Notice

Phishing attack at professional association (2021-06-07)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2021-06-07

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing an informally resolved data protection complaint involving a phishing attack at a professional association. It illustrates how the Ombudsman assessed a security incident and what remedial steps it considered adequate, rather than setting a new binding rule.

  • Incident: A staff member's account was compromised via phishing; the password was reset and active sessions terminated.
  • Impact assessed: Audit logs showed no other accounts compromised and no SharePoint access gained; risk to data subjects was found to be low.
  • Notification: All recipients of the phishing email were notified of the breach.
  • Gap identified: Multi-factor authentication (MFA) had not been implemented prior to the incident, but was enabled afterward.
  • Ombudsman's recommendations: Provide regular cybersecurity awareness training, run periodic phishing simulation testing, and develop an incident response procedure with clear reporting lines.

As an informal resolution case summary, this document does not create new statutory obligations but signals the security and breach-response practices the Ombudsman expects data controllers to maintain, including MFA, staff training, phishing testing, and documented incident response procedures.

Applies to

professional association, data controllers

Topics

Version history

2026-07-30

source file (current)