
A data breach at The Jersey Financial Services Commission (JFSC) has exposed non-public names and addresses, confirmed by the watchdog on March 7.
The breach, originating from a vulnerability detected in the registry system on January 23, 2024, prompted immediate action by the JFSC to address the issue. An initial forensic review conducted in collaboration with an independent cybersecurity partner identified a misconfiguration in the third-party-supplied registry system as the underlying cause of the vulnerability.
Jersey Finance, the promotional body for Jersey’s financial center, opted not to comment. Requests for comments were extended to the Cyber Security Centre for Jersey and the Jersey Office of the Information Commissioner.
The JFSC had previously cautioned financial services firms in the jurisdiction to bolster their cybersecurity checks in light of increased malicious incidents following Russia’s invasion of Ukraine.
Despite the breach, the JFSC assured that its corporate network remained uncompromised, and no individuals were linked to specific registered entities or roles. However, the breach did expose the names and addresses of 66,806 individuals, where this information was not publicly available on the register. The regulator has since communicated with over 2,400 affected individuals.
In response, the JFSC emphasized its commitment to implementing robust controls to safeguard information, acknowledging the impossibility of eliminating all risks while striving to prevent data compromise.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543