Jamaica Emerges as #1 Target for Cyber Attacks in Latin America & Caribbean
Jamaica has surged ahead as the most targeted country in Latin America and the Caribbean for cyber attacks, according to Mervyn Eyre, CEO of Fujitsu Caribbean. In an interview with the Jamaica Observer, Eyre highlighted Jamaica’s vulnerability compared to larger economies like Mexico and Colombia, citing inadequate cybersecurity readiness as a key factor. With ransomware incidents skyrocketing and major breaches like Biomedical Caledonia Medical Lab’s 400,000-file leak, the urgency for compliance with Jamaica’s Data Protection Act (DPA) 2023 has never been greater.
Why Jamaica? Key Vulnerabilities Fueling Cyber Threats
Fujitsu’s analysis reveals the Caribbean’s heightened risk due to:
- Low Cybersecurity Readiness: Organizations face 2,582 weekly attacks vs. the global average of 1,843.
- Email-Based Threats: 55% of malicious files are delivered via email, exploiting system weaknesses.
- Ransomware Surge: High-profile attacks on public/private entities, including a JSE-listed firm and a car dealership forced to halt operations.
“It’s not if you’ll be attacked, but when,” warned Eyre, stressing proactive measures to shift from a “hall of shame to a hall of fame” in cybersecurity resilience.
Recent Cyber Attacks Shake Jamaican Businesses
- Biomedical Caledonia Medical Lab Breach (November 2024):
- 400,000+ files stolen; 70,000 leaked on the dark web by INC RANSOM group.
- Caused by unauthorized vendor access, prompting enhanced security upgrades.
- SAFEPAY Ransomware Strike:
- Targeted a major Jamaica Stock Exchange-listed company, crippling digital operations.
- Phishing Schemes:
- Fraudulent calls (“from North Korea”) and fake branded texts targeting citizens.
The Growing Cost of Cybercrime in Jamaica
- Revenue Losses: Systems downtime forces manual operations, slashing productivity.
- Competitive Disadvantage: Stolen marketing plans and partner data erode trust.
- Consumer Risks: Identity theft and fraud escalate as hackers exploit leaked personal info.
Fujitsu’s Cybersecurity Wake-Up Call for Businesses
Eyre notes progress: 46% of Latin American firms now boost IT budgets by 1–10%, with 76% focused on cybersecurity. Key steps include:
- Proactive Defense: Regular vulnerability assessments and employee training.
- Transparency: Building trust by publicly addressing breaches and response strategies.
- Board-Level Action: Reducing delegation and prioritizing cyber resilience as a sustainability issue.
Jamaica’s Data Protection Act 2023: Compliance is Non-Negotiable
Enforced since December 2023, the DPA mandates:
- 72-Hour Breach Reporting: Failure risks fines or jail time.
- 8 Data Standards: Including encryption, accuracy, and cross-border transfer rules.
- OIC Registration: Required for all data controllers (learn more here).
The Office of the Information Commissioner (OIC) warns: “Due diligence is critical—report breaches immediately and empower citizens to hold organizations accountable.”
How Jamaican Businesses Can Strengthen Defenses
- Adopt Zero-Trust Frameworks: Limit access to sensitive systems.
- Backup Critical Data: Mitigate ransomware impacts.
- Leverage AI Monitoring: Detect threats in real time.
- Partner with Experts: Collaborate with firms like Fujitsu for end-to-end solutions.
Final Takeaway
As cybercriminals target Jamaica’s digital weak spots, businesses must act swiftly to align with the DPA and adopt enterprise-grade security. The stakes are high—protecting data isn’t just compliance; it’s a cornerstone of national economic stability.
Need Help? Contact cybersecurity experts to audit your systems and avoid becoming the next headline.






