An office building in Midrand, South Africa
Context image: commercial offices in Midrand; not confirmed as the breached site. Photo: Property24.

Payment did not buy certainty

MIP chief executive Richard Firth confirmed that the company paid a substantial undisclosed ransom after a June breach. The Gentlemen group allegedly promised to destroy stolen material, yet data later appeared online. Reporting said about 45 insurers were affected.

Why This Matters

Ransom payment can purchase a decryptor or a temporary delay, but it cannot make copied data un-copied. The case illustrates the asymmetry: the victim must trust criminals to keep a promise that is difficult to verify and easy to break.

The ecosystem and disputed responsibility

Insurers depend on shared administrators and software providers, so one supplier can become a concentration point. Hollard said there was no evidence its own environment was compromised and pointed to MIP. That distinction matters for containment, notification and liability even when customers experience the breach as one event.

What happens next

Affected companies need verified notification scopes, credential resets where appropriate and monitoring for identity fraud and targeted phishing. Regulators will examine safeguards and disclosure timing. The strategic lesson is to invest in segmentation, immutable backups and rehearsed recovery before an attacker turns urgency into negotiating leverage.

Sources: TechCentral breach report, TechCentral ransom report, ITWeb. Facts and figures are a fixed September 20, 2026 reporting snapshot and do not update live.

Technology / CybersecurityBack to today’s edition