Notice

Ransomware attack at overseas financial services provider (2020-09-14)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2020-09-14

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution outcome, not a rule or directive. It concerns a ransomware attack at an overseas financial services company with a Cayman Islands presence, and explains why the Ombudsman decided it had no jurisdiction over the resulting data breach.

  • What happened: A ransomware attack encrypted, blocked and extracted data across the company's core systems, halting business operations for two days and preventing clients from making withdrawals or deposits.
  • Notification: The breach notifier initially reported the incident to the Ombudsman believing it was a data controller under the Cayman Islands data protection framework.
  • Outcome: On review of the notifier's corporate structure and processing activities, the Ombudsman found it did not meet the definition of a data controller, and therefore concluded it had no jurisdiction because the breach related only to the overseas company.

Because the matter was resolved on jurisdictional grounds, the summary does not set out any new rule, obligation or compliance requirement for Cayman entities; it serves as an illustrative case outcome on how the data controller definition is applied to overseas entities with a local presence.

Applies to

overseas financial services company with a presence in Cayman, data controllers

Topics

Version history

2026-07-30

source file (current)