South Africa’s insurance sector is still dealing with the consequences of a breach that began with a single reused password. Three months on, 45 insurers are navigating unresolved regulatory obligations, one ransomware group has published the data anyway, and the Information Regulator has clarified a legal position that every responsible party in the country needs to understand.
MIP Holdings, a South African insurance software and administration company, discovered in mid-June 2026 that attackers had been inside its environment since approximately 25 May. The entry point was not a sophisticated exploit. An employee had reused a password on an unrelated service that had itself been breached. With those credentials, the attackers reached the employee’s personal laptop and, from there, an Atlassian Jira support platform MIP had decommissioned. Support tickets that should have contained obfuscated data held ID numbers, email addresses, and cellphone numbers in the clear.
The attackers were inside for approximately three weeks before detection. By the time MIP discovered the intrusion, attackers had exfiltrated data belonging to customers of about 45 insurance companies. That is roughly 400,000 records, affecting just under half of MIP’s client base, almost all of them life insurers.
MIP paid a ransom. The company’s CEO, Richard Firth, confirmed it was a substantial amount, paid after running anti-money-laundering checks, in exchange for an undertaking to destroy the data.
The data was not destroyed. The Gentlemen ransomware group listed Hollard on their leak site on 7 September. More than 100,000 Hollard funeral-policy records, including children’s names and identity numbers, were published after Hollard declined a separate demand.
The ransom bought nothing except three months of uncertainty.
What the Information Regulator Said and Why Every Insurer Should Read It
On 25 September 2026, TechCentral reported the Information Regulator’s formal position on the MIP incident. It is the clearest statement the Regulator has made this year on the relationship between operators and responsible parties under POPIA, with significant implications well beyond the insurance sector.
Only MIP filed a section 22 breach notification. The Regulator confirmed that the legal notification duty sits not with MIP as the operator, but with the insurers as the responsible parties. Each insurer whose customer data was held by MIP carries its own independent obligation to notify the Regulator and affected data subjects as soon as it has reasonable grounds to believe a compromise has occurred.
The Regulator was explicit on the ransom payment:
“The payment of a ransom should, however, not be understood, in itself, as either establishing or resolving compliance with POPIA.”
Paying a ransom does not discharge your notification obligation. It does not demonstrate that adequate security safeguards were in place before the breach. And it does not protect you from regulatory scrutiny of whether your operator agreement with MIP gave you sufficient governance rights and oversight to have known about the breach sooner.
Three months after the incident, the Regulator was still working with MIP to determine how many insurers and policyholders were affected. That is not a position any responsible party should find itself in.
The Prudential Authority Adds Its Signal
The Prudential Authority (PA) told TechCentral it learned of the MIP incident around mid-June through information shared by certain affected supervised financial institutions. Its message to those institutions was equally clear.
It expects insurers caught up in a supplier’s breach to obtain assurance about containment, recovery, and remediation. It noted that third-party providers such as MIP are not required to report to the PA directly, which means the obligation to know what is happening inside your supplier’s environment sits entirely with you.
The Joint Standard on Cybersecurity and Cyber Resilience Requirements, in effect since June 2025, requires reporting of material incidents within 24 hours. That clock starts when the supervised institution knows. As Orange Cyberdefense’s Willem Steynberg noted when commenting on the MIP incident, insurers’ 24-hour clock with the Prudential Authority only starts when they know. How quickly you know depends on what your operator agreement requires of your supplier for breach notification timelines, and whether you monitor those requirements.
The Credential at the Root of It All
The MIP breach began with a reused password. Not a sophisticated intrusion. Not a nation-state actor. An employee used the same credential across multiple services, one of which had previously been compromised. That credential provided the initial foothold.
The National Cybersecurity Alliance published the global Cybersecurity Awareness Month theme for 2026 as “Don’t Make It Easy for Them”. Its four foundational actions are:
- Strong and unique passwords managed through a password manager
- Multi-factor authentication (MFA)
- Software updates applied promptly
- Recognizing and reporting scams
The MIP breach is a direct illustration of what happens when the first of those four actions is neglected, not just on corporate devices, but on personal devices that can access corporate platforms. The employee’s personal laptop bridged a breached third-party credential and MIP’s internal Jira environment. Most organisations apply password governance to their own corporate accounts. Very few extend equivalent requirements to personal devices that access corporate SaaS platforms.
The Sophos State of Ransomware South Africa 2026 report, published in September, found that compromised credentials were the leading technical root cause of ransomware incidents in South Africa, accounting for 27% of cases. The MIP incident is a case study in exactly that vector, at a scale that affected 45 separate organisations through a single point of failure.
The Pattern Connecting MIP, RelyComply, and the August Cluster
The MIP breach does not stand alone. It sits within a pattern that has defined South Africa’s cyber risk landscape throughout 2026:
- September (RelyComply): A compliance and identity verification platform experienced a confirmed cyber incident that triggered breach notifications from Cell C, EasyEquities, Satrix, Bidvest Bank, and Peregrine Capital in the same weekend. The breach entered through a third-party access relationship, impacting financial services brands whose own systems were secure.
- August (Ransomware Cluster): Attacks hitting Hungry Lion, The Courier Guy, Babcock Africa, and others demonstrated that threat actors are working systematically through South Africa’s commercial ecosystem, targeting organisations whose operational disruption creates downstream pressure across multiple sectors.
In each case, the breach did not originate inside the primary organisation’s core defended environment. It came through a trusted relationship, platform, supplier, operator, or shared service.
The 2026 Verizon Data Breach Investigations Report found that third-party involvement appeared in 48% of confirmed breaches globally, up from 30% the prior year. South Africa’s breach record is tracking that trajectory with uncomfortable precision.
What Your Operator Agreements Need to Contain
POPIA draws a clear distinction between responsible parties (organisations that determine the purpose and means of processing personal information) and operators (organisations that process it on their behalf). That distinction matters because it defines where accountability sits.
Many South Africans have not yet absorbed that being the responsible party does not mean your accountability begins only when something goes wrong inside your own environment. It means your accountability extends to how your operators handle the data you have entrusted to them, including whether they notify you promptly when something goes wrong in their environment.
Section 21 of POPIA requires responsible parties to ensure that operators they engage provide sufficient guarantees about their security measures and comply with POPIA’s conditions. A standard data processing agreement drafted once at onboarding and never reviewed does not meet that requirement. It requires active governance: contractual notification timelines, audit rights, minimum security standards, and a clear escalation path that gets information to the right people inside your organisation quickly enough to keep the 24-hour PA reporting clock manageable.
The MIP case shows what happens without that governance: 45 insurers learned about a breach affecting their customers through a notification from MIP, three months after the attacker had already been in the environment, after the ransom had been paid, and after the data had been published on a dark web leak site.
The Ransom Payment Question South Africa Needs to Answer
Richard Firth’s public call for South Africa to ban ransomware payments, made on 29 September, reflects a genuine and growing industry debate. The UK has moved to ban payments by public bodies and critical national infrastructure operators, while Australia has deferred a similar ban. South Africa signed the International Counter Ransomware Initiative statement in November 2023, which states that national government institutions should not pay ransoms.
MIP’s experience is the most instructive local case study available:
- The ransom was paid.
- The data was published anyway.
- The regulatory obligations of 45 responsible parties remained unchanged by the payment.
This is not a criticism of MIP’s decision in the circumstances it faced. It is an argument for every South African organisation to have a board-approved ransom payment policy in place before it faces the same circumstances, so decisions are made within a governance framework rather than under extreme operational pressure.
What to Put on the Board Agenda This Month
Cybersecurity Awareness Month 2026 is the right moment for South African organisations to move the third-party risk conversation from the contract register to the board agenda:
- Map every operator: Include support and ticketing platforms, not just core systems. The MIP data sat in Jira support tickets. Most organisations have no visibility into what categories of personal information their helpdesk platforms hold.
- Review operator agreements: Check notification timelines, audit rights, and minimum-security standards. A contract requiring notification within 30 days is useless if the PA’s reporting clock starts at 24 hours.
- Pre-draft Section 22 notices: Prepare template communications for data subjects and the Regulator ahead of time. Drafting these during an active incident produces avoidable delays.
- Adopt a board-approved ransom payment policy: Define who can authorize payment, what criteria apply, and what protocols take effect if attackers fail to honor their word.
- Apply credential hygiene to personal devices: If your governance only covers corporate devices accessing SaaS platforms, the gap between your policy and your actual attack surface remains a gaping vulnerability.
The MIP breach cost 45 organisations their customers’ data, a ransom payment, and three months of regulatory uncertainty. The entry point was a reused password on a decommissioned platform.
Cyber Awareness Month’s theme reminds us: “Don’t Make It Easy for Them.” The MIP breach made it very easy.
SS-Consulting helps South African organisations build third-party risk governance and operator oversight frameworks that meet the standards POPIA, the Prudential Authority, and the Information Regulator now clearly expect. Visit www.ss-consulting.co.za.

