Cyber Expert Warns SA Insurers After MIP Holdings Breach Leaks Hollard Customer Data

By

October 4, 2026

Large insurance companies in South Africa have become prime targets for international cybercriminal groups, a local cybersecurity expert has warned. The warning follows a data breach at MIP Holdings that spread to several insurers.

Willem Steynberg, head of cybersecurity training at Orange Cyberdefense, told MyBroadband that insurers collect a lot of detailed personal information to sell their products. He said this makes a breach at an insurer more harmful than one at a retail company.

“The intruders were inside MIP for about three weeks before they were discovered, and the insurers’ 24-hour clock with the Prudential Authority only starts when they know,” Steynberg said.

MIP Holdings first told partners and customers about the problem on 23 June 2026. The notice went largely unnoticed at the time.

The company said it found suspicious activity on 14 June 2026 in Jira, a project management tool made by Atlassian. MIP said its clients use Jira to log and track tasks and issues.

“The Jira system operates in our data centre and does not have any direct integrations into any of our clients’ policy administration systems,” MIP Holdings said.

With help from security specialists, MIP found that the breach was limited to Jira and some file transfer sites. The company said its own system was not compromised. It said attackers still got access to some personal information and to login details clients used for secure file transfer platforms.

MIP named the attacker as The Gentlemen, an international ransomware group. The group sells its ransomware to smaller cells, which then carry out attacks under its name. This makes it hard to say which part of the group was behind the attack.

Hollard Insurance was one of the affected companies. The Gentlemen listed Hollard as breached on its dark web blog in September. According to MyBroadband, the group tried to extort Hollard, and when Hollard refused to pay, it leaked the data.

More than 100,000 records marked as Hollard customer funeral policies were published on the dark web. Hollard earlier told MyBroadband that its own systems remained secure and that it was investigating.

Guardrisk, the cell captive insurer owned by Momentum Group, was also listed on the group’s leak site over the weekend. Its exposure came through a third-party provider called CoverCubed, which was hit by the same MIP breach.

“There is no indication that our systems or client data have been compromised as a result of this event,” Guardrisk told MyBroadband. It said the main client relationship and data responsibility sits with CoverCubed as the binder holder.

Steynberg said insurers should run audits at once to find out which suppliers and partners hold customers’ personal information. He said they should check where that data is stored.

“The assumption is usually that it sits in properly encrypted databases, but the MIP breach came out of Jira,” he said. “What about employees sending spreadsheets back and forth, or uploading them to unencrypted file shares?”

He said insurers should ask suppliers how fast they will be told about a cyber incident. He added that contracts should set out the exact hours and who gets the call.

Steynberg said insurers should draft their Section 22 POPIA notices before they need them. He said the company that collected the data stays responsible, even when it outsources the work. “You are still responsible even if you outsourced the work,” he said.

Source: this article is based on reporting by MyBroadband. Image: MyBroadband. Written with the help of AI and published by the Tzaneen Voice Business desk. See our Editorial Standards.