The Day The Regulator Pulled The Plug
- February 25, 2026
A Closer Look at Circular 01 of 2026
After weeks of uncertainty and near total operational paralysis, Debt Counsellors have finally received formal communication from the National Credit Regulator explaining why the NCR Debt Help System was taken offline without prior warning.
Circular 01 of 2026 now provides the only official explanation for why Debt Counsellors have been unable to formally capture new debt review applications or update consumer records for nearly a month.
For a system that is central to daily compliance, the silence until the circular was extremely frustrating. Now we have information to help us understand what is going on. How things unfolded and what comes next.
Let’s look closely at what the circular says and what the wording implies.


The reference to the circular number and date here is wrong but don’t stress about that. The date at the top is right. So this is actually Circular 1 of 2026.
PURPOSE
“This communication is intended to provide Debt Counsellors and stakeholders with a factual update on the temporary unavailability of the Debt Help System (DHS) and to outline interim operational measures during the period of system downtime.”
The circular opens by calling this a factual update.
That sounds reassuring. But factual does not automatically mean super detailed as we will see. It simply means this is the information that the NCR feel comfortable prepared to release at this stage.
The word temporary is also important.
It means a solution is coming. But…temporary could mean hours. It could mean weeks. Unfortunately, there is no timeframe attached to when that solution is coming.
The reference to interim operational measures suggests that the regulator has something that Debt counsellors must do while the system is down for however long that may be.
“It serves as an external-facing notice to ensure consistent, accurate information is provided while the technical assessment and investigation remain underway.”
The phrase external-facing notice means there may be other internal info but this is what we the public and industry get to see for now. And that the investigation remains underway means, the NCR are looking for causes themselves. They have not yet found the cause. It is however a technical matter.
They want us to have accurate information rather than sit around wondering or guessing what is going on but this whole thing is not sorted out yet.


How NCR Debt Help Used To Appear When Visiting The Site
OVERVIEW
1.
“The National Credit Regulator (NCR) notifies all registered Debt Counsellors and interested parties that the Debt Help System (DHS) is temporarily unavailable.”
This confirms what Debt Counsellors already know but now the notice that the system is down is official.
But what don’t we see here? Since this says they are letting people know now, this points out to the one very weird part of the whole situation. There is no mention of the lack of prior warning. No reference to why there was no advance notice. No indication that stakeholders were not informed at the time of the sudden shutdown.
If you are not a Debt Counsellor you may wonder why that’s weird. Well, since the system is used daily for compliance and updating consumer data, the lack of any prior warning before someone decided to turn the whole site off is strange (and makes compliance with previous instruction from the NCR impossible).
2.
“On 3 February 2026, the DHS was taken offline as a precautionary measure following reports of misconfiguration issues.”
This is one of the most significant sentences in the entire circular.
The system was taken offline.
That means this was not a crash.
It was not a failure.
It was not a technical glitch.
It was not because someone forgot to pay a bill.
It was a decision.
Somewhere within the organisation, an instruction would have been issued by email or letter to the IT team or hosting provider to disable the system. This is the thing the Information Regulator or any auditor can ask to see and confirm. Easy.
This also suggests a perceived risk due to a misconfiguration issue.
What is a Misconfiguration Issue?
It’s a broad term.
In simple terms, a misconfiguration means something in a computer system was set up incorrectly.
It does not usually mean the system was hacked at that moment. It means a setting, permission or rule was wrong.
Think of it like this:
If a building has a fancy security system and someone forgets to lock one door properly, that is a misconfiguration.
The system exists.
The door is there.
But the setting of the door within that system is wrong.
In IT systems, common misconfiguration issues include:
- Access permissions set too wide (people can see more than they should).
- A firewall rule allowing traffic that should be blocked.
- A database exposed to the internet when it should be private.
- A test setting accidentally left active in the live system.
- An update applied incorrectly.
- Security features not fully enabled.
- Incorrect user roles or admin privileges.
Most misconfigurations commonly happen because of:
- Human error.
- Rushed changes that were not fully tested.
- Poor change management.
- Incomplete system updates.
- Systems being rebuilt after a failure or cyber incident (but the circular says it’s probably not this)
Some misconfigurations are minor and can be fixed quickly. Others can create serious security or operational risks. The seriousness depends on what was misconfigured and how long it remained that way.
Quick Fixes
In most modern IT environments, minor configuration errors are corrected while systems remain live.
Permissions can be adjusted. Firewall rules can be changed. Updates can be applied all without full shutdown. It is a quick fix.
A complete system shutdown usually implies one of two things:
Either the risk of leaving it live was considered too high (like someone was trying to take advantage of it to cause problems), or the IT team did not have sufficient confidence to correct the issue safely while DHS was operational.
The phrase precautionary measure suggests containment.


Someone Reported It
The phrase reports of misconfiguration issues is interesting.
It does not specify whether those reports came from internal monitoring, external security researchers, auditors, or another source, like a Debt Counsellor who was able to get into areas of the system they would normally not be able to.
It also implies causation.
Misconfiguration means something was set incorrectly. That suggests a human action, a system change, or maybe a specific event triggered it.
It did not simply appear on its own.


Trying to Figure Out What Made the Problem
“This step was taken to allow the NCR to conduct a focused technical assessment.”
A focused technical assessment suggests a structured investigation.
Once again this shows it was a decision by someone at the NCR who made the call and gave the instruction that the situation needed to be fully investigated to figure out the cause.
So what happens next behind the scenes?
In a typical major IT incident, this would naturally trigger:
- Daily internal reporting
- Incident logs
- Executive meetings and briefings
- Possibly external cybersecurity involvement
That level of process usually exists internally even if external communication is limited. Debt Counsellors should not expect a blow by blow daily even if this is going on in the background every day within the NCR.
But that raises an important question: if structured reporting was happening daily internally, it’s kinda weird that external communication was delayed for weeks and weeks?
3.
“The investigation is currently underway.”
This confirms the matter remains unresolved.
They are still investigating.
“The NCR has not yet received the technical inputs required to determine the root cause of the misconfiguration issues, and no definitive technical findings have been made.”
The phrase root cause is significant.
It implies that something caused the misconfiguration. A deployment. A change. A configuration update. A systems event.
Three or four weeks into downtime, this suggests serious complexity in the misconfiguration.
At this point in time, when the circular was released, no one with the NCR knows what caused the issue (as of 18th of February) that made them decide to take the site down on purpose.
Most configuration errors are identified quickly. Entire websites and databases can be built in less than three weeks. An extended investigation suggests deeper analysis. Possibly forensic. Possibly architectural.
So, we are not talking about small settings adjustments. After weeks and weeks they have not found the cause.
4.
“Based on the structure of the NCR’s ICT environment and the information available at this time, the DHS matter appears operationally separate from, and unrelated to, the cyber incident disclosed in November 2025.”
So, the NCR is fairly confident that the current issue is not linked to the November hack or ransomware incident. Based on their architecture and current findings, this is likely a separate matter.
However:
“This remains subject to ongoing verification.”
The conclusion is not final. Since no one currently knows what caused the issue.
If it is unrelated to the November incident, then the question becomes: what did cause it?
Because if it did not arise from hack recovery, it likely arose from a separate change, operational decision, or configuration process either long before or a while after, with a part of the system that was not affected by those hacks.
5.
“Further updates will be communicated once the investigation has progressed.”
This promises updates during the investigation.
This is great because everyone is sitting desperately hitting refresh on the webpage hoping to be able to access the system and do what they have to.


AFFECTED SERVICES
“As a result of the DHS downtime, all system functions are unavailable.”
This confirms the shutdown is total.
Not partial.
Not limited.
Complete.


Operational Obligations
“Debt Counsellors are reminded that their obligations in terms of the National Credit Act, applicable regulations and their conditions of registration continue to apply during this period.”
Now we get to the part that is causing problems for Debt Counsellors and consumers at the moment.
The NCR reminds Debt Counsellors that the National Credit Act and regulations put certain obligations on them (like notifying credit bureaus when consumers enter debt review and instructing credit bureaus to remove records of consumers’ debt review once they pay up their debts)
Compliance remains required.
In the past, this was done directly by Debt Counsellors to credit bureaus, but after the creation of DHS and an NCR circular, Debt Counsellors now use the system, which is now unavailable.
Credit Bureaus have instructions from the NCR not to accept Debt Counsellors word that debts are paid up.
Credit providers demand proof that consumers are registered on the system.
“However, where compliance with a specific requirement can only be effected through the Debt Help System (DHS), and the system is unavailable, Debt Counsellors will not be regarded as non-compliant for the duration of the system downtime.”
In the future, if there is a fight about whether Debt Counsellors updated the system during this time the NCR knows the system was down and understands it could not be accessed.
This will be important for monitoring and possible court cases or matters before the NCT.


But Why Not warn Everyone?
Since the NCR has said that the shutdown was deliberate on 3 February, and since internal reporting is likely happening daily, the delay in telling Debt Counsellors in advance or updating them sooner has caused confusion and a wave of rumours.
The matter has even hit the mainstream media.
Why not tell Debt Counsellors in advance?
There are a number of possible explanations:
- Perhaps the issue was expected to be resolved quickly.
- Perhaps the true level of complexity only emerged later.
- Perhaps communication was delayed pending technical clarity on what the actual issue was.
- Maybe someone was on holiday and could not vet the wording used in the circular.
- Maybe something else happened entirely and we (and the NCR) don’t yet have all the info yet.


Interim Measures
“Debt Counsellors are advised to continue performing their duties to the extent possible…”
This confirms that operations must continue offline.
DCASA has approached the various PDAs and software providers to find alternative ways to prove that work was done on consumers behalf during this time.
Some sort of record keeping is required. Back capturing will be also probably be required later.
The NCR are saying Debt Counsellors should try their best to keep running during this time when many consumers finally start looking for ways to deal with their end of year financial headaches.
What We Know
Based on the wording of the circular, we know:
- Reports of misconfiguration issues were received from someone in advance of the shutdown.
- The shutdown was intentional. Someone made the call in writing somewhere.
- It was precautionary to stop bad things happening.
- It was specifically triggered by misconfiguration concerns.
- A specific root cause exists but no one knows what it is.
- The NCR think is it unrelated to the November cyber incident.
- The issue is complex enough to require extended ongoing investigation for weeks.
- Internal reporting almost certainly exists.
- External communication has lagged behind technical action.
There are multiple possible explanations for the problem:
- A serious configuration risk required containment.
- A complex technical issue emerged unexpectedly.
- A deeper architecture review is underway.
- Or events did not unfold as originally anticipated.
- Or something else has happened that will later become clear after the whole situation is audited and reported (to the Info Regulator and Parliament)
But that’s all we know and can guess at for now. Until further updates are provided, stakeholders are left analysing the circulars language in place of any technical detail.
With an important, rather delayed circular like this, each word has been poured over prior to release to ensure it is as accurate as possible.
What We Don’t Know (Yet)
There are some things we do not know yet. Such as:
- What the misconfiguration actually was.
- Who identified it.
- Who at the NCR decided to turn the system off.
- Whether any data was exposed.
- How long it may have existed.
- Why stakeholders were not notified in advance.
- Why stakeholders were not notified the next day, or week.
- Whether the Regulator expects restoration in days or months.
All that information will eventually be clarified as this matter is having serious impact on the industry and there will no doubt be committees, briefings and updates.


Just Do What You Can for Now
With the recent serious breach and ransomware attack on the NCR’s database (which is available to buy on the dark web as a result), the DHS issues are a sad cherry on top of mounting website and database woes that have faced the Regulator.
‘It is a good reminder to all of us to focus on data security and backing up everything’
It is a good reminder to all of us to focus on data security and backing up everything and investing in IT these days.
Problems can and do come up and can have a big impact.
In the meantime, Debt Counsellors are doing what they can to assist consumers and try keep records of their work. The show must go on and hopefully with the help of the PDAs and software systems (for those DCs who use them) will be able to smooth things over.
There is talk that soon Debt Counsellors will be able to send documents to dedicated email addresses at the credit bureaus and that the CBA portal will be adjusted to handle the issue.
It is important to remember that this is having an impact on consumers. One consumer said: ‘For me [it has been] personally traumatizing. I’ve been under debt review for 7 years. I received my clearance a week ago. Now I have to wait, don’t know till when…had so many plans.’
Hope For the Best
Let’s hope that once the dust settles, the NCR DHS will become the tool it has always had the potential to be and end up being better than ever before. It could be amazing.
Whatever the case, it certainly will not be misconfigured.









