
Hollard South Africa: Denies Direct Hack, MIP Cyber Breach Source
Summary
- Hollard denied its IT systems were hacked, attributing dark web claims to a cyber incident at third-party provider MIP Holdings.
- MIP Holdings confirmed a June cyber extortion attack targeting its Jira platform, affecting personal information of customers from approximately 45 South African insurance companies.
- The ransomware group 'The Gentlemen' was identified as the attacker, employing a 'double-extortion' tactic.
- MIP Holdings notified the Information Regulator under POPIA on June 16, and also informed the FSCA and Prudential Authority.
- Hollard's internal forensic investigations found no evidence of compromise within its own environment.
Hollard Refutes Direct Cyber Attack Claims
This incident, where personal information linked to customers of numerous South African insurance companies was potentially exposed due to a third-party vendor compromise, underscores the critical importance of robust cybersecurity measures and diligent vendor management within the financial sector.
Leading South African insurer Hollard has publicly refuted claims of a direct cyber attack on its internal systems, clarifying that allegations made by a threat actor on the dark web actually stem from a security incident at a key third-party service provider. This clarification comes after a group known as “The Gentlemen” asserted on the dark web that they had compromised Hollard's infrastructure. Hollard stated that its proactive threat intelligence capabilities identified the dark web claims, prompting immediate activation of its cyber incident response protocols and engagement of specialist forensic investigators.
To date, these investigations have yielded no evidence of compromise within Hollard’s own operational environment. The insurer attributes the dark web claims to a June 2026 cyber security incident that affected MIP Holdings, a service provider to numerous companies within the insurance sector. This incident highlights the critical importance for South African legal and compliance teams to review their third-party vendor agreements and data processing arrangements, particularly concerning POPIA compliance and cyber incident response protocols.
MIP Holdings Confirms Breach Details
MIP Holdings, a crucial provider of policy administration, customer relationship management, and related technology to insurers, healthcare providers, lenders, pension administrators, and business process outsourcing companies, has confirmed experiencing a breach in June. The company detected a cyber extortion attack on June 14, specifically targeting its third-party Jira project-management platform. MIP emphasized that its core systems and client policy-administration databases remained uncompromised.
However, attackers successfully accessed the Jira environment and certain FTP/SFTP sites using credentials obtained from the platform. The compromised Jira environment contained personal information pertaining to employees, client users, and members/customers. This included information visible in screenshots, task attachments, and in some instances, access credentials. MIP's ongoing investigation aims to precisely determine the scope and categories of data affected, and whether any information was downloaded, copied, misused, or disclosed. The company has identified “The Gentlemen” as the perpetrators and has received assurances that unlawfully accessed data has been deleted and will not be published or misused.
The Threat Actor: 'The Gentlemen' Ransomware Group
The cyber criminal group “The Gentlemen,” which first emerged in mid-2025, employs a 'double-extortion' tactic, according to cybersecurity firm FortiGuard Labs. This involves breaching company networks, exfiltrating sensitive data, and then encrypting the victim's files. A ransom is subsequently demanded for file recovery, coupled with a threat to publish the stolen data online if payment is refused.
FortiGuard Labs indicates the group is believed to operate from Russian-speaking regions, evidenced by their policy against targeting entities within Russia and other Commonwealth of Independent States countries. By early 2026, their data leak site reportedly listed over 200 victim organizations across more than 50 countries and every major continent, spanning over 20 industries including critical sectors like energy, government, and healthcare services. The Gentlemen openly promote their tools on underground criminal forums, functioning as a ransomware-as-a-service (RaaS) operation that promises affiliates a substantial 90% share of profits.
Regulatory Notifications and Industry Impact
MIP Holdings promptly notified affected stakeholders of the cyber attack, which compromised personal information linked to customers of approximately 45 South African insurance companies. Following the breach, MIP fulfilled its regulatory obligations by notifying the Information Regulator on June 16, in accordance with section 22 of the Protection of Personal Information Act (POPIA). The company also informed the Financial Sector Conduct Authority (FSCA) and the Prudential Authority about the incident, as detailed in a June 23 breach notification signed by MIP Holdings CIO Fergus McLoskey.
This incident, where personal information linked to customers of numerous South African insurance companies was potentially exposed due to a third-party vendor compromise, underscores the critical importance of robust cybersecurity measures and diligent vendor management within the financial sector. It highlights the need for robust due diligence and clear contractual obligations regarding data security and breach notification from service providers, given the widespread impact of the MIP Holdings breach on the insurance sector.
Practical Implications
This incident underscores the critical importance for South African legal and compliance teams to review their third-party vendor agreements and data processing arrangements, particularly concerning POPIA compliance and cyber incident response protocols, given the widespread impact of the MIP Holdings breach on the insurance sector. It highlights the need for robust due diligence and clear contractual obligations regarding data security and breach notification from service providers.
Source
Source: Original reporting via ITWeb
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Finish Reading the Full Story and the Expert Analysis.
Get the latest legal & regulatory intelligence in South Africa
Wansom is AI and can make mistakes.
