Data breach
Hollard Insurance Group
- Records
- 278,812
- Breach date
- 7 September 2026Estimated
- Added
- 24 September 2026
What was exposed
4 types of data · 1 more reported
- Names278,812
- Dates of birth148,267
- Email addresses70,678
- Phone numbers47,976
- Government IDsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
The criminal group calling itself The Gentlemen has published data linked to South African insurer Hollard Insurance Group on its dark web leak site. According to our investigation team, the listing covers 278,812 rows of records associated with hollard.co.za, and the group claimed the attack on September 7, 2026.
The leak sits within a larger incident. In June 2026, attackers breached MIP Holdings, a technology provider that handles policy administration for insurers, exposing personal information linked to customers of roughly 45 South African insurance companies. Hollard says its own systems were not compromised and that the published information traces back to the MIP incident. MIP paid the extortionists a substantial, undisclosed sum in exchange for a promise to destroy the data, but the group kept the material and has since demanded ransoms from insurers, including Hollard, which reportedly refused to pay. The South African insurer appears to have been hit hardest among those named so far.
Breach Timeline
June 14, 2026: MIP Holdings detected a cyber extortion attack targeting its Jira project management platform, according to a company breach notification.
June 16, 2026: MIP notified South Africa's Information Regulator under section 22 of the Protection of Personal Information Act.
September 7, 2026: The Gentlemen listed Hollard Insurance Group on its leak site, warning it would publish stolen data unless the company negotiated, as tracked by ransomware.live.
September 18, 2026: TechCentral and ITWeb reported that Hollard customer data had been dumped on the dark web.
What Information Was Compromised?
Our analysis found the following data types in this breach: full names, dates of birth, email addresses, and phone numbers. Names appeared in every record in the dataset, while the other types were present for smaller portions of it.
Reporting by TechCentral, based on material the outlet reviewed on the group's leak site, additionally found policyholder names, the names of children attached to the policies, South African identity numbers, and email addresses among the published records.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Identity numbers are the most serious element here. Unlike a password, they cannot be changed, and they are central to opening accounts and verifying identity in South Africa. Combined with a name and email address, they provide the raw material for identity fraud.
Dates of birth, emails, and phone numbers enable targeted phishing. Criminals can craft convincing messages that reference real policy details, funeral policies, or family members. Because the affected records appear to involve funeral policyholders, children's names may be included, raising concerns for minors whose identities were exposed. Watch for fake communications claiming to come from Hollard, brokers, or insurers, especially any that ask for banking details or identity documents.
What Is Hollard Insurance Group Doing in Response?
Hollard says it identified the threat through its threat intelligence monitoring, activated its incident response processes, and engaged forensic investigators. In statements reported by ITWeb and TechCentral, the company said forensic work has found no evidence of compromise within its own environment and that the published data is linked to the June 2026 incident at MIP. Hollard said it has already notified customers affected by the June incident and is engaging with regulatory authorities. The company declined to comment on any payment details and urged customers to stay alert to phishing and unsolicited requests for personal or financial information.
What Should You Do If You Were Affected?
Treat unexpected calls, emails, or SMS messages about your policy with suspicion, even if the sender knows your name.
Never share your identity number, banking details, or passwords in response to an unsolicited request.
Monitor your bank accounts and consider checking your credit record with South African credit bureaus for activity you did not authorize.
If you receive a suspicious message referencing Hollard or your funeral policy, contact the company directly through the number on your policy documents, not through the contact details in the message.
Report suspected identity fraud to the South African Police Service and the Information Regulator.
In the news
- TechCentral: Hollard client data dumped on dark webtechcentral.co.za (opens in a new tab)
- ITWeb: Hollard data hits dark web after MIP hackitweb.co.za (opens in a new tab)
- ITWeb: Hollard rejects hacking claim, points to MIP cyber breachitweb.co.za (opens in a new tab)
- Ransomware.live: Hollard Insurance Group victim entryransomware.live (opens in a new tab)
