Trinidad and Tobago — Cyber Threat Profile

Trinidad and Tobago's national CSIRT, TT-CSIRT, was established in November 2015 with assistance from the Organization of American States and the International Telecommunication Union, delivering a core objective of the National Cyber Security Strategy prepared by the Inter-Ministerial Committee for Cyber Security in December 2012; it operates under the Ministry of Homeland Security. In January 2024 National Security Minister Fitzgerald Hinds reported 205 successful cyber attacks to TT-CSIRT between 2019 and 2023, 52 of them in 2023, including a 125 per cent rise in 2020 over 2019 as government rushed out work-from-home platforms during COVID-19. Exposure is concentrated in state-linked operators of essential services: the majority state-owned Telecommunications Services of Trinidad and Tobago was breached by the RansomEXX group in October 2023, which published a dark-web file detailing over 1.2 million customers, and the National Insurance Board was hit by ransomware on 26 December 2023, disrupting an agency that serves more than 630,000 people. Legal capacity lags the threat: the Data Protection Act was only partially proclaimed, on 6 January 2012, and no timetable has been set for bringing the remainder into force. Sector regulation is moving faster — after two rounds of consultation the Telecommunications Authority of Trinidad and Tobago issued the final version 1.0 of its Cybersecurity Framework for Public Telecommunications Networks and Broadcasting Facilities on 30 January 2026, imposing measures classified as required or recommended on public telecommunications networks that run on IP or provide internet connectivity.

Threat actors targeting Trinidad and Tobago

Most targeted sectors

Recent claimed incidents

Read the full analysis on IntelFusions