Customers of 45 insurers exposed in South African cyber breach

A cyber attack on MIP Holdings’ support platform exposed personal data of customers from about 45 insurers, mainly life insurers, in South Africa. The breach involved 400,000 records and prompted regulatory notification and ransom payment. The incident raises concerns about systemic risk and data p…

A cyber intrusion at MIP Holdings, a South African IT service provider, exposed personal information belonging to customers of roughly 45 insurers in June. The attackers gained access to an Atlassian Jira support platform that MIP was in the process of decommissioning. The breach resulted in the theft of about 400,000 records, including e‑mail addresses, cellphone numbers, policy numbers linked to identity numbers, and a limited set of residential addresses.

How the breach unfolded

According to MIP CEO Richard Firth, intruders entered the support platform through an employee’s personal laptop. The employee had reused credentials that had been compromised in an unrelated breach. Once inside, the attackers identified the MIP email address, mapped the employee’s access scope, and moved into the Atlassian instance. They then extracted data from support tickets that were supposed to contain only obfuscated information. Instead, the tickets held clear‑text personal data because staff members pasted error messages, screenshots, or reports directly into the tickets.

The attackers operated for roughly three weeks, from around 25 May until mid‑June when MIP noticed irregular activity on a Sunday. During that period they transferred data slowly to avoid detection. The group, known as The Gentlemen, also encrypted some of the stolen material and demanded a ransom for the decryption keys. MIP was able to reproduce the encrypted files, so the extortion threat carried little weight. The real value for the attackers lay in the customer data itself.

Impact on insurers and regulatory response

MIP notified every affected client as it identified the parties involved. The company also reported the incident to the Information Regulator and the Prudential Authority. In response, MIP built a messaging package and platform that allowed each insurer to notify its own customers directly. The Prudential Authority held a meeting with MIP to discuss concerns that a breach affecting a large share of the life‑insurance sector’s administration layer could pose a systemic risk. The authority concluded that the breach did not constitute a systemic threat.

Under South Africa’s Protection of Personal Information Act (POPIA), the responsibility to notify the regulator and affected individuals lies with the data controller – in this case, each insurer – rather than with the data processor, MIP. The Information Regulator has previously fined organisations for compliance failures discovered after a cyberattack, rather than for the attack itself. The regulator’s investigation into the MIP incident remains open and ongoing.

Ransom payment and aftermath

In a surprising turn, MIP confirmed that it paid the ransom demanded by The Gentlemen. While the amount was not disclosed, CEO Richard Firth described it as substantial. In return, the attackers pledged to destroy the stolen data. MIP conducted anti‑money‑laundering checks on the accounts involved before payment, following advice from cyber and legal specialists brought in immediately after the breach was discovered.

Despite these precautions, The Gentlemen listed the insurance giant Hollard on their leak site on 7 September. MIP identified markers linking the leaked material to the data taken in June. Hollard stated that forensic investigations found no evidence of compromise within its own environment and attributed the leak to the MIP incident. Hollard has yet to confirm whether its customer information was among the records taken or whether it notified the Information Regulator and policyholders at the time of discovery.

Why this matters

The incident highlights the vulnerability of shared IT platforms in the insurance sector and the potential for widespread data exposure when a single service provider is compromised. It also underscores the importance of robust credential management, data obfuscation practices, and clear regulatory responsibilities under POPIA.

Key takeaways

  • 400,000 customer records stolen from MIP’s Atlassian support platform.
  • Data included e‑mail, cellphone numbers, policy and identity numbers, and limited addresses.
  • Attackers accessed the platform via reused credentials from a breached personal laptop.
  • MIP paid a substantial ransom, after which attackers agreed to destroy the data.
  • Regulatory bodies remain investigating compliance and systemic risk implications.

Why it matters

The breach exposes the fragility of shared insurance IT infrastructure and raises questions about data protection compliance, regulatory responsibilities, and systemic risk in the South African insurance market.

Key points

  • 400k records stolen from MIP’s Atlassian platform
  • Attackers accessed platform via reused credentials
  • MIP paid ransom and data was destroyed
  • Regulators investigating compliance and systemic risk
  • Hollard linked to leaked data but found no internal breach

Frequently asked questions

What data was stolen in the breach?

E‑mail addresses, cellphone numbers, policy numbers linked to identity numbers, and a small number of residential addresses were taken from about 400,000 records.

How did the attackers gain access?

They used credentials reused by an employee on a personal laptop that had been compromised in another breach, then accessed MIP’s Atlassian Jira support platform.

Did MIP’s core systems get compromised?

No, MIP stated that its core administration systems were not touched during the intrusion.

What actions did regulators take?

The Information Regulator and Prudential Authority were notified; the regulator’s investigation remains open, and the authority assessed the breach as not posing systemic risk.

Reporting drawn from

More from World

Felo News, House 42, Bridge Colony, Kot Lakhpat, Lahore, Pakistan
+92 308 4354717 · felopronews@gmail.com