Notice
Malware attack on electronic payment system (2021-08-31)
Issued 2021-08-31View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution following a data breach notification, not a binding rule or policy. It concerns a malware attack on an electronic payment system jointly owned by six retail banks, which was serviced by a third party provider, Prism Services.
- Incident: Malware designed to deploy cryptocurrency mining software infected the payment system's main service provider; the intrusion went undetected for several months.
- Reporting: Each affected bank independently reported the breach to the Ombudsman while a cybersecurity firm investigated and guided containment.
- Findings: Unpatched vulnerabilities existed at the time of intrusion, but the Ombudsman determined no personal data appeared to have been impacted.
- Recommendations: The Ombudsman recommended patching server and client operating systems and applications, improving network and endpoint threat detection and prevention, and conducting ongoing vulnerability testing and assessments.
As a closed case summary, this document is informational and illustrates the Ombudsman's expectations on incident response and security hygiene rather than imposing new formal legal requirements.
Applies to
retail banks, electronic payment system operators, third party service providers
Topics
Version history
2026-07-30