Software developers keep a running list of their work in a tool called Jira, and they paste things into it: a screenshot of a bug, the credentials for a service, a data file to test against. MIP Holdings, which builds the policy systems behind roughly 45 South African insurers, was most of the way through retiring the instance it had used for years. Intruders got in before it finished, and left with about 400 000 records.
They did not break anything to do it. An employee had reused a password on a service that was itself breached, and the credentials still worked on a personal laptop that could reach the support platform. MIP believes they were inside from about 25 May, moving data out slowly enough not to trip an alarm, until somebody noticed on a Sunday in mid-June. Chief executive Richard Firth told TechCentral the company was taken aback that all of this data was sitting inside that platform at all.
Why a task tracker held identity numbers
MIP's own breach notice explains that without quite meaning to. Many tasks in Jira do have personal information attached, it says: screenshots in which some detail is visible, instructions recording the credentials for a service, data files attached for testing or debugging. That is how a development tool ends up holding email addresses, cellphone numbers and policy numbers with identity numbers attached. One file alone held roughly 200 000 cellphone numbers, gathered for an SMS campaign. LegalWise, one of the affected clients, has told its members the categories still being assessed include banking details, which MIP's notice does not itemise.
The payment that did not hold
MIP paid. Firth confirmed that to TechCentral but would not say how much, only that the sum was substantial. It ran anti-money-laundering checks on the accounts first, on specialist advice, and they came back clear. In exchange the group calling itself The Gentlemen undertook to delete everything it took and not to publish it. MIP's public notice on 23 June recorded that undertaking and said nothing at all about a payment.
It held until 7 September, when the group listed an insurance client on its leak site and MIP found markers in the material tying it back to June. Hollard, the client named, says its own forensic work found no evidence of compromise inside its environment and that the claim appears attributable to MIP's incident. So the data MIP believed it had bought back went up anyway.
A regulator chain has been running underneath this since the first week. MIP notified the Information Regulator on 16 June and met the Prudential Authority and the Reserve Bank six days later, where the question raised was whether a breach reaching much of the life insurance sector's administration layer was a systemic risk. The authority concluded it did not. Firth said MIP chose to talk because companies that suffer breaches tend to hide them and silence helps no one. The Information Regulator's investigation is still open.