Notice

Phishing Attack at Financial Services Company (2020-02-11)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2020-02-11

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data breach complaint under the Data Protection Law (DPL). It illustrates how the Ombudsman evaluates a company's breach notification and response, rather than creating any new rule or obligation.

  • Incident: A fund services company in Canada, a sister company of a Cayman Islands-based entity, suffered a phishing attack causing a data breach affecting employee data and over 2,000 external data subjects, many based in the Cayman Islands.
  • Notification: The company notified the Ombudsman and affected data subjects in accordance with DPL requirements.
  • Investigation findings: The Ombudsman found no evidence the threat actor downloaded email contents or that systems other than email were affected.
  • Outcome: The Ombudsman was satisfied with the technical and organizational measures the company took to contain and mitigate the breach, and resolved the matter informally with no further action.

As a case summary of a closed, informally resolved matter, this document does not itself impose new obligations, but it reinforces the existing DPL requirement to notify the Ombudsman and affected data subjects promptly following a data breach.

Applies to

data controllers, financial services companies

Topics

Version history

2026-07-30

source file (current)