Notice

Malware attack on electronic payment system (2021-08-31)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2021-08-31

Current version last checked: 2026-09-14

Summary

This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution following a data breach notification, not a binding rule or policy. It concerns a malware attack on an electronic payment system jointly owned by six retail banks, which was serviced by a third party provider, Prism Services.

  • Incident: Malware designed to deploy cryptocurrency mining software infected the payment system's main service provider; the intrusion went undetected for several months.
  • Reporting: Each affected bank independently reported the breach to the Ombudsman while a cybersecurity firm investigated and guided containment.
  • Findings: Unpatched vulnerabilities existed at the time of intrusion, but the Ombudsman determined no personal data appeared to have been impacted.
  • Recommendations: The Ombudsman recommended patching server and client operating systems and applications, improving network and endpoint threat detection and prevention, and conducting ongoing vulnerability testing and assessments.

As a closed case summary, this document is informational and illustrates the Ombudsman's expectations on incident response and security hygiene rather than imposing new formal legal requirements.

Applies to

retail banks, electronic payment system operators, third party service providers

Topics

Version history

2026-07-30

source file (current)