Hollard customer data leaked on the dark web
Hollard Insurance said that some of its funeral policyholders’ data may have been leaked on the dark web as part of a cybersecurity incident involving MIP Holdings in June 2026.
Notorious cyber extortion gang The Gentlemen claimed it breached Hollard’s systems last week and obtained sensitive data, which it threatened to leak unless the company negotiated with the group.
Cybersecurity firm Check Point Software reported The Gentlemen as the second-most active ransomware group globally in August 2025.
It is believed to have split from the Qilin ransomware group, which was the most active in Check Point’s analysis.
Following The Gentlemen’s claim that it exfiltrated data from Hollard, the insurer told MyBroadband it was unaware of an attack but was actively and urgently investigating the claims.
“We are aware of claims made by a threat actor in a post referencing the organisation on the dark web,” Hollard said.
“We identified the threat through our proactive threat intelligence capabilities, immediately activated our cyber incident response processes and engaged specialist forensic investigators.”
The Gentlemen published the data on its dark web leak site earlier this week, after the deadline for its ransom demand lapsed.
In a subsequent update, Hollard said the information appeared to be linked to a previous cybersecurity incident involving MIP.
MIP is a South African IT and policy administration provider to several organisations within the insurance sector.
“We understand the concern this situation may cause and remain committed to protecting the information entrusted to us by our customers, brokers and partners,” Hollard said.
“The matter appears isolated to individual funeral policyholders. We have notified customers who were affected by the June 2026 incident and are engaging with the relevant regulatory authorities.”
A subset of the data seen by MyBroadband contained policyholders’ full names, surnames, ID numbers, dates of birth, email addresses, phone numbers, contract numbers, and contract types.
Over 100,000 Hollard records stolen in attack

In certain cases, the personal information of policyholders’ partners, children, and beneficiaries was included alongside their own information.
We counted over 100,000 records for customers indicated as having Hollard funeral policies, although this may not have been all the compromised data.
Hollard said that the forensic and assurance activities conducted to date showed no evidence of compromise within the insurer’s own environment.
“As a precaution, customers are encouraged to remain vigilant against unsolicited communications, phishing attempts and requests for personal or financial information,” it said.
“Protecting the information entrusted to us by our customers, brokers and partners remains a priority. We continue to monitor the situation closely.”
The insurer said that should any material information emerge which changed its current assessment, it would communicate this promptly through its established incident response channels.