Notice

Processor employees fall victim to a smishing attack allowing access to customer information (2023-08-15)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2023-08-15

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing a personal data breach investigation under the Data Protection Act (DPA). A data processor for a global financial services provider suffered a smishing attack that let attackers steal employee login credentials, exposing certain customer data.

  • Incident: Employees were tricked by a fake login page into revealing credentials used to access internal administrative tools, resulting in a breach of customer data.
  • Scope: Over 70,000 customers were affected globally, only one of whom was based in Cayman.
  • Data exposed: Email addresses, partial phone numbers, and processor IDs, leading to spam, unsolicited marketing, and account access attempts.
  • Remedial steps taken: The provider investigated the breach and published a cybersecurity awareness blog post for customers.
  • Ombudsman's finding: The institution failed to notify affected data subjects within the statutory 5 day period and did not disclose what specific data was impacted; the blog post did not satisfy this statutory notification duty.

The Ombudsman reminded the entity of the need to comply fully with the statutory breach notification requirements under section 16 of the DPA. This is a case outcome summary illustrating enforcement of existing breach notification duties rather than a new rule or policy statement.

Key obligations

  • Data controllers and processors must notify affected data subjects of a personal data breach within the statutory 5 day period required by section 16 of the Data Protection Act.
  • Breach notifications to data subjects must specify what categories of personal data were impacted, not merely provide general awareness information.

Applies to

data processors, data controllers, financial services providers

Deadlines

  • 5 days: Statutory deadline under section 16 of the DPA for notifying affected data subjects of a personal data breach.

Topics

Version history

2026-07-30

source file (current)