Cayman Islands — Cyber Threat Profile

The Cayman Islands, a British Overseas Territory and major offshore financial centre, has no standalone national CERT: government incident response runs through the CIG Cyber Security Office, with the UK's NCSC and NCA and the US FBI assisting the probe of a thwarted February 2024 attack on government systems. Threat activity concentrates on finance: the 2019 Phineas Fisher hack leaked 2.21 TB of Cayman National Bank data via its Isle of Man subsidiaries; a misconfigured Azure blob exposed a Cayman investment firm's backups, passport data and banking PINs in 2020; and the KillSec ransomware group listed Cayman National Bank on its leak site in March 2025. The Data Protection Act (2021 Revision), enforced by the Ombudsman with 5-day breach notification, and CIMA's Cybersecurity Rule for regulated entities (72-hour incident reporting, revised April 2023) anchor the regulatory framework.

Threat actors targeting Cayman Islands

Most targeted sectors

Recent claimed incidents

Read the full analysis on IntelFusions