
More than three months after attackers took the personal information of insurance customers from software supplier MIP Holdings, the Information Regulator is still trying to establish how many insurers and policyholders were affected – and it is working that out with MIP, not the insurers.
In a written response to questions from TechCentral, the regulator confirmed that MIP reported the breach as required under section 22 of the Protection of Personal Information Act (Popia), which deals with notifying the regulator of security compromises. It said it was engaging with MIP “to establish the circumstances that led to the breach including the number of responsible parties and data subjects that have been affected”.
Under Popia, the responsible party is the organisation that decides why and how personal information is processed – in this case, each insurer. MIP, which processes the data on their behalf, is an operator. Data subjects are the people the information belongs to.
“The obligation rests on the responsible party in respect of the processing concerned,” the regulator said. An operator’s duty is to tell its client “without undue delay” when it has reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person.
Asked how many notifications it had received in connection with the incident, and from whom, the regulator confirmed only MIP’s. It did not say whether any of the insurers had notified it separately. MIP CEO Richard Firth told TechCentral earlier this month that about 45 of its client organisations, almost all of them life insurers, were affected.
The regulator declined to disclose the scope, status or substance of its investigation, including whether it extends to the insurers, saying that could prejudice the regulatory process. Its enforcement powers, it said, may be exercised against responsible parties and, where applicable, operators.

The Prudential Authority (PA), the Reserve Bank arm that supervises insurers, said it became aware of the incident around mid-June “through information shared by certain affected supervised financial institutions”. It then sought more information from those institutions and requested a meeting with MIP.
The PA said third-party service providers are not required to report to it directly. The obligation, again, lies with the insurers. Supervised institutions must assess incidents affecting their systems, operations or information, including those that originate at a service provider, the PA said. Where an incident is classified as material, the institution must report it to the PA within 24 hours under Joint Standard 2 of 2024 on Cybersecurity and Cyber Resilience.
The PA would not say which insurers reported the incident, when they did so or how many reports it received, describing this as confidential supervisory information.
Nor would it confirm Firth’s account that a meeting with the Reserve Bank concluded the breach did not pose a systemic risk. The PA said only that it and the relevant functions of the Reserve Bank monitor incidents of this kind for their potential impact on financial stability, weighing factors such as disruption to services, the containment measures taken and the potential for risk “to transmit or amplify across the sector”.
MIP paid the ransomware group, known as The Gentlemen, a sum Firth would describe only as substantial, in exchange for an undertaking to destroy the data. The undertaking did not held. The group has since published Hollard funeral policyholders’ details on a dark web leak site, including the names of their children, identity numbers and e-mail addresses. Hollard refused a ransom demand, TechCentral has learnt.
A ransom payment settles nothing
Both regulators made clear that MIP’s payment changes nothing for the insurers. The Information Regulator said it could not comment on MIP’s “engagements with threat actors”, as its concern is whether responsible parties have adequate measures to protect the confidentiality and integrity of personal information. “The payment of a ransom should, however, not be understood, in itself, as either establishing or resolving compliance with Popia,” it said.
The PA said a ransom payment “does not conclude an incident or relieve a supervised institution of its governance, risk management, notification and customer protection responsibilities”. It expects insurers caught up in a supplier’s breach to obtain assurance about containment, recovery and remediation and to assess the impact on their customers.
Whether the Hollard leak triggers a fresh notification duty depends on the facts, the Information Regulator said, including what was known about the original compromise and whether the later publication amounts to a separate unauthorised access or acquisition. “An earlier notification does not, as a general proposition, provide a blanket exemption from subsequent obligations under Popia,” it said. Equally, a later publication does not automatically require a second section 22 notification.
Hollard has said it notified customers affected by the June incident, is engaging with the relevant regulators and has found no evidence of compromise within its own systems.

MIP is not regulated or supervised by the PA. Yet the breach, which began when attackers used an employee’s reused credentials to reach a support platform the company was decommissioning, touched close to half its insurer clients.
Asked how it assesses concentration risk where a single unregulated software supplier serves a large share of one sector, the PA said third-party risk management remains the responsibility of supervised institutions. It collects and analyses information on material third-party and outsourcing arrangements from those institutions once a year to identify potential concentration risks. It declined to validate MIP’s figures on how many clients were affected.
The PA would not say whether it has closed its engagement with MIP or whether it plans any supervisory action. “Where shortcomings are identified, the PA may address them through its established supervisory processes.” – © 2026 NewsCentral Media





