Notice
Phishing Attack at Financial Services Company (2020-02-11)
Issued 2020-02-11View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data breach complaint under the Data Protection Law (DPL). It illustrates how the Ombudsman evaluates a company's breach notification and response, rather than creating any new rule or obligation.
- Incident: A fund services company in Canada, a sister company of a Cayman Islands-based entity, suffered a phishing attack causing a data breach affecting employee data and over 2,000 external data subjects, many based in the Cayman Islands.
- Notification: The company notified the Ombudsman and affected data subjects in accordance with DPL requirements.
- Investigation findings: The Ombudsman found no evidence the threat actor downloaded email contents or that systems other than email were affected.
- Outcome: The Ombudsman was satisfied with the technical and organizational measures the company took to contain and mitigate the breach, and resolved the matter informally with no further action.
As a case summary of a closed, informally resolved matter, this document does not itself impose new obligations, but it reinforces the existing DPL requirement to notify the Ombudsman and affected data subjects promptly following a data breach.
Applies to
data controllers, financial services companies
Topics
Version history
2026-07-30