Hollard data leak puts third-party cyber risk under the spotlight

Information reportedly associated with Hollard customers has appeared on the dark web after the ransomware group The Gentlemen published material connected to the June 2026 cyber incident at MIP.
Hollard has stressed that the development does not indicate that its own systems were breached.
The insurer said the information circulating online appears to originate from the previously disclosed MIP incident, in which personal information associated with customers of approximately 45 South African insurance companies was potentially exposed.
“Based on the forensic and assurance activities conducted to date, there remains no evidence of compromise within the Hollard environment,” Hollard said.
The company said the information identified so far appears to relate to individual funeral policyholders. Customers affected by the original incident have been notified, while Hollard continues to engage with the relevant regulatory authorities.
From supplier breach to customer exposure
MIP provides technology and administrative services to organisations across the insurance and broader financial services sectors.
The company's June incident involved unauthorised access to a Jira-based support environment. MIP subsequently disclosed that information belonging to customers of around 45 insurance companies had been exposed.
More recent reporting has put the scale of the information taken at approximately 400,000 records, although the precise scope and categories of affected information remain subject to investigation. Reported information includes contact details and policy-related information.
The incident illustrates a growing challenge for organisations that rely on external technology providers: a company may maintain controls around its own infrastructure while sensitive customer information is simultaneously exposed through a supplier's systems.
MIP has said its core policy administration systems were not compromised in the incident.
The company also confirmed that it paid the attackers an undisclosed amount following the extortion attempt. The subsequent publication of information linked to Hollard raises questions over the effectiveness of assurances provided by cybercriminal groups following ransom payments.
Hollard maintains its systems were not breached
The distinction between a direct compromise and exposure through a service provider is central to the Hollard case.
Hollard said its incident-response processes were activated after the threat emerged and that specialist forensic investigators were engaged.
The insurer maintains that there is currently no evidence that attackers gained access to its own environment.
For customers, however, the distinction may offer limited reassurance where personal information has nevertheless been exposed through a third party.
Hollard is advising customers to remain alert to unexpected communications, particularly requests for personal, banking or other sensitive information.
The warning reflects one of the principal risks following a data exposure: stolen information can potentially be used to make subsequent phishing and social-engineering attempts appear more credible.
The Gentlemen's growing presence
The group behind the extortion campaign, known as The Gentlemen, emerged in the cybercrime landscape in 2025.
According to FortiGuard Labs, the group uses a ransomware model involving the theft of sensitive information and, in some cases, encryption of victims' systems. Its extortion strategy includes the threat of publicly releasing stolen information if victims do not meet ransom demands.
FortiGuard has identified more than 200 organisations on the group's leak site as of early 2026, spanning multiple industries and more than 50 countries.
The group is also reported to operate an affiliate-based ransomware model, allowing other cybercriminals to use its infrastructure and share in ransom proceeds.
A warning for the insurance sector
For South Africa's financial services industry, the MIP incident extends beyond a single cyberattack.
The concentration of sensitive information within specialist technology providers means a successful attack on one supplier can potentially affect customers across numerous organisations simultaneously.
This makes third-party risk management an increasingly important part of cybersecurity governance.
Organisations need visibility not only into their own security controls, but also into how suppliers store, access, transmit and protect personal information on their behalf.
The Hollard case also demonstrates that the consequences of a cyberattack can continue long after the original intrusion has been contained. Information obtained during an attack can remain a liability if it is subsequently traded, published or used for further criminal activity.
For affected consumers, the immediate priority is vigilance. Unexpected requests for identity documents, policy information, passwords, banking details or other personal information should be treated with caution and independently verified.
As organisations continue to expand their dependence on interconnected technology ecosystems, the MIP incident serves as a reminder that the security boundary no longer ends at the corporate firewall.