Customers of 45 insurers exposed in South African cyber breach

Customers of 45 insurers exposed in South African cyber breach


Personal information belonging to the customers of roughly 45 insurance companies was taken from IT service provider MIP Holdings in June, after intruders spent about three weeks inside a support platform the software company was in the middle of decommissioning, CEO Richard Firth has told TechCentral.

The 45 organisations represent just under half of MIP’s client base. Almost all are life insurers. MIP, which supplies policy administration and CRM software to insurers, medical schemes, lenders and pension administrators, says its core administration systems were not touched.

In the region of 400 000 records were taken. Firth said the data included e-mail addresses, cellphone numbers, policy numbers with identity numbers attached and a small number of residential addresses. One file alone held roughly 200 000 cellphone numbers assembled for an SMS campaign.

The system involved was an Atlassian platform, the Jira service on which MIP’s clients logged support tasks. It was being replaced: MIP had decided it could not migrate to a newer version and was moving to a different structure entirely, partly for security reasons.

Tickets logged on that platform were supposed to contain obfuscated data. They did not. When a client’s staff member logged a problem, Firth said, they would paste in what they were looking at – an error message, a screenshot, a report someone had complained about – and the underlying record came with it. Identity numbers, e-mail addresses and cellphone numbers sat in the tickets in the clear.

“That’s why we were taken aback that all of this data was actually sitting inside that platform,” Firth said.

Reused credentials

The intruders did not break MIP’s perimeter. They reached the support platform through an employee’s personal laptop, after obtaining credentials the employee had reused on an unrelated service that had itself been breached. From there they identified the MIP e-mail address, worked out what the employee had access to and reached the Atlassian instance.

MIP believes they were inside from about 25 May, moving data out slowly to avoid detection, until the company realised something was wrong on a Sunday in mid-June.

The attackers, a group known as The Gentlemen, copied data and encrypted some of it, offering to return the keys. That part of the extortion carried no weight, Firth said, because MIP could reproduce the encrypted material and its administration systems were unaffected. What the attackers did have was customer data.

MIP notified every affected client as it established who was involved, and reported the incident to the Information Regulator and to the Prudential Authority. It built a messaging package and platform so that each affected client could notify its own customers directly.

MIP was also called into a meeting with the Prudential Authortu, where concerns were voiced that a breach touching a large share of the life insurance sector’s administration layer could be a systemic risk. The authority concluded that it was not, Firth said.

MIP Holdings CEO Richard Firth
MIP Holdings CEO Richard Firth

Under Popia, the obligation to notify the regulator and affected individuals rests with the responsible party – each insurer – rather than with the operator processing data on its behalf. The Information Regulator has fined organisations before over compliance failures uncovered after a cyberattack, rather than over the attack itself.

The Information Regulator’s case remains open and its investigation is continuing, Firth said. TechCentral has asked the regulator how many breach notifications it has received in connection with the MIP incident and from which organisations, whether its investigation extends to the insurers that used MIP as an operator, and whether it takes a view on responsible parties or their service providers paying ransoms.

TechCentral has also put questions to the Prudential Authority, asking it to confirm the notification and the systemic risk assessment, and how it treats concentration risk where a single unregulated software supplier serves a large share of one sector. This article will be updated once feedback is received from both regulators.

Notably, MIP confirmed to TechCentral that it paid the extortionists. Firth confirmed the payment on the record but would not disclose the amount, saying only that it was substantial. In exchange, the group undertook to destroy the data.

Before paying, MIP ran anti-money laundering checks on the accounts involved, on the advice of the cyber and legal specialists it brought in on day one. The checks came back clear.

But it appears that undertaking has not held. The Gentlemen listed insurance giant Hollard on its leak site on 7 September, and MIP identified markers in that material linking it to the data taken in June.

Silence helps no one

Hollard told TechCentral in a statement on Tuesday that its own forensic work has found no evidence of compromise inside its environment, and that the claim appears attributable to the June incident at MIP.

TechCentral has since put further questions to the insurer, asking when it was first told its data was involved, whether Hollard customer information was among the records taken, and whether it notified the Information Regulator and affected policyholders at the time.

Firth said MIP had chosen to speak publicly because companies that suffer breaches tend to hide them, and that silence helps no one.  — (c) 2026 NewsCentral Media

  • This is a developing story