The ransomware group The Gentlemen, already tied to the June breach at South African software supplier MIP Holdings, added three more local names to its leak site: legal-expenses insurer LegalWise, municipal medical scheme Samwumed, and Edcon. TechCentral saw countdown timers on Monday 5 October with a little over 100 hours left, which puts expiry on Friday afternoon, 9 October.
What happened
The listings had no sample data. They carried short company profiles that look like they were copied from business directories. TechCentral could not verify that the group holds data for those three, or that any of it came from MIP.
Only LegalWise has publicly confirmed it was caught up in the MIP incident. On 26 June it said there was no evidence of access to its core systems, member databases or transactional platforms. Its insurer notified the Information Regulator. Samwumed and Edcon have not said whether they used MIP. Edcon no longer trades.
MIP's own breach is not in dispute. Attackers used a reused password to reach a Jira support platform MIP was switching off. They were in from about 25 May until mid-June and took about 400,000 records, including identity numbers, email addresses and cellphone numbers pasted into tickets. About 45 insurers were exposed. MIP paid a ransom. The group later published Hollard funeral-policyholder data anyway.
Who is affected
- LegalWise, which has confirmed third-party exposure via MIP.
- Samwumed and Edcon, named on the leak site with no public confirmation and no sample.
- Customers of the roughly 45 insurers whose staff data sat in MIP support tickets.
What to do now
If you are an MIP client, or you insure people who are, confirm your notification duty under POPIA before Friday and do not treat a paid ransom as proof the data is gone.
The Information Regulator has said MIP's was the only notification it had received, even though each insurer is the responsible party. A leak-site timer is a claim, not proof. Plan communications as if a dump can land on 9 October.
Source: TechCentral, 5 October 2026. Ransomware gang threatens to dump more South African client data.
Also on the blog
- Denmark CPR breach exposes 8.8 million identity records
- CVE-2026-21589 lets attackers read files in 8 Atlassian products
- CVE-2026-63277: LibreOffice spreadsheet runs code with no macro warning
- CVE-2026-86360: Dell System Update path traversal to root
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.