Notice

Investor personal data leaked on the dark web (2023-09-25)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2023-09-25

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing the outcome of an investigation into a personal data breach at a Cayman Islands investment fund. It illustrates how the Ombudsman assesses a fund's response to a cybersecurity incident and compliance with data breach notification requirements, rather than creating new rules.

  • Incident: A fund suffered unauthorized access via a firewall device, an attempted ransomware attack, and exfiltration of directors' personal data that was later published on the dark web.
  • Fund's response: The fund notified affected directors, explained the breach and containment steps, and engaged a cyber forensic expert to investigate.
  • Notification timing issue: The Ombudsman noted the fund had notified it outside the statutory notification period; the fund attributed this to the high data volume, number of affected directors, and the incident originating in Hong Kong, making it initially unclear that Cayman entities and directors were affected.
  • Outcome: The Ombudsman assessed the fund's response as appropriate and closed the case without further action.

The summary serves as guidance on regulatory expectations for breach response and notification timeliness, though it does not itself impose new obligations beyond existing data protection notification requirements.

Key obligations

  • Data controllers experiencing a personal data breach must notify the Ombudsman within the statutory notification period.
  • Data controllers must notify affected individuals of a data breach and communicate the steps taken to contain its impact.

Applies to

Cayman Islands investment funds, data controllers

Topics

Version history

2026-07-30

source file (current)