More than three months after attackers gained access to the personal information of insurance company clients through software provider MIP Holdings, the Information Regulator continues to determine how many insurers and policyholders were affected. This process is conducted jointly with MIP, not directly with the insurers.
In a written response to inquiries from TechCentral, the regulator confirmed that MIP notified about the leak in accordance with Section 22 of the Personal Data Protection Act (Popia), which governs notifying the regulator about security breaches. The regulator stated that it is interacting with MIP to establish the circumstances that led to the leak, including the number of affected parties and data subjects.
According to Popia, the responsible party is the organization that determines why and how personal data is processed—in this case, each insurance company. MIP, which processes data on their behalf, acts as the operator. Data subjects are the individuals to whom this information belongs.
The regulator emphasized: 'The obligation lies with the responsible party regarding appropriate processing.' The operator's duty is to inform its client 'without undue delay' when it has reasonable grounds to believe that personal information has been obtained or accessed by an unauthorized person.
When asked by the regulator about the number of notifications received regarding this incident and from whom they came, it confirmed receiving them only from MIP. It did not specify whether any of the insurers had notified it separately. MIP CEO Richard Firth previously told TechCentral earlier this month that about 45 of MIP's client organizations, almost all of which are insurance companies, were affected by the incident.
The regulator declined to disclose the scale, status, or nature of its investigation, including whether it extends to insurers, stating that doing so could harm the regulatory process. It noted that its enforcement powers can be applied to responsible parties and, where applicable, to operators.
Actions of Prudential Authority
The Prudential Authority (PA), a division of the Reserve Bank that supervises insurers, learned about the incident around mid-June 'based on information provided by some supervised financial institutions.' Following this, PA requested additional information from these institutions and initiated a meeting with MIP.
PA stated that third-party service providers are not required to report to it directly. The responsibility, again, lies with the insurers. PA explained that supervised institutions must assess incidents affecting their systems, operations, or information, even if they occur at a service provider. If the incident is classified as material, the institution is obliged to report it to PA within 24 hours in accordance with General Standard 2 of 2024 on Cybersecurity and Cyber Resilience.
PA declined to specify which insurers reported the incident, when it occurred, or how many reports it received, calling this information confidential supervisory information. It also did not confirm Firth's version that the meeting with the Reserve Bank showed the leak did not pose a systemic risk. PA only stated that it and relevant functions of the Reserve Bank monitor such incidents for their potential impact on financial stability, considering factors such as service disruptions, containment measures taken, and the potential risk of 'spreading or intensifying across the sector.'
MIP paid a ransomware group known as The Gentlemen a sum that Firth described only as significant, in exchange for a promise to destroy the data. This promise was not kept. The group has since published data of Hollard funeral insurance policyholders on a darknet leak site, including names of their children, identification numbers, and email addresses. According to TechCentral, Hollard refused the ransom demand.
Paying the ransom does not solve anything
Both regulators clearly stated that MIP's payment does not change the position for insurers. The Information Regulator noted that it cannot comment on 'MIP's interactions with threat actors,' as it is concerned about whether responsible parties have adequate measures in place to protect the confidentiality and integrity of personal information. However, it added: 'However, the payment of the ransom itself cannot be understood to establish or resolve compliance with Popia requirements.'
PA stated that the ransom payment 'does not conclude the incident and does not relieve the supervised institution of its obligations in terms of governance, risk management, notification, and customer protection.' It expects insurers involved in the supplier leak to receive assurances regarding containment, recovery, and remediation, and to assess the impact of the incident on their clients.
The Information Regulator indicated that whether the Hollard leak requires a new notification depends on the facts, including what was known about the initial compromise and whether the subsequent publication constitutes a separate unauthorized access or acquisition. It also stressed: 'A previously submitted notification does not provide, as a general rule, a full exemption from subsequent obligations under Popia.'
Similarly, a later publication does not automatically require a second notification under Section 22.
Hollard stated that it notified clients affected by the incident in June, is interacting with relevant regulators, and found no evidence of compromise in its own systems.
Although MIP is not regulated or supervised by PA, the leak, which began with attackers using reused employee credentials to access a platform the company was decommissioning, affected nearly half of its insurance clients.
When asked by PA how it assesses concentration risk when one unregulated software provider serves a large portion of one sector, it responded that third-party risk management remains the responsibility of supervised institutions. PA annually collects and analyzes information on material third-party agreements and outsourcing from these institutions to identify potential concentration risks. It declined to confirm MIP's figures on the number of affected clients.
PA also did not comment on whether it has concluded its interaction with MIP or plans any supervisory actions. It concluded: 'If deficiencies are identified, PA may address them through its established supervisory processes.'
