
The ransomware group behind the June breach at software supplier MIP Holdings has added three more South African organisations to its dark web leak site: legal-expenses insurer LegalWise, municipal workers’ medical scheme Samwumed and Edcon, the retailer that collapsed into business rescue in 2020.
Each listing carries a countdown timer. At about 11am on Monday, according to listings seen by TechCentral, the three timers had a little over 100 hours to run, putting their expiry on Friday afternoon, 9 October.
The listings contain no sample data, only short company profiles that appear to have been compiled from business directories such as ZoomInfo. TechCentral has not been able to verify that the group, known as The Gentlemen, holds data belonging to LegalWise, Samwumed or Edcon, or that any such data came from the MIP incident.
Of the three, only LegalWise has publicly confirmed that it was caught up in the MIP breach. In a statement on 26 June, it said MIP had identified unauthorised access to a legacy system used for software development and support, and that there was no evidence of unauthorised access to LegalWise’s core systems, member databases or transactional platforms.
In a later update, it said its insurer, Legal Expenses Insurance Southern Africa, had notified the Information Regulator and that it was not aware of any fraudulent use of information associated with the incident.
Samwumed and Edcon have not said publicly whether they used MIP’s services. MIP supplies policy administration and CRM software to insurers, medical schemes, lenders and pension administrators. Edcon no longer trades; its Edgars and Jet chains were sold off during its business rescue. TechCentral has reached out to Samwumed for comment and will update this article when feedback is received.
The group also listed Guardrisk, part of Momentum Group, in late September. TechCentral has not established whether that listing is linked to MIP. No Guardrisk client data had been published on the dark web by The Gentleman at the time of publication.
A ransom that bought nothing
MIP CEO Richard Firth told TechCentral last month that personal information belonging to customers of about 45 insurance companies – just under half of MIP’s client base and almost all of them life insurers – was taken in June.
The intruders reached an Atlassian Jira support platform that MIP was decommissioning, using credentials an employee had reused on an unrelated service that had itself been breached.
They were inside from about 25 May until MIP noticed in mid-June, and took about 400 000 records, including identity numbers, e-mail addresses and cellphone numbers that clients’ staff had pasted into support tickets.
MIP paid the group a sum Firth would describe only as substantial, in exchange for an undertaking to destroy the data. That undertaking did not hold. The Gentlemen listed Hollard on its leak site on 7 September, and MIP identified markers linking that material to the June breach. Hollard refused a ransom demand, and the group went on to publish Hollard funeral policyholders’ details, including the names of their children, identity numbers and e-mail addresses. Hollard has said its own systems were not compromised.

The Information Regulator told TechCentral last month that MIP’s was the only notification it had received in connection with the incident, even though under Popia the obligation to notify rests with each insurer as the responsible party.
It also said the payment of a ransom should not be understood “in itself, as either establishing or resolving compliance with Popia”. The case has added weight to the question of whether South Africa should ban ransomware payments.
The Gentlemen
The Gentlemen is a ransomware-as-a-service operation that emerged in mid-2025 and supplies its tools to affiliates, who carry out the attacks. Check Point Research counts more than 400 public victims and ranks it as the second most active ransomware group in the world this year. It says the group typically gets in through VPNs and network appliances, by buying access from brokers or by using credentials harvested from infostealer logs. – © 2026 NewsCentral Media





