MIP Holdings chief executive Richard Firth said South Africa should make it illegal to pay ransoms to hackers. He spoke to TechCentral on Tuesday, after his own company paid a ransom earlier this year.
MIP supplies software to insurers. Firth said the company paid a “substantial” sum to a cybercrime group called The Gentlemen. The gang had stolen data on customers of about 45 insurers.
“I think banning ransomware payments will be a powerful deterrent,” Firth told TechCentral.
Firth said the attackers did not reach MIP’s administration platforms. He said they got into “a third-party tool that we use for support ticket management”.
TechCentral reported that the gang promised to destroy the data if it was paid. It appears the gang did not do so, and in September it turned on the insurers.
Hollard refused a ransom demand of its own, and its client data was published on the dark web. Hollard said its forensic work found “no evidence of compromise within the Hollard environment”. The insurer linked the leak to the MIP incident.
Firth said cryptocurrency is what makes these attacks pay. “I don’t think crypto is currently truly being regulated at all and that leaves this massive gaping hole for attackers,” he said.
He said MIP checked the accounts it was given before it paid. The accounts passed anti-money laundering tests, even though the money was a ransom. “The mechanism isn’t being controlled at all,” Firth said.
Firth said there are hundreds of ransomware attacks in South Africa every month. “But people are staying quiet. People don’t want to admit when they’ve been attacked,” he said.
Dominic White, managing director for South Africa at Orange Cyberdefense, was less sure about a ban. “Blindly banning ransomware payments doesn’t alleviate the pressure that causes a victim to pay in the first place,” he told TechCentral.
White pointed to Australia as a better model. Since 30 May 2025, businesses there with turnover above A$3 million must report any ransom payment within 72 hours. The rule also covers operators of critical infrastructure.
White said the government could make it more attractive to spend money on recovery instead. He named tax relief, rebates and grants for smaller organisations as options.
He said any ban should also allow a fast exception. A victim that had reported the attack and hired an accredited responder could apply to pay as a last option.
South Africa signed a statement by members of the International Counter Ransomware Initiative in November 2023. It said national government institutions should not pay ransomware demands. TechCentral reported that the pledge carries no legal force and covers only state institutions.
Security company Sophos surveyed 135 South African organisations hit by ransomware in the past year. Of those whose data was encrypted, 58% paid a ransom to get it back, down from 71% a year earlier. The survey found that 54% used backups, up from 35%.
Only 40% of the local victims recovered within a week. Sophos said that was the lowest rate of any country it surveyed.
Source: this article is based on reporting by TechCentral. Image: TechCentral. Written with the help of AI and published by the Tzaneen Voice Technology desk. See our Editorial Standards.
Werner Jacobs covers technology for Tzaneen Voice. Werner reports on mobile networks, data prices, internet access, smartphones, apps, AI, cybersecurity and South African tech companies. Each story explains what a new product, price change or policy means for ordinary users in South Africa.