Notice
Phishing attack at professional association (2021-06-07)
Issued 2021-06-07View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing an informally resolved data protection complaint involving a phishing attack at a professional association. It illustrates how the Ombudsman assessed a security incident and what remedial steps it considered adequate, rather than setting a new binding rule.
- Incident: A staff member's account was compromised via phishing; the password was reset and active sessions terminated.
- Impact assessed: Audit logs showed no other accounts compromised and no SharePoint access gained; risk to data subjects was found to be low.
- Notification: All recipients of the phishing email were notified of the breach.
- Gap identified: Multi-factor authentication (MFA) had not been implemented prior to the incident, but was enabled afterward.
- Ombudsman's recommendations: Provide regular cybersecurity awareness training, run periodic phishing simulation testing, and develop an incident response procedure with clear reporting lines.
As an informal resolution case summary, this document does not create new statutory obligations but signals the security and breach-response practices the Ombudsman expects data controllers to maintain, including MFA, staff training, phishing testing, and documented incident response procedures.
Applies to
professional association, data controllers
Topics
Version history
2026-07-30