Cayman Islands — Cyber Threat Profile
The Cayman Islands, a British Overseas Territory and major offshore financial centre, has no standalone national CERT: government incident response runs through the CIG Cyber Security Office, with the UK's NCSC and NCA and the US FBI assisting the probe of a thwarted February 2024 attack on government systems. Threat activity concentrates on finance: the 2019 Phineas Fisher hack leaked 2.21 TB of Cayman National Bank data via its Isle of Man subsidiaries; a misconfigured Azure blob exposed a Cayman investment firm's backups, passport data and banking PINs in 2020; and the KillSec ransomware group listed Cayman National Bank on its leak site in March 2025. The Data Protection Act (2021 Revision), enforced by the Ombudsman with 5-day breach notification, and CIMA's Cybersecurity Rule for regulated entities (72-hour incident reporting, revised April 2023) anchor the regulatory framework.- Data protection authority: Cayman Islands Ombudsman (source: CNIL)
- Secure Internet servers per 1M people (2024): 26,673.1 (source: World Bank)
Threat actors targeting Cayman Islands
Most targeted sectors
Recent claimed incidents
Read the full analysis on IntelFusions