1 reviews | Active since Dec 2022
Possible Internal ***** and POPIA Breach – RCS Credit Card ***** Not Handled Properly
Possible Internal ***** and POPIA Breach – RCS Credit Card ***** Not Handled Properly
Complaint Body:
On 23 July 2025, two online transactions of R9,000 each (R18,000 in total) were made on my RCS credit card without my knowledge or authorisation.
I only found out on 30 July, when I tried to use the card at Goodhope Wheel & Tyre, and it was declined. I contacted the RCS call centre, and to my surprise, I was told that the email address on my account had been changed — even though I had received my statement on 13 July via the correct email.
I was later informed that my card had been frozen due to suspected *****. I immediately asked how to dispute the transactions. The agent promised to email me a dispute form. I gave them my correct email address again, but after an hour, no email arrived.
Frustrated, I went to Cape Gate Game store to ask for help. The staff there contacted RCS themselves. At one point, RCS sent a form with someone else’s personal details — a clear breach of the POPI Act, which requires that personal information be protected at all times.
Eventually, the correct form was sent. I completed it and submitted it on Friday, along with all the supporting documents requested. To date, I haven’t received any feedback — not even confirmation of receipt.
What’s deeply concerning is that my email address was changed without my consent, and I believe this may be an inside job. Under the POPIA (Protection of Personal Information Act), changing someone’s contact information without proper verification is a serious breach. Only someone with internal system access could bypass the necessary security checks.
RCS has not taken this seriously and their communication has been poor throughout. I am still waiting for:
A proper investigation
Confirmation that my details are secure
Refund of the R18,000 *****ulently taken from my account
This is unacceptable and disappointing from a company that handles sensitive financial data.
Desired Outcome:
Full investigation and refund
Written explanation and apology
Report to the Information Regulator for POPIA breach if unresolved
