
Real estate agency Pam Golding may not have been entirely transparent regarding how it acquired the personal information that was compromised in a recent breach of its customer relationship management (CRM) platform.
A security researcher contacted one of the StormWarning! associates shortly after the incident, upon discovering that Pam Golding was using an email address that it should not have had access to.
The researcher explained that the email address in question had been used exclusively for one purpose—to sign up for TransUnion’s identity theft and credit monitoring service through its MyTransUnion portal.
Pam Golding, the largest real estate agency in South Africa, suffered a data breach on Friday, 7 March 2025. The company stated that an unknown third party had gained unauthorized access to its CRM system, Alchemy, via an existing user account.
“The information accessed by the threat actor depends on the type of information we have stored in the Alchemy System for a particular client,” the company stated. “For example, this may include names, contact details, and, in some cases, identity numbers.”
Pam Golding notified potentially affected individuals of the breach on 11 March. Subsequently, one of the StormWarning! associates was contacted by several individuals who expressed confusion regarding how the company had obtained their contact information.
When queried about this two weeks ago, Pam Golding stated that every individual who had interacted with the company in any capacity was stored in its system. This included inquiries, evaluation requests, and newsletter subscriptions.
However, the security researcher who reached out to StormWarning! asserted that this did not explain how Pam Golding had obtained the email address she had used exclusively for her MyTransUnion registration.
She elaborated that she utilizes a catchall mailbox associated with a custom domain, which we will refer to as emailfunnel.com to protect her identity.
Her domain configuration allows her to receive emails at any username within a single mailbox without having to predefine specific aliases. For instance, she might use
She emphasized that she does not send emails from these addresses, instead using a separate address,
It was therefore unexpected when she received Pam Golding’s breach notification at the “mytransunion” address, which she had used solely for her TransUnion account since 2017.
Upon searching her inbox for emails associated with that address, she also discovered a direct marketing email from Pam Golding Properties, dated 5 September 2024, concerning a property she owns in Cape Town.
She confirmed that she had never contacted the real estate agency regarding renting out the property—let alone used her MyTransUnion email address to do so.
Although the researcher requested her claims where verified during a video call in which she demonstrated the search results of her email inbox via screen sharing.
Pam Golding and TransUnion was contacted for clarification on how the real estate agency had obtained an email address entrusted exclusively to TransUnion. However, both entities cited the Protection of Personal Information Act (POPIA) as a barrier to providing further information.
“Please note that we can only respond to inquiries regarding client information and processing within the provisions of POPIA,” Pam Golding stated. “Please advise the client to contact us directly via
A response was sent, copying the researcher, and clarified that full authorization had been granted to handle inquiries on her behalf. She further confirmed this in her response.
Despite this, Pam Golding maintained its stance, stating: “We have noted your email; however, regardless of which entity acts on her behalf of this researcher, in compliance with POPIA, we are unable to divulge any private information or engage with any representing organisation on a matter that pertains to a specific client.”
TransUnion initially denied any link between its data and the Pam Golding breach, stating: “TransUnion South Africa is aware of media reports regarding a cyber incident involving Pam Golding Properties. We have no evidence to suggest that this incident is linked to TransUnion’s systems or data.”
This denial was issued despite the researcher’s detailed explanation of her catchall email system and the absence of any other plausible explanation for Pam Golding’s possession of the email address.
Following further correspondence, evidence was offered the researcher offered to disclose her identity for TransUnion’s investigation. TransUnion agreed and issued the following response:
“TransUnion has a standard dispute process that must be followed to assist the consumer further, as we require her ID number to access her profile in a compliant manner.”
"Doxxing-as-a-Service" in South Africa
Cybersecurity expert Dominic White has long warned that South African credit bureaus effectively sell personal data to those willing to pay for it. Speaking at a past conference, White described the situation as “doxxing-as-a-service.”
He explained that multiple online services in South Africa allow individuals and businesses to purchase personal information from credit bureaus for a fee. While some require additional verification, such as ID document scans and proof of address, these services are widely accessible to real estate agents and other entities.
A plausible explanation for this situation is that Pam Golding accessed homeowner data from the deeds office and subsequently enriched it by querying TransUnion for additional details. In doing so, TransUnion may have provided the researcher’s MyTransUnion email address.
This practice is not unlawful under POPIA. The National Credit Act specifically grants credit bureaus the legal authority to engage in such data-sharing activities.
White noted that the fundamental issue lies in the lack of controls over how credit bureaus disseminate collected information, stating, “The legality is structured around what credit bureaus can collect but does not adequately regulate how they distribute it.”
Correspondence from Pam Golding’s information officer to the researcher supports this theory, albeit with careful wording. The officer acknowledged the existence of industry services that provide contact information for homeowners, enabling companies to conduct initial outreach in accordance with POPIA.
“It is possible that such a service was used by the agent or office in question,” the information officer stated.
Furthermore, the officer clarified that once data is obtained, it cannot be deleted entirely. If an individual opts out of direct marketing, their information is retained to ensure compliance with POPIA and to prevent further contact.
“Once a client opts out, the information would have been marked accordingly within our system, ensuring that no further canvassing occurs,” the information officer explained. “We retain personal information solely for maintaining a do-not-contact list in accordance with guidance from the Information Regulator.”
Conclusion
In conclusion incidents like this highlight the urgent need for businesses to conduct thorough cybersecurity audits to ensure the safety of their clients' personal data. StormWarning! provides a comprehensive, automated NIST cybersecurity audit system that identifies vulnerabilities, strengthens risk management policies, and enhances overall cybersecurity resilience. With tailored training modules and real-time compliance monitoring, StormWarning! helps organizations safeguard their systems against unauthorized access and data breaches. To learn more about how StormWarning! can help protect your business, visit https://StormWarning.co.za
How StormWarning! Can Protect Your Organization
With phishing attacks evolving rapidly, organizations must adopt advanced cybersecurity measures to stay protected. StormWarning! provides comprehensive automated NIST cybersecurity audits, identifying vulnerabilities such as those exploited by Astaroth. Our automated analysis and reporting tools detect weaknesses in authentication methods, session security, and access controls, offering tailored recommendations to enhance your defenses. StormWarning! even offers tailored online cyber threat and risk mitigation training to personel in subscribed organisations as part of the service so that they can improve their awareness outside of production hours if needed.
Additionally, StormWarning!’s Cybersecurity LMS offers over 100 lessons, ensuring your team is trained in the latest security best practices, including recognizing and mitigating phishing threats. By aligning security training with real-time audit findings, StormWarning! helps businesses proactively defend against evolving cyber threats.
StormWarning! – Your Frontline Defense Against Cybercrime... ... Probe. Prepare. Prevent. Protect. Prevail. PROTECT YOUR BUSINESS NOW!