Hackers may have been paid millions
A payment of $4.4 million out of Bermuda’s coffers may have covered ransom to perpetrators of the cyberattack that crippled government IT systems in 2023, an official report tabled today in Parliament revealed.
The long-awaited document from the joint select committee on the September 2023 incident sheds light on events leading up to the attack, including an assessment that warned four months earlier that the island’s cybersecurity risk was “critical”.
A four-member committee left no doubt that the payment was made but recommended an investigation by the Public Accounts Committee to look into who was paid, for what purpose and value, and with whose approval.
Figures in the 2023-24 Budget showed an allocation of $3.09 million for the cyber incident from the Ministry of Finance headquarters and approximately $1.32 million from Information and Digital Technologies, for a combined total of about $4.41 million.
Since the attack, the Government has remained tight-lipped about whether a ransom was ever paid.
The 42-page report said: “The committee does not state, on the basis of the line items alone, that the full amount was paid as ransom.
“However, the scale, timing and description of those line items require full explanation.”
It outlined an alternative scenario whereby rebuilding without access to back-ups or original software could have cost between $25 million and $70 million, or exceeding $100 million if critical data had to be manually reconstructed or systems fully replaced. The rebuild may have taken up to a year, the report suggested.
“The committee did not conduct a detailed financial audit, therefore made no finding of impropriety in relation to the expenditure,” it said.
The report revealed that the attacker, or “threat actor”, had infiltrated the systems ten days before being detected, during which time access to system back-ups was removed, enabling the criminals to demand the ransom.
Furthermore, the committee said verified sources confirmed that personal data was compromised, though little detail was given on what types of data or to whom it belonged.
The report landed with an urgent recommendation that cybersecurity be treated by the Government as “critical national infrastructure”, with adequate funds, resources and full-time specialist employees dedicated to it.
It said: “The committee concludes … that Government had been warned of a critical cybersecurity posture in May 2023.
“Remediation had begun but key controls were incomplete or not fully operational when the attack occurred.
“The committee further concludes that the incident exposed weaknesses not only in technical controls but also in governance, implementation discipline, resource allocation, workforce capacity, data compromise disclosure, public communication and financial accountability.”
A risk assessment provided by the cybersecurity firm Cyberdine identified a high probability of successful attack and limited recovery capability, with causes including resource constraints, gaps in strategic direction and attack vectors such as ransomware, phishing, privacy breach, cloud-based breach and third-party risk.
“Evidence received by the committee indicates that there may have been a gap in institutional awareness regarding the assessment after leadership changes,” the report said.
“The committee does not make a personal finding against any individual on this point.
“Rather, the issue is one of governance continuity; a critical cybersecurity assessment should not depend on informal memory, personality or individual handover.”
The document said that the period from May to September 2023 was one of the most important periods in the committee’s review, adding: “Government was on notice of critical cybersecurity risk before the attack …
“However, governance maturity, funding, specialist staffing, enterprise monitoring, disaster recovery and cross-sector co-ordination did not consistently keep pace with the growth in digital reliance.”
Its top recommendation was: “Bermuda must now treat cybersecurity as a standing national resilience priority, not as a project-based or incident-driven function.”
The final committee was chaired by Lawrence Scott, the Progressive Labour Party backbench MP, and members included Scott Simmons and Jamahl Simmons, also PLP MPs, and Dwayne Robinson, the One Bermuda Alliance MP.
The committee was initially appointed in October 2024, more than a year after the severely disruptive attack.
It was dissolved, along with the rest of the legislature, when a General Election was called for February 2025.
The committee was reinstated in May 2025, when members included opposition senator and computer expert Dion Smith, who resigned his post in the Upper House this year.
The September 2023 attack shut down many government services for months, with significant disruptions affecting everything from digital payment processing to court operations and customs systems.
The committee said that all available evidence suggested that a ransom demand was made and “ransom-related payment activity may have occurred” — a view based on multiple factors including the modus operandi of Alphv/BlackCat ransomware-type incidents, comparative cases and line-item expenditure.
September 30, 2019: Bermuda launches a cybersecurity strategy, developed with the Commonwealth Telecommunications Organisations
May 2023: the Government receives the Cyberdine cybersecurity assessment that indicated that its risk level was “critical”
September 20, 2023: the Government's IT systems face a crippling cyberattack. At 10pm, the systems experienced the “visible” phase of the attack
September 21, 2023: Information and Digital Technologies commences work on the matter, which was reported to the Bermuda Police Service. Essential services operate at limited capacity amid restoration efforts aided by Britain’s National Cybersecurity Centre
September 28, 2023: the Government states it is slowly restoring operations. Some e-mail functionality returns. However, payroll and other services were still not operating normally. Overseas experts are said to be assisting
2023-24 Budget: The Budget book records cyber incident 2023 expenditure totalling approximately $4.41 million
November 7, 2023: it is revealed that an external report was submitted to the Government. The Cabinet Office rules out making it public
November 2023: the Opposition calls for a commission of inquiry to examine the attack, arguing investigations should be independent
May 2024: the Government says a joint select committee made up of MPs and senators from both parties will be set up to examine causes of the attack
June 2024: amendments to the Cybersecurity Act 2024 are passed in the House of Assembly. The Act mandates the creation of a National Cybersecurity Incident Response Team while establishing a Cybersecurity Unit and Cybersecurity Advisory Board
October 2024: an initial five-member cross-party committee is appointed
January 2025: the committee is dissolved, along with the rest of the legislature, when a General Election is called
May 2025: a JSC is reinstated
July 2025: the Ministry of National Security announces it formally engaged the International Telecommunication Union to provide technical assistance and capacity-building support for the implementation of the response team
May 2026: Bermuda’s inaugural National Cybersecurity Risk Assessment begins to gather information from across the public and private sectors and guide planning
July 17: the joint select committee report on the September 2023 cyberattack is presented to Parliament
Referring to the ten-day delay in detecting the attack, the committee said it did not adopt a single universal “industry standard” detection period.
It did say, however, that evidence from “critical infrastructure stakeholders”, which included the likes of Belco and the Bermuda Hospitals Board, helped in identifying the features of a mature monitored environment.
The report said: “A ten-day undetected presence before the visible attack phase is materially significant when compared with the level of monitoring and escalation expected in a mature, critical-infrastructure environment … Their evidence provides a practical benchmark for the minimum level of cyber visibility, monitoring, escalation and resilience that should be expected across government systems.”
Touching on compromised personal data, the report said the final evidence bundle should identify the sources that confirmed the compromise, the categories of data and “the appropriate level of public or confidential disclosure”.
The committee noted that the Bermuda Police Service and the Government issued public warnings concerning phishing, scams and actors impersonating the Government.
“Those warnings are relevant because they indicate that members of the public faced downstream risks associated with exposed, compromised or misused information,” the report said.
“In the committee’s view, such warnings are consistent with a cyber incident involving data compromise or the credible risk of misuse of government-related information.”
The committee recommended that the Government establish a clear process for assessing, confirming and disclosing data compromise.
More than 20 recommendations were made by the committee, most of which fell within the remit of the Government.
They included the establishment of a dedicated National Cybersecurity Task Force, increased funds and staffing, and the creation of a National Cybersecurity Advisory Council including essential services representatives.
• Treat cybersecurity as critical national infrastructure
• Establish a dedicated National Cybersecurity Task Force
• Increase dedicated cybersecurity funding
• Increase government cybersecurity FTEs
• Create a National Cybersecurity Advisory Council
• Develop a National Cyber Incident Response Plan
• Establish a formal ransomware decision framework
• Strengthen back-up, disaster recovery and business continuity
• Require regular, independent cybersecurity assessments
• Require formal remediation plans for critical findings
• Strengthen public communication and scam warnings
• Improve data compromise assessment and disclosure
• Require Cabinet-level cyber-risk oversight
• Conduct annual cross-sector cyber exercises
• Develop a critical infrastructure cybersecurity framework
• Strengthen third-party and vendor risk management
• Strengthen identity, access and privileged account controls
• Establish continuous security monitoring
• Require mandatory cyber training and phishing simulations
• Improve data classification and retention
• Establish an emergency cyber expenditure protocol
• Improve parliamentary oversight and implementation tracking
• Require mandatory post-incident review
• Proposed National Cyber Resilience Operating Model
• To see the report, see Related Media
• UDPATE: this article has been updated with additional information from the report

