Cyber & AI intelligence
Wasteland.
Briefs indexed3016
Issues31
Published Mondays07:30 CT
▣ Breach THE-GENTLEMEN-MIP 2026-10-05

MIP Holdings Clients: The Gentlemen Ransomware Adds Legalwise, Samwumed and Edcon to Leak Site

"The Gentlemen ransomware group was behind the June 2026 breach at South African software supplier MIP Holdings. It has now added three more South African organisations to its dark web leak site: legal-expenses insurer…"

The Gentlemen ransomware group was behind the June 2026 breach at South African software supplier MIP Holdings. It has now added three more South African organisations to its dark web leak site: legal-expenses insurer LegalWise, municipal workers' medical scheme Samwumed, and Edcon, the retailer that went into business rescue in 2020. TechCentral says each listing has a countdown timer due to run out around Friday afternoon, 9 October. MIP has confirmed the June breach. Its CEO told TechCentral that about 400,000 records tied to customers of roughly 45 insurers were taken. The new listings follow the group's earlier publication of Hollard-linked data, even though MIP says the attackers had promised to delete what they stole.

What Happened

MIP's breach notification of 23 June was signed by CIO Fergus McLoskey and reported by eriinfo. It says MIP detected a cyber extortion attack on 14 June against its third-party Atlassian Jira project-management platform. MIP notified the Information Regulator on 16 June under section 22 of the Protection of Personal Information Act (POPIA). MIP CEO Richard Firth told TechCentral that the intruders spent about three weeks inside a support platform the company was in the middle of decommissioning.

The leak-site activity has come in waves:

Of the three new names, only LegalWise has publicly confirmed it was affected by the MIP breach. On 26 June it described the incident as unauthorised access to "a legacy system used for software development and support." It said there was no evidence of access to its core systems, member databases or transactional platforms. Its insurer, Legal Expenses Insurance Southern Africa, has notified the Information Regulator. Samwumed and Edcon have not said whether they used MIP. Edcon no longer trades.

What Was Taken

Firth told TechCentral that about 400,000 records were taken. They belonged to customers of about 45 organisations, just under half of MIP's client base and almost all of them life insurers. MIP's own notification is more cautious. It says the investigation was still working out the precise scope and categories of data affected, and whether data was downloaded, copied, misused or disclosed. Nothing published so far gives an independently verified record count.

Data reported as exposed includes:

Support tickets were supposed to contain obfuscated data, but they did not. When client staff logged a problem, they pasted in error messages, screenshots and reports, and the underlying customer records came with them in clear text. "That's why we were taken aback that all of this data was actually sitting inside that platform," Firth said.

MIP says its core administration systems and client policy-administration databases were not compromised.

Why It Matters

Paying for deletion did not buy deletion. MIP says it received undertakings that the stolen data had been deleted and would not be published or misused. One aggregator report says MIP paid a "substantial" undisclosed ransom after anti-money-laundering checks. That claim has not been independently confirmed in the sources reviewed here. Either way, Hollard-linked data has since been published, and new victims keep appearing on the leak site. This shows again that a ransomware group's promise to delete data is worth nothing.

Downstream victims get named whether or not they were breached. The Gentlemen is listing MIP's clients (and possibly companies with no MIP link at all) as if each had been breached directly. Hollard, Guardrisk and LegalWise have all had to rebut claims of a direct compromise. Defenders in financial services should expect supplier breaches to come back as separate extortion attempts against each client.

The group operates at high volume. Threat intelligence vendors agree the group is large and growing fast, but their numbers differ:

Sophos says the scheme began in mid-2025. Unit 42 says it was active from at least July 2025. Both agree it opened to affiliates in September 2025 and offers them a 90/10 split of ransom payments. Unit 42 says the team previously operated as ArmCorp, a Qilin affiliate. Microsoft tracks it as Storm-2697.

The Attack Technique

Accounts of the MIP intrusion agree that the attackers did not break through MIP's perimeter. They used credentials reused on an employee's personal laptop, which were reportedly exposed in an earlier, unrelated breach. With those credentials they reached the Jira support platform, which MIP had decided to retire, partly for security reasons. According to MIP, credentials found inside Jira then gave them access to certain FTP/SFTP sites.

This matches the wider playbook vendors attribute to Gentlemen affiliates:

What Organizations Should Do

  1. Treat retiring systems as live attack surface. Platforms that are being decommissioned still hold data and credentials. Lock down access, enforce MFA, and purge or archive their contents before the migration finishes, not afterwards.
  2. Scrub personal data from support channels. Use data-loss-prevention (DLP) controls or automated redaction on ticketing systems, and audit existing tickets, attachments and screenshots for ID numbers, contact details and credentials.
  3. Never store credentials in tickets or wikis. Rotate any secret found in Jira, Confluence or similar tools. Watch FTP/SFTP and file-transfer services for logins from unusual sources.
  4. Enforce phishing-resistant MFA on all remote and SaaS access, and check for exposed credentials. Monitor infostealer and breach feeds for staff credentials, including ones used on personal devices, and force resets when they turn up.
  5. Map supplier data exposure before a leak-site listing does it for you. Insurers and medical schemes should know exactly which customer data each administrator or software vendor holds. They should also have a prepared response for "we were named but not breached" claims, including when to notify the regulator.
  6. Hunt for Gentlemen tradecraft. Following Sophos guidance, look for unusual administrative activity, misuse of exfiltration tools, unexpected staging directories, and attempts to disable EDR. Patch FortiGate and Cisco edge devices as a priority.

Sources: Ransomware gang threatens to dump more South African client data | Ungentlemanly behavior: Insights into a ransomware operation SOPHOS | Customers of 45 insurers exposed in South African cyber breach | Hollard rejects hacking claim, points to MIP cyber breach - eriinfo | Hollard Denies It Was Hacked As Cyber Breach Hits Data… | Guardrisk distances itself from MIP cyber breach - ITWeb | Hollard client data (primarily related to funeral policies) has bee... | The Gentlemen: self-propagating RaaS profile Sentrix