Notice

“White hat hacker” informs bank of security breach (2020-03-26)

Cayman Islands Office of the Ombudsman (OMBUDSMAN) · Cayman Islands

Issued 2020-03-26

Current version last checked: 2026-07-30

Summary

This is a published case summary from the Cayman Islands Ombudsman describing an informal resolution of a data protection complaint involving a bank. A white hat hacker accessed a disk drive held by the bank's data processor and demonstrated security weaknesses, exposing some personal data of about 1,800 customers (email addresses, login names, ID codes, account numbers and balances, but no passwords).

  • Bank's response: Notified affected customers via the online banking messaging system, sent a follow up notice on fraud risks and mitigation steps, revoked the data processor's remote access, securely erased the drive, and strengthened security (ongoing IT monitoring, replacement of login and account credentials).
  • Ombudsman's finding: Concluded there was no evidence personal data had actually been breached (only accessed), so the incident was classified as a security breach rather than a personal data breach under the Data Protection Law, and the case was closed.

The summary is informational, illustrating how the Ombudsman assessed compliance with the seventh data protection principle and breach notification practices under the DPL; it does not itself create new rules but documents an accepted resolution.

Applies to

banks, data controllers, data processors

Topics

Version history

2026-07-30

source file (current)