South African insurer refused to pay ransom after computer hack
Liberty Holdings couldn’t comment on the identity of outside parties that gained access to the IT infrastructure.
(Bloomberg) – Liberty Holdings Ltd., the South African insurer midway through an overhaul to improve profit, said it refused a ransom demand after hackers breached its information-technology infrastructure and accessed some emails. The stock fell the most since April 4.
No concessions
“We did engage with the external parties involved to determine their intentions, but we made no concession in the face of this attempted extortion,” Liberty Chief Executive Officer David Munro said Sunday in Johannesburg. “Liberty is at an advanced stage of investigating the extent of the data breach, which at this stage, seems to be largely emails and possibly attachments.”
Related: Ransomware: What to do when it happens to you
The threatened data leak comes as Munro pushes ahead with a turnaround of the largest provider of long-term insurance products to affluent South Africans, which has struggled to grow sales into a weak local economy. Since being appointed to the post in May last year, Munro has sought to improve customer service by revamping its call center, while simplifying its offerings that had become too complex for its 3,000 agents to market and finding ways of improving returns at its asset-management unit.
Liberty couldn’t comment on the identity of outside parties that gained access to the IT infrastructure, or divulge the payment demanded because the matter is still subject to investigation by various authorities, Munro said. Shares in the insurer dropped 4%, the biggest decliner in the six-member FTSE/JSE Africa Life Assurance Index.
No losses
The 60-year-old insurer has more than 2.5 million life-insurance policies and administers more than 10,000 retirement plans and 500,000 individual and institutional investment customers, according to its website.
“There is no evidence at this point in time that there is any financial loss to any of our customers,” he said. “We have gone to extreme lengths to enforce our IT infrastructure to ensure our customers’ information is protected.”
Related 5 cybersecurity problems facing mid-size insurance companies
Liberty sent text messages to clients informing them of the attack. “We totally understand the concerns they might have about the impact of this act of criminality,” he said.
South Africa’s Information Regulator is concerned by the “disturbingly high number of material data breaches in the past few months,” including the leaking of personal information in the so-called Master Deeds leak, as well as leaks involving Facebook Inc. and ViewFine, a local traffic payments website, the Pretoria-based authority said in an email. The regulator, which still needs to start fully operating, has requested an “urgent meeting” with Liberty’s CEO, it said.
Stolen emails
Information that was stolen probably was restricted to Liberty emails and customers of Standard Bank Group Ltd., which controls Liberty, wouldn’t be affected unless they were also the insurer’s customers, according to Munro. The breach is limited to Liberty, he said.
“There is no inter-connection when it comes to Liberty and Standard Bank systems,” he said. “This was an infiltration of our network and a specific email system or repository of email data. It looks like the bulk of the data they stole from us is email, relatively recent rather than deeply dated.”
Related: Kidnap & ransom insurance: Unlocking coverage for ransomware attacks