the Southern African Fraud Prevention Service at www.safps.org.za.
5.2 How can I spot a phishing or social-engineering attempt?
Warning signs include urgency or threats, requests for credentials, pressure to move money to a 'safe' account, requests to install software, an unexpected refund or payment link, an altered sender address, or a caller who uses genuine transaction details to win trust. Knowing your name, payment amount or partial card number does not prove a contact is genuine. If someone mentions 'Direwolf' or claims to hold your information, do not reply, pay, or click — keep the message and report it to SAPS Crime Stop on 08600 10111.
5.3 What should I do if I see an unauthorised transaction or suspect identity fraud?
Contact your bank or payment provider immediately, ask it to secure the account or card, and follow its fraud-dispute process. Keep the evidence, tell Virgin Active, and consider reporting suspected criminal conduct to the police. You can also obtain your credit report from a registered bureau and use the Southern African Fraud Prevention Service's free protective registration, which asks participating organisations to take extra care when your identity details are used.
5.4 How can I check that a Virgin Active notification is genuine?
Do not rely on a link or telephone number in a message you are unsure about. Go to the official Virgin Active South Africa website or Help Centre yourself and use the published contact channel. Virgin Active will never ask for your PIN, CVV, banking password or one-time password.
6. Your POPIA rights and requests
6.1 Can I ask what information Virgin Active holds, or have it corrected or deleted?
Yes. Subject to POPIA's procedures and lawful limits, you may ask what personal information Virgin Active holds about you and request access to it, and you may request correction or deletion under section 24 where information is inaccurate, out of date, excessive, misleading, unlawfully obtained or no longer authorised to be retained. Virgin Active may need to verify your identity first. This is not an unconditional right to erasure: some records must be kept for your membership or payments, tax and accounting, a dispute or chargeback, a fraud investigation, or legal claims. Virgin Active will explain the outcome of a verified request.
6.2 Can I ask Virgin Active to delete the bank or payment details linked to my membership?
You may. Virgin Active will verify your identity and assess each field against its purpose and legal retention obligations. Anything no longer necessary may be deleted or de-identified, but records needed for an active membership, payment reconciliation, audit, tax, disputes, chargebacks, fraud prevention, or legal claims must be kept. If you remove a current payment method, you will need to provide an alternative to keep your membership in good standing.
6.3 Will deleting my information undo the incident?
No. A deletion request cannot reverse access that may already have occurred in RelyComply's environment, and it does not extend to security logs, forensic evidence or records that must lawfully be preserved. Virgin Active can act on information within its control and pass appropriate requests to its operators.
6.4 How do I exercise my rights or raise a complaint?
Contact Virgin Active using the details in your notification or through the official Virgin Active South Africa Help Centre. Say that your request concerns the RelyComply incident and describe what you are asking for. Never send a full card number, PIN, CVV, password or one-time password.
If you believe your personal information has been managed in breach of POPIA, you may complain to the Information Regulator; its website sets out the complaint form and current submission channels. Contacting Virgin Active first does not affect that right.
7. Further information and updates
7.1 Where can I read the other organisations' statements?
RelyComply published 'RelyComply cyber incident: what happened and what you can do' on 16 September 2026 on its website, and lists incident@relycomply.com for incident-specific questions. The Peach Payments information in this FAQ comes from its formal section 22 notice to Virgin Active rather than a public FAQ. Virgin Active cannot control the content of external websites.
7.2 Where will Virgin Active publish updates?
Material updates will go directly to affected members where appropriate and appear on Virgin Active's official South African website or Help Centre. If you are unsure whether an update is genuine, navigate to the official site yourself.
Sources and useful links
- RelyComply incident statement (16 September 2026)
- Protection of Personal Information Act 4 of 2013 (POPIA)
- Information Regulator: Fact Sheet on Handling of Security Compromises (2025)
- Information Regulator: POPIA forms
- Southern African Fraud Prevention Service: fraud prevention and protective registration
- Virgin Active South Africa privacy policy
Notification under section 22 of the Protection of Personal Information Act, 2013Dear Member, We are writing to inform you of a cybersecurity incident involving RelyComply, a third-party service provider used by our payment provider, Peach Payments, for transaction-monitoring and compliance purposes. We understand that receiving a notice of this nature may be concerning. This notice explains what happened, how your personal information may have been affected, the actions taken in response and the steps we recommend that you take.
On 8 September 2026, RelyComply notified Peach Payments of a security incident involving unauthorised access to RelyComply’s systems. The information currently available indicates that the unauthorised access may have commenced on or around 2 September 2026. A threat actor group identifying itself as “Direwolf” has publicly claimed responsibility for the incident. RelyComply has advised that it believes the incident has been contained, subject to ongoing forensic verification, and that independent digital forensic specialists are investigating the incident. Virgin Active received formal notification from Peach Payments on 15 September 2026. Since then, we have been working with Peach Payments to establish the impact on Virgin Active and identify the members whose information was involved. Why we are contacting youPeach Payments’ records confirm that information associated with one or more of your Virgin Active payment transactions was contained in the affected transaction-monitoring data. The investigation has not established whether every individual record in that data was specifically accessed or copied. However, because an unauthorised person may have been able to access your information, we are notifying you so that you can take appropriate precautions. The relevant transaction or transactions occurred between 07/05/2026 and 09/09/2026. Information relating to youBased on the information currently available, the affected data relating to you could have included:
Peach Payments has confirmed that full payment card numbers and sensitive banking credentials were not provided to RelyComply. Possible consequencesThe affected information could be used to make phishing, impersonation, social-engineering or other fraudulent communications appear more convincing. For example, someone might refer to genuine transaction, payment or contact information in an attempt to gain your trust or persuade you to disclose additional information. At present, Virgin Active and Peach Payments are not aware of any confirmed misuse of your information arising from this incident. We will continue to monitor the position. Actions takenPeach Payments has advised us that it has:
Virgin Active has:
What we recommend you doAs a precaution, we recommend that you:
Virgin Active will not contact you to ask for your password, card PIN, CVV security code or one-time password in connection with this incident. If anyone claiming to represent “Direwolf” contacts you, or if someone refers to this incident while requesting information or payment, do not engage with them. Preserve the communication and report it to SAPS by calling Crime Stop at 08600 10111. Contacting usWe regret the concern that this incident may cause. We will continue working with Peach Payments and the relevant authorities and will provide further information if the investigation identifies any material development affecting you. If you have questions about this notice, receive a suspicious communication, or believe that your information may have been misused, please contact us at: escalations@virginactive.co.za Email: official Virgin Active email address To protect yourself from fraudulent communications, please obtain our contact details directly from the Virgin Active South Africa website or your existing Virgin Active membership documentation. Kind regards Virgin Active South Africa
|
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article