Legal News

Hollard Denies Hacking, Cites MIP Cyber Breach Impacting Insurer

South Africa·Wire Summary⏱️ 3 min read

MIP Holdings has confirmed the breach, which it says happened in June. (Image source: iStock) Insurer Hollard has rejected claims that its IT systems were hacked, saying a threat actor’s allegations stem from a cyber incident at a third-party service provider. This, after a threat actor called “The Gentlemen” claimed on the dark web that it had compromised Hollard’s systems. The third-party service provider, MIP Holdings, has since confirmed the breach, which it says happened in June. MIP Holdings provides policy administration, customer relationship management and related technology to insurers, healthcare providers, lenders, pension administrators and business process outsourcing companies. The company says it notified affected stakeholders of the cyber attack, in which personal information linked to customers of about 45 South African insurance companies was compromised. According to a 23 June breach notification signed by MIP Holdings CIO Fergus McLoskey, the company detected a cyber extortion attack on 14 June targeting its third-party Jira project-management platform. MIP says its core systems and client policy-administration databases were not compromised, but the attackers accessed Jira and certain FTP/SFTP sites using credentials obtained from the platform. The affected Jira environment contained personal information relating to employees, clients’ users and members/customers, including information visible in screenshots, task attachments and, in some cases, access credentials. MIP notes its investigation is still determining the precise scope and categories of data affected, and whether information had been downloaded, copied, misused or disclosed. The company identified the attacker as the ransomware group “The Gentlemen” and says it had received undertakings that unlawfully accessed data had been deleted and would not be published or misused. MIP also notified the Information Regulator on 16 June under section 22 of the Protection of Personal Information Act (POPIA) and informed the Financial Sector Conduct Authority and Prudential Authority. Emerging in mid-2025, The Gentlemen is a cyber criminal group that breaks into company networks, steals sensitive data and encrypts the victims’ files, says cyber security firm FortiGuard Labs. It explains that the group then demands a ransom to recover the encrypted files, with the added threat that they will publish the stolen data online if the company refuses to pay – a strategy commonly known as the “double-extortion” tactic. According to FortiGuard Labs, the group is speculated to be working out of Russian-speaking regions due to a prohibition enforced by the operators against targeting organisations in Russia and other Commonwealth of Independent States countries. It adds that as of early 2026, the group’s data leak site lists more than 200 victim organisations in over 50 countries, spanning every major continent. These victims represent over 20 industries, including vital areas such as energy, government and healthcare services. The Gentlemen publicly advertises its tools on underground criminal forums, operating what looks like a ransomware-as-a-service program and promising affiliates a ‘generous’ 90% cut of the profits. In a statement, Hollard says it is aware of claims made by a threat actor in a post referencing the organisation on the dark web. “We identified the threat through our proactive threat intelligence capabilities, immediately activated our cyber incident response processes and engaged specialist forensic investigators.” According to the company, based on the forensic and assurance activities conducted to date, there is no evidence of compromise within the Hollard environment. “At this stage, the claim appears to be attributable to a June 2026 cyber security incident that affected a third-party, MIP (a service provider to several companies within the insurance sector), rather than to any compromise of Hollard’s systems. “Protecting the information entru

Get Deeper AI analysis

How does this affect you?

Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.

Finish Reading the Full Story and the Expert Analysis.

Get the latest legal & regulatory intelligence in South Africa

Instant access to full analysis, cited statutes & expert commentary
Customize your dashboard to track what matters to your business operations

Already have an account? Log in

Wansom is AI and can make mistakes.