Hollard client data (primarily related to funeral policies) has been published on the dark web by the ransomware group “The Gentlemen,” linked to a June 2026 breach at third-party IT service provider MIP Holdings rather than a direct compromise of Hollard’s own systems.

Hollard client data (primarily related to funeral policies) has been published on the dark web by the ransomware group “The Gentlemen,” linked to a June 2026 breach at third-party IT service provider MIP Holdings rather than a direct compromise of Hollard’s own systems.
0
(0)
photo credit

MIP Holdings, a South African software company providing policy administration, CRM, and related technology to insurers, medical schemes, lenders, and pension administrators, suffered a cyber extortion attack detected around mid-June 2026 (intruders were inside from about late May).

  • Attackers gained access via reused credentials on an employee’s personal laptop (tied to an unrelated prior breach), then reached MIP’s Atlassian Jira support platform (which was being decommissioned) and certain FTP/SFTP sites. Core policy-administration databases were reportedly not compromised.
  • Roughly 400,000 records belonging to customers of about 45 insurance companies (nearly half of MIP’s client base, mostly life insurers) were taken. Data included email addresses, cellphone numbers, policy numbers linked to identity numbers, a small number of residential addresses, and in some cases information from screenshots/task attachments. One file alone contained ~200,000 cellphone numbers compiled for an SMS campaign. Tickets on the Jira platform often contained unobscured personal data pasted by client staff.
  • MIP notified affected clients, the Information Regulator (under POPIA), the Financial Sector Conduct Authority, and the Prudential Authority. It paid a “substantial” ransom (amount undisclosed) after AML checks, in exchange for an undertaking that the data would be destroyed.

The Hollard-Specific Dump

The Gentlemen listed Hollard on its leak site around 7 September 2026. MIP identified markers linking the material to the June data. TechCentral reviewed published records that included Hollard policyholder names, names of children (common on funeral policies where dependants/minors are listed), identity numbers, and email addresses.

Hollard has stated that:

  • There is no evidence of compromise in its own environment; the claim is attributable to the MIP incident.
  • The published information appears isolated to individual funeral policyholders at this stage.
  • It had already notified affected customers from the June incident and is engaging with regulators.
  • It received a further ransom demand from the attackers and refused to pay, after which the data was published.

Hollard’s official updates (including its third-party privacy notice) reiterate that names, policy numbers, ID numbers, and bank account details of impacted customers/members may have been accessed via the MIP incident. It stresses ongoing monitoring, no evidence of misuse so far, and encourages vigilance against phishing and unsolicited requests for personal/financial information.

Broader Context and Implications

This is a classic double-extortion scenario that escalated: the group took payment from the service provider, then targeted the data owners (insurers) for secondary payments. “The Gentlemen” (active since mid-2025, with a ransomware-as-a-service model and hundreds of claimed victims across industries and countries) is known for such tactics.

Key risks for affected individuals:

  • South African ID numbers are particularly sensitive (unchanging identifiers used for account opening/verification). Combined with names and emails, they enable identity fraud, targeted phishing, and social engineering.
  • Funeral policies often list minors/dependants, raising additional privacy concerns.
  • Potential for fraud, account takeovers, or other misuse, though Hollard reports no evidence of actual misuse to date.

Third-party risk lessons: Outsourcing data processing does not eliminate a company’s responsibility under POPIA. A single vendor serving dozens of insurers creates concentration risk. Experts note that organisations must perform strong due diligence and ongoing oversight of suppliers, as even robust internal security can be undermined by weaker partners.

What Affected Customers Should Do

  • Remain highly vigilant for phishing, SMS/email/calls requesting personal, policy, banking, or OTP details—especially anything referencing insurance or funeral policies.
  • Monitor bank accounts, credit reports, and any accounts tied to your ID number for suspicious activity.
  • Change passwords on email and related accounts; enable multi-factor authentication where possible.
  • Contact Hollard Customer Service (0800 935 465 or mypolicy@hollard.co.za) if you have specific questions about your data or need confirmation of impact.
  • Report any suspected fraud or suspicious activity related to your policy directly to Hollard and relevant authorities (e.g., your bank, the Information Regulator).

Hollard and other affected parties continue investigations and regulatory engagement. Developments may emerge as the Information Regulator and Prudential Authority review the matter. Separate earlier Hollard-related incidents (e.g., an Australian Hollard cyber incident in 2026 involving isolated systems, or older South African third-party issues) appear unrelated to this MIP-linked dump.

How was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

As you found this post useful...

Share on social media!

Leave a Reply