The criminal group behind the June breach at MIP Holdings is now extorting South African insurers directly after taking a ransom payment from the software supplier in exchange for an undertaking to destroy the stolen data. Some of the data has now been published online.
TechCentral has reviewed material on a dark web leak site that includes Hollard policyholder names, the names of their children, identity numbers and e-mail addresses.
The breach exposed the customers of roughly 45 insurance companies, just under half of MIP’s client base, MIP CEO Richard Firth told TechCentral this week.
Firth confirmed in an interview that the company paid the extortionists, declining to say how much was involved beyond describing the amount as substantial. In exchange, the cybercrime group known as The Gentlemen undertook to destroy the data.
The payment bought nothing, however: the attackers’ undertaking has not been honoured and the ransomware group has now turned on the insurers whose customers the data belongs to.
The published records include the names of policyholders, the names of children attached to those policies, identity numbers and e-mail addresses. Hollard told TechCentral on Friday that the matter appears at this stage to be isolated to individual funeral policyholders. It’s a product class in which dependants, including minors, are routinely listed.
“The information was unlawfully obtained through the MIP incident and is the subject of an ongoing criminal investigation,” Hollard said.
Phishing risk
Identity numbers are the most damaging element. They do not change, they are the key to a great deal of South African account opening and verification, and paired with a name and an e-mail address, they are the raw material for identity fraud and targeted phishing.
In a statement on Friday, Hollard said the information published online is linked to the June incident at MIP rather than to any compromise of its own systems, and that its forensic and assurance work to date has found “no evidence of compromise within the Hollard environment”.
The insurer said it had already notified customers affected by the June incident and is engaging with the relevant regulatory authorities. It urged customers to remain vigilant against unsolicited communications, phishing attempts and requests for personal or financial information.

TechCentral has learnt reliably that Hollard received a ransom demand from the attackers and refused to pay, prompting the publication of the client details on the dark web.
TechCentral has approached the Information Regulator and the South African Reserve Bank, whose Prudential Authority supervises the insurers concerned. Both have undertaken to answer the publication’s questions by Monday. — © 2026 NewsCentral Media
