Notice
Business Email Compromise Schemes (2017-10-17)
Issued 2017-10-17View on CIMA's website Source document
Summary
This is a general public notice issued by the Cayman Islands Monetary Authority (CIMA) on 17 October 2017 alerting Financial Service Providers to a growing trend of Business Email Compromise (BEC) schemes, a form of cybercrime. The notice explains that these schemes typically involve phishing emails that impersonate business executives to trick recipients into remitting funds to fraudulent accounts, and warns that similar tactics may be used for fraudulent instructions such as changes of contact details or redemption requests.
The notice calls on Financial Service Providers to remain vigilant and carefully scrutinize emails, particularly those requesting fund transfers or changes to account/transactional instructions.
- Reporting expectations: If a provider suspects it has been the victim of a BEC or other cyberattack, it should file an incident report immediately with the Financial Crime Unit of the Royal Cayman Islands Police Service and the Financial Reporting Authority.
- CIMA-regulated entities: If the provider is regulated by CIMA, it should also notify the Authority.
- Suspicious emails: These can also be forwarded to the Cayman Islands Cybersecurity Incident Response Team (CIRT).
This is an awareness/advisory notice rather than a binding rule or regulatory amendment, but it does articulate specific reporting expectations for regulated entities that experience or suspect a BEC or cyberattack.
Key obligations
- If a Financial Service Provider suspects it has been the victim of a BEC attack or other cyberattack, it should immediately file an incident report with the Financial Crime Unit of the Royal Cayman Islands Police Service and the Financial Reporting Authority
- If the Financial Service Provider is regulated by CIMA, it should also notify the Authority of the suspected BEC or cyberattack incident
- Financial Service Providers should carefully scrutinize emails, including those instructing changes of contact details or transactional instructions such as redemption requests, to guard against BEC schemes
- Suspicious emails may be forwarded as an attachment to the Cayman Islands Cybersecurity Incident Response Team (CIRT) at Cirt-ky@icta.ky
Applies to
Financial Service Providers
Deadlines
- immediately: An incident report should be filed immediately with the Financial Crime Unit of the Royal Cayman Islands Police Service and the Financial Reporting Authority upon suspicion of a BEC attack or other cyberattack