Monday, 5 October 2026
Tech & Telco

Ransomware gang threatens to leak data of three South African firms

Ransomware gang threatens to leak data of three South African firms

According to TechCentral, the ransomware group known as The Gentlemen has added three South African organisations to its dark-web leak site and attached countdown timers that will expire on 9 October.

The listings show LegalWise, the legal-expenses insurer; Samwumed, a municipal workers’ medical scheme; and Edcon, the former retailer now in business rescue. At about 11 am on Monday the timers displayed just over 100 hours remaining, meaning the data could be published by Friday afternoon.

TechCentral has not been able to verify that The Gentlemen actually holds data belonging to any of the three firms, nor that the data would come from the June breach at software supplier MIP Holdings. Of the three, only LegalWise has publicly confirmed it was caught up in the MIP incident. In a statement on 26 June the insurer said MIP identified unauthorised access to a legacy system used for software development and support, but found no evidence of unauthorised access to LegalWise’s core systems, member databases or transactional platforms.

MIP supplies policy administration and customer-relationship-management software to insurers, medical schemes, lenders and pension administrators. Its chief executive Richard Firth told TechCentral that about 400 000 records, identity numbers, e-mail addresses and cell-phone numbers, were taken after intruders accessed an Atlassian Jira support platform using reused employee credentials. MIP paid the attackers a sum described only as substantial in exchange for a promise to destroy the data, a promise that was not kept.

The Gentlemen operate as a ransomware-as-a-service (RaaS) outfit, meaning they provide the malicious tools to affiliates who carry out the attacks. Check Point Research counts more than 400 public victims and ranks the group as the second most active ransomware gang worldwide this year. Their typical entry points include vulnerable VPNs, network appliances, purchased access from brokers or credentials harvested from infostealer logs.

Under the Protection of Personal Information Act (POPIA), the responsibility to notify the Information Regulator rests with each data-controller, in this case the insurers and schemes that hold the personal information. The regulator said it had only received a notification from MIP, even though many insurers were affected. It also warned that paying a ransom does not automatically satisfy POPIA compliance, adding weight to calls for a ban on ransomware payments in South Africa.

For small-business owners and entrepreneurs, the episode highlights the risk of third-party software providers. If a company relies on a supplier like MIP for critical data processing, a breach at the supplier can expose the client’s customers and trigger regulatory scrutiny. Keeping an eye on notifications from insurers, schemes and other service providers, and reviewing contractual clauses on data security, are practical steps to mitigate exposure.

Read more about similar cyber-security developments in our Tech & Telco coverage.

The three leak listings provide only brief corporate profiles, apparently drawn from public directories such as ZoomInfo, and do not include any sample records for verification, a detail highlighted by the source material. This absence of data samples makes it harder for the affected firms to assess the scope of any potential exposure. While LegalWise has confirmed its involvement in the June breach, the other two entities, Samwumed and Edcon, have not issued public statements regarding their use of MIP’s services. The source also notes that the ransomware outfit previously added Guardrisk, part of Momentum Group, to its site in late September, though no Guardrisk client data had appeared at the time of reporting.

Hollard’s experience illustrates the tangible risk of refusing a ransom demand. After The Gentlemen listed Hollard on the leak platform on 7 September, the gang published funeral policyholder details, including children’s names, identity numbers and e-mail addresses, despite Hollard asserting that its own systems were not compromised. This episode underscores that a ransom payment does not guarantee data destruction, as the group’s earlier promise to MIP proved ineffective. The source confirms that Hollard declined the payment, yet the attackers still released the information, demonstrating the limited leverage a payment can provide against a determined affiliate.

Under POPIA, each data-controller must submit a notification to the Information Regulator when a breach occurs, a duty that rests with the insurers, schemes or other entities holding the personal information. The regulator has so far only received a single notification from MIP, even though many insurers were impacted, according to the source. The regulator further clarified that the act of paying a ransom does not, by itself, satisfy POPIA compliance, reinforcing the argument for a potential ban on ransomware payments within South Africa’s legal framework.

The process for a POPIA breach notification involves the affected controller compiling a report that details the nature of the breach, the categories of data involved, and any remedial steps taken. This report must be lodged with the Information Regulator promptly, after which the regulator may issue guidance or require additional actions. The source material indicates that LegalWise’s insurer, Legal Expenses Insurance Southern Africa, has already informed the regulator and reported no evidence of fraudulent use of the compromised information, illustrating a concrete example of the notification workflow in practice.

Finally, the timeline of the intrusion at MIP reveals how long attackers can remain undetected. The source states that the intruders accessed an Atlassian Jira support platform from roughly 25 May until MIP discovered the breach in mid-June, during which they extracted about 400 000 records. The compromised data comprised identity numbers, e-mail addresses and cell-phone numbers that staff had pasted into support tickets. This prolonged presence highlights the importance of rigorous credential hygiene and continuous monitoring of decommissioned systems to prevent similar prolonged exposures.