Hollard: Hollard data hits dark web after MIP hack

Hollard: Hollard data hits dark web after MIP hack

Cybercrime Group "The Gentlemen" Leaks Hollard Customer Data After Third-Party Breach

A cybercrime group known as The Gentlemen has published stolen data from South African insurer Hollard on the dark web, following a June 2026 ransomware attack on its third-party technology provider, MIP Group. The group, which demanded a ransom from Hollard to prevent the data’s release, has now made customer information publicly accessible.

The breach stems from a cyberattack on MIP Holdings, a provider of policy administration and customer relationship management systems for insurers, healthcare providers, and financial services firms. The incident potentially exposed data linked to 45 South African insurance companies, though Hollard states the leaked information appears limited to individual funeral policyholders. While MIP reportedly paid an undisclosed ransom, The Gentlemen shifted focus to extorting its clients, including Hollard.

Hollard confirmed the data’s publication but emphasized that the breach did not originate from its own systems. The company has notified affected customers and regulatory authorities, stating that forensic investigations found no evidence of compromise within Hollard’s environment.

The Gentlemen, active since mid-2025, employs a double-extortion tactic encrypting victims’ files while threatening to leak stolen data if ransom demands go unmet. The group operates a ransomware-as-a-service (RaaS) model, offering affiliates a 90% cut of profits. Based on analysis by FortiGuard Labs, the group avoids targeting organizations in Russia and Commonwealth of Independent States (CIS) countries, suggesting ties to Russian-speaking regions. As of early 2026, its leak site listed over 200 victims across 50+ countries, spanning industries like energy, government, and healthcare.

Source: https://www.itweb.co.za/article/hollard-data-hits-dark-web-after-mip-hack/wbrpOqg2J5oMDLZn

Hollard Insurance cybersecurity rating report: https://www.rankiteo.com/company/hollard-insurance

"id": "HOL1790015448",
"linkid": "hollard-insurance",
"type": "Ransomware",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Individual funeral '
                                              'policyholders',
                        'industry': 'Insurance',
                        'location': 'South Africa',
                        'name': 'Hollard',
                        'type': 'Insurance Company'},
                       {'customers_affected': '45 South African insurance '
                                              'companies',
                        'industry': 'IT Services, Policy Administration, CRM',
                        'location': 'South Africa',
                        'name': 'MIP Group',
                        'type': 'Technology Provider'}],
 'attack_vector': 'Third-party compromise (MIP Group)',
 'customer_advisories': 'Yes (affected customers notified)',
 'data_breach': {'data_exfiltration': 'Yes',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'Personally identifiable information '
                                        '(PII)',
                 'type_of_data_compromised': 'Customer data (funeral '
                                             'policyholders)'},
 'date_detected': '2026-06',
 'description': 'A cybercrime group known as *The Gentlemen* has published '
                'stolen data from South African insurer Hollard on the dark '
                'web, following a June 2026 ransomware attack on its '
                'third-party technology provider, MIP Group. The group '
                'demanded a ransom from Hollard to prevent the data’s release, '
                'but has now made customer information publicly accessible.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage to '
                                       'Hollard',
            'data_compromised': 'Customer data (funeral policyholders)',
            'identity_theft_risk': 'High (personally identifiable information '
                                   'exposed)',
            'operational_impact': 'Regulatory notifications, Customer '
                                  'advisories',
            'systems_affected': 'Third-party provider (MIP Group) systems'},
 'initial_access_broker': {'data_sold_on_dark_web': 'Yes'},
 'investigation_status': 'Ongoing (forensic investigation completed for '
                         'Hollard)',
 'motivation': 'Financial gain (extortion), Data exfiltration',
 'post_incident_analysis': {'root_causes': 'Third-party compromise (MIP '
                                           'Group), Double-extortion '
                                           'ransomware attack'},
 'ransomware': {'data_encryption': 'Yes (double-extortion tactic)',
                'data_exfiltration': 'Yes',
                'ransom_demanded': 'Yes (undisclosed amount)',
                'ransom_paid': 'MIP Group paid (undisclosed amount), Hollard '
                               'did not pay'},
 'references': [{'source': 'FortiGuard Labs'}],
 'regulatory_compliance': {'regulatory_notifications': 'Yes'},
 'response': {'communication_strategy': 'Customer and regulatory notifications',
              'incident_response_plan_activated': 'Yes',
              'remediation_measures': 'Forensic investigation, Customer '
                                      'notifications'},
 'threat_actor': 'The Gentlemen',
 'title': "Cybercrime Group 'The Gentlemen' Leaks Hollard Customer Data After "
          'Third-Party Breach',
 'type': 'Ransomware, Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.