A ransomware gang linked to the June breach at software supplier MIP Holdings has added three more South African organisations to its dark web leak site. They are LegalWise, Samwumed and Edcon, TechCentral reported.
LegalWise sells legal expenses insurance. Samwumed is a medical scheme for municipal workers. Edcon is the retailer that went into business rescue in 2020.
Each listing has a countdown timer. At about 11am on Monday, the timers had just over 100 hours left. That puts the deadline on the afternoon of Friday, 9 October.
The group behind the listings is known as The Gentlemen. The listings hold no sample data. They only show short company profiles that seem to come from business directories such as ZoomInfo.
TechCentral said it could not confirm that the gang holds data from LegalWise, Samwumed or Edcon. It also could not confirm that any such data came from the MIP breach.
Of the three, only LegalWise has said in public that the MIP breach affected it. In a statement on 26 June, LegalWise said MIP found unauthorised access to an old system used for software development and support.
LegalWise said there was no evidence that anyone reached its core systems, member databases or payment platforms. In a later update, it said its insurer, Legal Expenses Insurance Southern Africa, had told the Information Regulator. LegalWise said it knew of no fraud linked to the incident.
Samwumed and Edcon have not said whether they used MIP’s services. MIP supplies policy and customer software to insurers, medical schemes, lenders and pension administrators. Edcon no longer trades, and its Edgars and Jet chains were sold during business rescue.
In late September, the gang also listed Guardrisk, which is part of Momentum Group. TechCentral said it has not found out whether that listing is linked to MIP. No Guardrisk client data had been published by the gang at the time of the report.
MIP CEO Richard Firth told TechCentral last month that the gang took personal details of customers from about 45 insurance companies. That is just under half of MIP’s clients, and almost all are life insurers.
The attackers got into an Atlassian Jira support platform that MIP was shutting down. They used login details that an employee had reused on another service, which had itself been hacked.
They were inside from about 25 May until MIP noticed in mid-June. They took about 400 000 records, including ID numbers, email addresses and cellphone numbers pasted into support tickets.
MIP paid the gang an amount Firth would only call substantial. In return, the gang promised to destroy the data. That promise did not hold.
The gang listed Hollard on its leak site on 7 September. MIP found signs linking that material to the June breach. Hollard refused to pay a ransom, and the gang then published details of Hollard funeral policyholders. Hollard said its own systems were not hacked.
The Information Regulator told TechCentral that MIP’s report was the only one it received about the incident. Under Popia, each insurer must report a breach itself. The regulator said paying a ransom does not on its own settle whether a company has complied with Popia.
The Gentlemen first appeared in mid-2025 and rents its tools to other attackers. Check Point Research said the group has more than 400 public victims. It ranks the gang as the second most active ransomware group in the world this year.
Source: this article is based on reporting by TechCentral. Image: TechCentral. Written with the help of AI and published by the Tzaneen Voice Technology desk. See our Editorial Standards.
Werner Jacobs covers technology for Tzaneen Voice. Werner reports on mobile networks, data prices, internet access, smartphones, apps, AI, cybersecurity and South African tech companies. Each story explains what a new product, price change or policy means for ordinary users in South Africa.