The CEO of MIP Holdings, Richard Firth, advocates for introducing a ban on paying ransoms to ransomware groups in South Africa, based on his personal experience. He told TechCentral on Tuesday that such a ban could serve as a strong deterrent.
MIP, a company that supplies software to insurance companies, paid a significant sum to the cybercriminal group The Gentlemen after this group stole data from clients of about 45 insurers earlier this year. Firth emphasized that the attackers gained access not to MIP's administrative platforms, but to a third-party tool the company used to manage support requests—the Atlassian Jira service, which MIP was already planning to replace, according to TechCentral.
The group promised to destroy the data if payment was made, but apparently, this did not happen, and at the beginning of this month they published the data of the affected insurers. Hollard, which refused to pay the ransom, discovered the client data leak in the darknet. Hollard reported that forensic examination results showed no signs of compromise within Hollard's environment and linked this leak to the MIP incident.
Firth considers cryptocurrency one of the factors contributing to these attacks. He noted that despite government discussions about a possible ban on cross-border crypto payments through the Reserve Bank's draft regulations, he believes that cryptocurrency is currently insufficiently regulated, creating a 'huge gap' for attackers. In his opinion, closing this catalyst will stop the payment cycle and eliminate the incentive for such actions.
The draft crypto asset guidelines published by the Ministry of Finance and the Reserve Bank in August would have stipulated a ban on South African companies making cross-border crypto transactions in both directions. In fact, this could solve many of the problems Firth raises. However, a coalition of crypto platforms, which includes GoTyme Bank, is challenging these rules.
Firth stated that before making the payment, they conducted checks of the accounts for 'terrorist threats,' and the accounts passed anti-money laundering checks, even though it concerned a ransom. He added that because they develop software platforms and possess all necessary ISO certifications, this proved useless, and that 'nobody is safe. The [payment] mechanism is not controlled at all.'
