Log In

Reset Password

BPS: no active lines of inquiry into cyberattack

No active lines: Antoine Daniels, the Assistant Commissioner of Police, says there is insufficient new information available to progress the cyberattack investigation further (File photograph by Akil Simmons)

No active lines of inquiry are being pursued by the Bermuda Police Service into the cyberattack that brought down government IT systems in September 2023, the Assistant Commissioner of Police has confirmed.

Antoine Daniels responded to questions from The Royal Gazette in the wake of the tabling of the joint select committee report into the attack, stating that the investigation has not been formally closed.

A recommendation in the report is that the Public Accounts Commission continue investigations into the financial aspects of the incident including who authorised a $4.4 million payment from the Government and whether it was paid as ransom to the perpetrators of the attack.

However, Douglas De Couto, the chairman of the PAC, said this week that the committee was not a criminal investigation body, and while it would endeavour to trace the payment, finding the perpetrators would ultimately fall to the police or similar authority.

Mr Daniels told the Gazette: “The BPS conducted an investigation into the September 2023 cyber incident affecting government IT systems. Investigators pursued all reasonable lines of inquiry based on the information and evidence that were made available to them at the time.

“While the matter has not been formally closed, there are no active investigative lines of inquiry being pursued, pending the receipt of new information or evidence that could advance the investigation.

“Investigators reviewed the information provided, explored potential evidential opportunities, and sought assistance from overseas law enforcement and technical partners with expertise in cybercrime investigations. At present, there is insufficient new information available to progress the matter further.”

Mr Daniels said that given the nature of cybercrime investigations and the sensitivities surrounding cybersecurity incidents, it would be inappropriate to comment on specific investigative findings or technical details.

“What can be said is that investigators assessed the available information, sought specialist assistance where appropriate and examined potential avenues for identifying those responsible,” he said.

“Unfortunately, the evidence available did not allow investigators to develop prosecutorial opportunities.”

Mr Daniels confirmed that investigators of cybercrime often involve multiple agencies and jurisdictions.

He said that, depending on circumstances, specialist law enforcement agencies, international policing partners, cybersecurity authorities, intelligence-led organisations and other technical agencies may be able to provide assistance where additional evidence or intelligence becomes available.

He added: “The BPS engaged with overseas law enforcement and technical experts during the course of the investigation. I am not in a position to comment on the activities of any other agencies or organisations beyond the involvement that occurred in support of the BPS investigation.”

Asked whether he thought the perpetrators of the crime could ever be caught, Mr Daniels said: “Cybercrime investigations are inherently complex and often involve offenders operating across multiple jurisdictions while utilising sophisticated techniques designed to conceal their identities.

“While it is never possible to rule out future developments, the likelihood of identifying those responsible depends on the emergence of new evidence, intelligence or opportunities that were not previously available.

“The most important factors in any cybercrime investigation are the timely reporting of incidents, the preservation and sharing of digital evidence, close co-operation among affected organisations, and effective collaboration between local and international partners.

“As technology and investigative capabilities continue to evolve, new opportunities may emerge that could assist in identifying those responsible for offences of this nature.”

Mr Daniels emphasised that the primary role of the BPS in such cases is the investigation of criminal offences and the identification of offenders.

Responsibility for cybersecurity governance, system protection and preventive measures rests with the relevant organisations and agencies managing those systems.

He said: “Where appropriate, the BPS work with local and international partners on matters relating to cybercrime awareness, intelligence sharing and criminal investigations.

“The BPS took this matter seriously and dedicated investigative resources to examining all information that was available.

“Investigators also sought support from overseas partners with specialist cybercrime expertise. Despite those efforts, the investigation did not produce sufficient evidence to pursue those responsible.

“Should new information become available, the BPS would assess it and determine whether further investigative opportunities exist.

“Cybercrime investigations are often complex and can take years to yield results, particularly where offenders operate outside local jurisdictions.”

Royal Gazette has implemented platform upgrades, requiring users to utilize their Royal Gazette Account Login to comment on Disqus for enhanced security. To create an account, click here.

You must be Registered or to post comment or to vote.

Published July 24, 2026 at 6:58 am (Updated July 24, 2026 at 5:47 am)

BPS: no active lines of inquiry into cyberattack

Users agree to adhere to our Online User Conduct for commenting and user who violate the Terms of Service will be banned.