Notice
“White hat hacker” informs bank of security breach (2020-03-26)
Issued 2020-03-26View on OMBUDSMAN's website Source document
Summary
This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data protection complaint involving a bank. A white hat hacker accessed a disk drive held by the bank's data processor and demonstrated security weaknesses, exposing some personal data of about 1,800 customers (email addresses, login names, ID codes, account numbers and balances, but no passwords).
- Bank's response: Notified affected customers via the online banking messaging system, sent a follow up notice on fraud risks and mitigation steps, revoked the data processor's remote access, securely erased the drive, and strengthened security (ongoing IT monitoring, replacement of login and account credentials).
- Ombudsman's finding: Concluded there was no evidence personal data had actually been breached (only accessed), so the incident was classified as a security breach rather than a personal data breach under the Data Protection Law, and the case was closed.
The summary is informational, illustrating how the Ombudsman assessed compliance with the seventh data protection principle and breach notification practices under the DPL; it does not itself create new rules but documents an accepted resolution.
Applies to
banks, data controllers, data processors
Topics
Version history
2026-07-30