Thursday 17 September
Donation
SurgeZirc Media
...
Business

Hollard Denies It Was Hacked As Cyber Breach Hits Data Linked To 45 SA Insurers

Hollard says investigators have found no evidence its own systems were breached after ransomware group The Gentlemen claimed to have compromised the insurer, with the incident instead traced to technology provider MIP Holdings.

Share:
Hollard Denies It Was Hacked As Cyber Breach Hits Data Linked To 45 SA Insurers
Hollard Denies It Was Hacked As Cyber Breach Hits Data Linked To 45 SA InsurersHollard

South African insurer Hollard has rejected claims that its own IT systems were hacked after a cybercriminal group named the company on a dark-web leak site.

The insurer says forensic investigations have so far found no evidence of a compromise within its environment and that the claims appear to stem from a June cyberattack on third-party technology provider MIP Holdings.

The ransomware group known as The Gentlemen had claimed that it compromised Hollard and obtained sensitive information.

MIP has since confirmed suffering a cyber incident in June that affected information associated with customers of about 45 South African insurance companies.

The distinction is significant: while information connected to Hollard may have been held by the affected third-party provider, Hollard says investigators have found no evidence that attackers penetrated its own systems.

Hollard Says Its Systems Were Not Compromised

Hollard said it became aware of the dark-web claims through its threat-monitoring capabilities and immediately launched its cyber incident response procedures.

“We identified the threat through our proactive threat intelligence capabilities, immediately activated our cyber incident response processes and engaged specialist forensic investigators,” Hollard said.

YOU MAY ALSO LIKE: Cartrack Confirms Ransomware Attack As Direwolf Claims 500GB Data Theft

The insurer said the forensic work conducted to date had not identified evidence of a breach within its own environment.

“At this stage, the claim appears to be attributable to a June 2026 cyber security incident that affected a third-party, MIP (a service provider to several companies within the insurance sector), rather than to any compromise of Hollard’s systems,” it said.

Hollard said it would continue monitoring the situation and provide further information if evidence emerged that changed its assessment.

“Protecting the information entrusted to us by our customers, brokers and partners remains a priority,” the insurer said.

MIP Holdings Confirms June Cyberattack

MIP Holdings provides technology services including policy administration and customer relationship management to insurers and other financial-services businesses.

According to information disclosed following the breach, MIP detected a cyber-extortion attack on 14 June involving its third-party Jira project-management environment.

The company said its core systems and client policy-administration databases were not compromised.

Attackers were, however, able to access the Jira environment and certain FTP and SFTP sites using credentials obtained from the platform.

Information held in the affected environment included personal information relating to employees, users of client systems and customers or members.

Some information was contained in screenshots and task attachments, while access credentials were also present in certain cases.

MIP said its investigation had been working to establish precisely what information was affected and the extent to which data had been downloaded, copied, disclosed or misused.

The company identified the attacker as The Gentlemen.

MIP notified South Africa’s Information Regulator on 16 June under section 22 of the Protection of Personal Information Act and also informed the Financial Sector Conduct Authority and Prudential Authority.

Data Linked To About 45 Insurers Affected

The scale of the MIP incident extends beyond Hollard.

Personal information associated with customers of approximately 45 South African insurance companies was affected in the breach.

MIP chief executive Richard Firth has separately said about 400,000 records were taken during the attack.

The information included email addresses, cellphone numbers and policy numbers linked to identity numbers, as well as a smaller number of residential addresses.

YOU MAY ALSO LIKE: X Says Chinese Bot Farm Used AI-Generated Content To Target Data Centres

MIP has maintained that its core policy-administration systems were not compromised.

The company also said the attackers had provided an undertaking that unlawfully accessed information would be deleted and would not be published or misused.

The subsequent appearance of Hollard on The Gentlemen’s leak site, however, brought renewed attention to the June incident.

LegalWise And Other Organisations Affected

Other organisations have also notified customers or members about the MIP breach.

LegalWise South Africa and its insurer, Legal Expenses Insurance Southern Africa Limited, said they had been working with MIP, independent cyber-security specialists and legal advisers to determine the scope and impact of the incident.

LegalWise said it had found no evidence of unauthorised access to its core systems, member databases or transactional platforms.

The National Fund for Municipal Workers has also warned members that some personal information may have been accessed through the MIP incident.

Potentially exposed personal information can be exploited for phishing, identity fraud and other forms of cybercrime.

Affected organisations have consequently urged customers and members to remain cautious about unsolicited emails, messages, links and requests for sensitive personal or banking information.

Third-Party Providers Increasingly A Cyber Risk

The incident also highlights the exposure companies can face through technology providers that store or process information on their behalf.

Jason Jordaan, principal forensic scientist at DFIR Labs, said cyberattacks against South African organisations were not new but had become more frequent, intense and visible.

Ransomware and cyber-extortion groups increasingly publicise successful attacks as part of their attempts to pressure organisations into paying, he said.

Jordaan said outsourcing the processing of personal information did not eliminate an organisation’s responsibility for protecting that data.

“Third-party cyber security risk cannot simply be treated as somebody else’s problem,” he said.

YOU MAY ALSO LIKE: X Says Chinese Bot Farm Used AI-Generated Content To Target Data Centres

Companies need to conduct appropriate due diligence and ensure outside providers entrusted with sensitive information maintain adequate security controls, he added.

Third-party technology companies can be particularly attractive targets because a successful breach may provide access to information associated with numerous organisations through a single attack.

“Your security posture is increasingly influenced by the security of every third-party to whom you entrust your information,” Jordaan said.

He said The Gentlemen was an established cybercriminal operation whose claims warranted investigation, although indications of possible links to Russian-speaking territories did not establish where individual members were physically based.

“I would certainly take the threats made by this group seriously,” Jordaan said.

Hollard maintains that, based on the forensic investigation conducted to date, there is no evidence its own environment was compromised.

Topics:Hollard cyberattackMIP Holdings cyber breachThe Gentlemen ransomwareSouth Africa insurance data breachHollard hack