What Business Owners Need to Know This Week

Week 39 (13–19 September 2026) is the week South Africa learned what its supplier breaches contained, and who else was in them. The Hollard claim resolved, and the answer was a supplier: MIP Holdings, which supplies policy administration software to insurers, medical schemes and lenders, disclosed that intruders spent about three weeks inside a Jira support platform it was decommissioning and took roughly 400,000 records belonging to the customers of about 45 insurers. Separately, the provider behind the EasyEquities notice has a name: RelyComply, the compliance platform running FICA identity verification and screening for banks, brokers and lenders.

The Bottom Line: MIP’s experience settles one board question for good. It paid The Gentlemen a substantial ransom, ran anti-money-laundering checks on the wallet first, and received an undertaking to destroy the data — and the data was published anyway. In both cases the institutions whose names appear on the policies and accounts did nothing wrong in their own estates and still owe the notification, because POPIA puts the duty on the responsible party. The question to put to your executive this week: which operators hold identity numbers on your behalf, in what environment, and does the contract say who tells the customers?

The Week in Numbers

  • ~400,000 records — taken from MIP Holdings’ Jira support platform, belonging to the customers of about 45 insurers; HIGH threat level for the 22nd consecutive week.
  • ~3 weeks from late May — how long intruders were inside a platform MIP was decommissioning.
  • 100,000+ Hollard funeral policyholders — in the records published this week, including identity numbers, dates of birth and the names of children and beneficiaries.
  • 1 reused password — the entry route into the MIP platform, on one employee’s account.
  • 200 GB — claimed by DireWolf from RelyComply’s production databases and Amazon S3 storage.
  • 6 named institutions — EasyEquities, SA Home Loans, Peregrine Capital, Satrix and Alexforbes confirm records sat in the breached environment; Standard Bank is investigating.
  • SC20263150 — RelyComply’s Information Regulator incident reference.
  • 7 new KEV additions — half last week’s count, four already overdue; two are Cisco zero-days the vendor found while working support cases.
  • CVSS 10.0 / 9.8 — Cisco Identity Services Engine authentication bypass (the product that decides who joins your network) and Secure Email Gateway SQL injection reaching root from a crafted email.
  • 15 weeks — since the Information Regulator’s last register entry.

Major Incidents: Who Was Hit and How

MIP Holdings — 45 Insurers’ Customers in Support Tickets

MIP told TechCentral on 15 September that intruders spent about three weeks from late May inside a Jira support platform it was decommissioning, reached through one employee’s reused password, and took roughly 400,000 records belonging to the customers of about 45 insurers. The records were there because insurers’ staff had pasted screenshots and reports with identity numbers in the clear into support tickets. MIP paid The Gentlemen a substantial ransom for an undertaking to destroy the data, having run anti-money-laundering checks on the wallet first. The undertaking did not hold. The group listed Hollard on 7 September, demanded a ransom Hollard refused, and published records this week counted at more than 100,000 Hollard funeral policyholders — identity numbers, dates of birth, and the names of children and beneficiaries. Hollard’s statement of 16 September says the data came from the June MIP incident and that forensic work found no compromise of its own environment. The publication and its supplier origin are CONFIRMED; the group’s claim to have breached Hollard itself stays CLAIMED.

RelyComply — The FICA Verification Layer for Six Institutions

RelyComply published a notice on 16 September: an unauthorised party exploited a zero-day in a third-party application, reached systems holding customer data, and the incident is reported to the Information Regulator under reference SC20263150. DireWolf listed it on 9 September claiming 200 GB from production databases and Amazon S3 storage — and the aggregator tagged the record GB, which is why it never appeared in W38’s South African count. EasyEquities, SA Home Loans, Peregrine Capital, Satrix and Alexforbes have each confirmed customer records sat in the breached environment; Standard Bank is investigating; Bidvest Bank has still not named its provider, so its notice of the same evening is not attributed to this event. Treat every verification record the provider held for you as exposed for phishing purposes: full name, identity number, date of birth, contact details and, for some clients, bank account details.

Two Cisco Zero-Days — Check Before You Trust the Appliance

Cisco found both while resolving support cases and confirms active exploitation. CVE-2026-76461 (Secure Email Gateway, CVSS 9.8) is a SQL injection reaching root from a crafted email; the check is grep -i for COPY.*TO PROGRAM across mail_logs on every cluster member, because a compromised member exposes the SSH keys the cluster shares — a virtual appliance with a hit is rebuilt on 16.5.0-780, not cleaned in place. CVE-2026-76460 (Identity Services Engine, CVSS 10.0) is an authentication bypass in the product that decides who joins a corporate network; the check is show logging application ise-kong/access.log piped to dummyuser on every node, and a hit means re-image from a configuration backup. Restrict management-plane reachability with infrastructure ACLs while you patch.

Correction to W38 — The Aggregator Hid a Victim

W38 put the derived South African listing count for its window at two — VSB Attorneys and Hollard. It was three. DireWolf listed RelyComply AML Platform on 9 September, inside that window, and the aggregator recorded the country as GB, so the country-scoped feed this report reads never returned it. RelyComply lists Johannesburg and Cape Town offices alongside London and reported the incident to the South African Information Regulator, so it is a South African victim for this report’s purposes. Worth noting the direction: every previous aggregator country-field error in this series invented a South African victim; this one hid one.

POPIA and Regulatory

These two cases turn on one section of POPIA. The obligation to notify the Regulator and the data subjects under section 22 rests with the responsible party — the insurer or the bank — rather than with the operator processing on its behalf. MIP’s response, building a messaging platform so each insurer could notify its own customers, is the practical expression of that rule. There are three clocks, and one incident triggers parallel reports to different authorities under different statutes with different thresholds: section 22 of POPIA; section 54 of the Cybercrimes Act, which requires electronic communications service providers and financial institutions to report cyber offences to the SAPS within 72 hours, with a fine of up to R50,000 for non-compliance; and the FSCA and Prudential Authority 24-hour notification under Joint Communication 5 of 2026, running from the institution’s own classification of materiality. The Regulator’s register still carries nothing later than the Gauteng Department of Health notice of 10 June, and the SABS notice described at the 31 August briefing has not appeared in three weeks — the count moves to fifteen weeks. Two open cases will test it in public: MIP reported to both the Regulator and the Prudential Authority and says its case remains open, and the Prudential Authority has already asked whether one unregulated software supplier serving a large share of a sector is a systemic risk.

Full Intelligence Report

The complete Week 39 technical report covers the MIP Holdings and RelyComply supplier breaches in full with affected-institution analysis, the Hollard publication and its supplier origin, the ransom-payment case study, all seven catalogue additions with both Cisco compromise-check commands, the responsible-party and operator analysis across three statutory notification clocks, the corrected W38 listing count, structured hunt missions with IOC tables and the full source list.

What Your Business Should Do Right Now

  • Patch both Cisco zero-days and run the vendor compromise checks before trusting the appliance again: On Secure Email Gateway, grep -i for COPY.*TO PROGRAM across mail_logs on every cluster member — a compromised member exposes the SSH keys the cluster shares, and a virtual appliance with a hit is rebuilt on 16.5.0-780 rather than cleaned in place. On ISE, check ise-kong/access.log for dummyuser on every node; a hit means re-image from a configuration backup.
  • Restrict management-plane reachability with infrastructure ACLs while you patch: Both Cisco flaws are unauthenticated, and ISE is the product that decides who joins your network. Reducing who can reach the management interface buys time the patch window needs.
  • If you use RelyComply or any FICA verification provider, rotate API tokens and SSO federation this week: RelyComply’s notice asks customers to rotate tokens and refresh identity-provider configurations; SA Home Loans and Alexforbes both did so before reinstating the service. Read the provider’s logs for your own integration rather than accepting a summary.
  • Notify your customers on an exposure basis, not a forensic one: Treat every verification record the provider held as exposed for phishing — full name, identity number, date of birth, contact details and in some cases bank account details. EasyEquities and SA Home Loans sent notices before the forensic result was in. Register affected customers’ interest with the Southern African Fraud Prevention Service.
  • Find the identity numbers sitting in your suppliers’ support tickets: MIP’s intruders took 400,000 records from Jira tickets where insurers’ staff had pasted screenshots and reports with ID numbers in the clear. Ask each operator which ticketing and collaboration platforms hold your data, whether tickets are scrubbed, and whether the platform enforces SSO with MFA and managed devices.
  • Audit what you are decommissioning: The MIP platform was on its way out when it was breached. Systems mid-retirement lose their monitoring, their patching and their ownership before they lose their data. Inventory anything scheduled for decommissioning and confirm it still has all three.
  • Settle the ransom question at board level, using this case: MIP paid, vetted the wallet first, obtained an undertaking to destroy the data, and the data was published anyway. Payment bought nothing that survived contact with the actor.
  • Map your three notification clocks now, in one document: POPIA section 22 (responsible party, as soon as reasonably possible), Cybercrimes Act section 54 (72 hours to SAPS, R50,000 fine), and the FSCA and Prudential Authority 24-hour material incident notification. One incident triggers all three on different thresholds — work that out before an incident, not during one.