Who is Most at Risk?
Businesses, government services and critical infrastructure operators are primary targets, but individuals are equally at risk through phishing, fraud and ransomware. Anyone with internet-connected devices, online banking or digital services is potentially vulnerable.
Before
- Use strong, unique passwords for every account and enable two-factor authentication wherever possible.
- Keep all devices, software and apps updated — updates often contain critical security patches.
- Change the default password on your home router and on any other network or smart-home devices — default credentials are a common way in.
- Back up important data regularly to a secure, offline or cloud location.
- Be cautious of unexpected emails, links and attachments — phishing is the most common entry point for cyber attacks.
- Install reputable antivirus and firewall software on all personal devices.
- Know how to contact your bank quickly to freeze accounts if fraud is suspected.
- Businesses should have a cyber incident response plan in place and train staff in basic cyber hygiene.
- Keep a note of important contacts and account details in a secure offline location in case systems become inaccessible.
During
- If you suspect a cyber attack or data breach, disconnect affected devices from the internet immediately — do not turn them off.
- Change passwords for compromised accounts from a different, unaffected device.
- Contact your bank immediately if you believe financial accounts have been compromised.
- Report the incident to the Royal Gibraltar Police (RGP) on 200 72500.
- If you receive a phishing email or text, report it to the organisation being impersonated — most banks have an address for this. If you have lost money, or given out personal or financial details, report it to the Royal Gibraltar Police.
- If the scam involves an investment, or a firm claiming to be authorised in Gibraltar, report it to the Gibraltar Financial Services Commission on 222 59050.
- Do not pay ransomware demands — contact authorities for advice first.
- Preserve any evidence — screenshots, emails, logs — for investigation purposes.
- If you can still get into the account, sign out of all active sessions and turn on two-factor authentication, or check it is still enabled. This catches session hijacking, not just a stolen password.
- If an unexpected call, email or text presses you to act urgently — from your bank, “IT support” or a delivery company — verify it using a number or website you already know, never the one in the message.
- Businesses: inform affected customers, partners or colleagues if a data breach may affect them.
After
- Work with a qualified IT professional to assess and restore affected systems securely.
- Change all passwords and review account access permissions.
- Businesses and organisations: report any confirmed personal data breach to the Gibraltar Regulatory Authority, as required under data protection law.
- Review and update your cyber security measures to prevent reoccurrence.
- If personal data has been compromised, monitor your credit and bank statements for unusual activity.