5.4 Million Attacks in 90 Days: Jamaica's AI-Powered Cybersecurity Arms Race

By Howard Williams | July 20, 2026 | Cybersecurity & Crime

Dark data centre server racks with glowing fibre optic cables, no people visible

A server room at night. Jamaican government agencies, banks, and businesses absorbed millions of attempted intrusions in the first quarter of 2026 alone. Photo via Unsplash.

TL;DR:

Jamaica's National Health Fund found out in the first week of June that a group calling itself PEAR was claiming to have walked off with 2.9 terabytes of its data: financial records, HR files, vendor contracts, patient personal and health information, email correspondence, database exports. The NHF's public line held steady. Services were unaffected, the claims were unverified, and the Major Organised Crime and Anti-Corruption Agency was on it. That is the version of events that made the news. The version that matters more is the one nobody in Jamaica can see from outside a security operations centre: how much of what hit the NHF, and the tens of millions of other attempts against Jamaican targets this year, was assembled, aimed, or accelerated by artificial intelligence.

The honest answer, according to the people whose job is watching this traffic, is a lot of it. Jamaica is not fighting more crime this year so much as it is fighting faster crime, and the country's legal and institutional response, while real and underway, has not caught up to the speed of the thing it is chasing.

The Numbers Behind the Panic

Start with what Fortinet's FortiGuard Labs actually measured. The firm's Global Threat Landscape Report put attempted cyberattacks against Jamaica at 46.7 million for all of 2025, with active scanning attempts, the reconnaissance sweeps that precede a real intrusion, at 7 million for the year. Then 2026 opened harder: 5.4 million attack attempts and 2 million scanning attempts in the first quarter alone, a pace that if it held for the full year would roughly match 2025's total in a third of the time, as reported by the Jamaica Gleaner on July 16.

A separate figure floated around the same period, and it is worth keeping the two straight rather than merging them. When the government made its case for new cybersecurity legislation in June, officials cited a national count of 49 million cyberattack attempts in 2025, up from 12 million in 2022, an increase of more than 300% in four years, according to the Jamaica Observer. That is a different tally from a different measurement point, likely counting differently than Fortinet's own commercial telemetry does. The two numbers do not need to reconcile to make the same point twice: whichever count you trust, the volume hitting Jamaica has grown several times over in a few years, and the growth curve has not started to bend.

5.4 million Cyberattack attempts Fortinet recorded against Jamaican targets in just the first three months of 2026, on top of 46.7 million logged across all of 2025.

Why AI Changes the Math

Emmanuel Oscar, Fortinet's senior engineering manager for the English Caribbean, told the Jamaica Observer that the conversation around cybersecurity in Jamaica has changed dramatically over the past few years, moving from a reactive posture, where organisations tightened up only after an incident, toward treating security as a standing business priority. Carlo Caloca, the firm's regional sales manager, was more specific about why the shift felt urgent now: without proper governance, awareness, and security controls, he said, AI can unintentionally introduce new vulnerabilities of its own. That cuts both ways. Attackers are using AI and automation to scan for weak systems, run reconnaissance, and scale campaigns at a speed manual methods never allowed. Defenders adopting AI tools without matching discipline can open fresh gaps in the same motion.

The dollar figure that makes this concrete is not even a Jamaican number. Fortinet's own benchmark, cited alongside the local statistics, puts the global average cost of a data breach at roughly US$5 million. Jamaica does not need to be the most targeted country in the world for that number to matter. It only needs one breach at one bank, one hospital fund, or one government database to land anywhere near that figure for the abstract statistic to become a very real line item.

Close-up of glowing green code streaming down a dark screen, no people visible

Automated scripts and scanning tools do the reconnaissance work that used to take a human attacker hours, compressing it into minutes. Photo via Unsplash.

What Actually Happened at the National Health Fund

The NHF incident is the clearest local test case Jamaica has had this year. PEAR's claim, first reported around June 10, alleged access to financial records, HR data, provider and vendor information, patient personally identifiable and protected health information, correspondence, and database exports, a combination that, if genuine at anywhere near the claimed scale, would be one of the most serious breaches in Jamaica's public sector to date. The NHF's response followed the standard playbook: engage MOCA, loop in the Office of the Information Commissioner, bring in outside cybersecurity experts, keep services running, and decline to confirm the extortionists' figures while the investigation continued.

What the incident actually changed was the political temperature around the pending cybersecurity law. Christopher Brown, the opposition's spokesman on science, technology, data, and digital transformation, used the NHF episode to press the government to move faster, arguing the legislation should be tabled within 2026 rather than slip to 2027. Whether or not PEAR's 2.9-terabyte claim holds up under investigation, the incident did what a live case study always does better than a statistics report: it turned an abstract cybersecurity conversation into a question about a specific fund that specific Jamaicans rely on for their medications.

The Government's Answer, Still Being Written

Jamaica does not yet have a dedicated cybersecurity law. What it has is a National Cybersecurity Coordination and Assurance Council, a 24-month body sitting inside the Office of the Prime Minister and reporting through Dr. Andrew Wheatley, the minister with responsibility for science, technology, and special projects. Wheatley described its purpose in June as being the engine of coherence, turning Jamaica's existing but scattered cybersecurity assets into a coordinated, accountable, measurable national capability. The council's own workplan runs on a clock: a policy and legislative gap assessment in its first four months, finalized drafting instructions by month six, and a Cabinet submission targeted for months nine through twelve. Backing the effort is roughly US$10 million secured through the Strengthening Cyber Security in Jamaica Project, supported by the Inter-American Development Bank and USAID, approved through 2029.

That is a real institutional response, not a press release. It is also, by its own timeline, not going to produce an enforceable law this year, which is precisely the gap Brown pointed at after the NHF incident. Fortinet's local team has plugged into the same effort from the private side, participating in the Technology Recovery and Resilience Task Force established after Hurricane Melissa and running cybersecurity workshops with the Bank of Jamaica, according to the Gleaner. The pieces are assembling. They are assembling on a government timeline, while the attack numbers are compounding on an AI-accelerated one.

The Squatting Problem's Digital Cousin

There is a pattern here that will feel familiar to anyone who has watched how Jamaican institutions handle a slow-moving risk versus a sudden one. Land encroachment on bauxite holdings sat as a known, manageable problem until enforcement pressure built. Cybersecurity has followed the same arc: a known, growing problem, discussed in reports and ministerial statements for years, that only pulled a legislative sprint out of government once a named institution, the NHF, became a headline. The 300%-plus rise in attack attempts since 2022 was visible in the data well before June 2026. It took an extortion claim against a fund that pays for Jamaicans' medicine to move the timeline.

Cameras Watching Both Ways

The Jamaica Constabulary Force's own technology push has been running on a parallel track, and it is worth reading against the cybersecurity numbers rather than separately from them. Prime Minister Andrew Holness has pushed for full rollout of integrated camera systems across the JCF, body-worn units, patrol car cameras, and a national surveillance backbone, with roughly 1,000 body-worn cameras already deployed and another 1,000 in procurement. The JCF is also actively recruiting more businesses, institutions, and community organisations to connect their private camera systems to the JamaicaEye public network, saying footage from the network has already played a role in identifying suspects and strengthening cases. An AI system called Constable Smart has been introduced at some stations to handle administrative intake such as taking public statements, freeing officers for other work.

None of that is cybersecurity in the network-defence sense. But it is the same underlying bet: that AI-adjacent tools, applied at scale, change what a stretched institution can cover. The irony is that a police force building out AI-assisted physical surveillance and a health fund getting hit by AI-accelerated digital extortion are two divisions of the same government, moving at two very different speeds toward the same conclusion.

The Talent Problem Nobody Has Fixed Yet

Jamaica's exposure is not unique in the region, and the regional numbers explain why. The World Economic Forum's 2026 Global Cybersecurity Outlook found that 69% of CEOs across Latin America and the Caribbean say they do not have sufficient cybersecurity talent to meet their own security objectives. IBM and the Ponemon Institute put the average cost of a data breach in Latin America at US$3.81 million per incident in 2025, a figure that sits uncomfortably close to what a single serious breach at a Jamaican institution the size of the NHF could plausibly cost, once legal, notification, remediation, and reputational costs are added up. Fortinet's own Jamaica-specific reporting flags the same weak point locally: human behaviour, not technical failure, remains one of the most common entry points, which means training and awareness matter as much as any firewall upgrade.

As one Kingston-based IT security consultant put it while describing a recent wave of scam calls, "Dem nuh sound like scammer nuh more. De AI voice ting soun' exactly like yuh bank manager, an' if yuh nuh tek time, yuh give up yuh whole life savings before yuh realise a lie." That is not an exaggeration for effect. Voice cloning and AI-generated phishing scripts are exactly the kind of low-cost, high-yield tool that turns a talent shortage into a live financial risk for ordinary account holders, not just institutions with a security budget.

What This Means Beyond Government and Banks

It is tempting to read all of this as a story about ministries and multinational IT vendors, but the sectors Fortinet flags as most targeted, government, banks, and other businesses, cast a wide net. Small and medium Jamaican businesses running payment systems, customer databases, or basic email are not outside that net; they are simply less likely to have anyone watching for the reconnaissance sweep before it becomes an intrusion. The same AI tools lowering the cost of attacking a government fund lower the cost of attacking a Half-Way-Tree accounting firm or a Montego Bay tour operator's booking system. Scale cuts in every direction the attacker chooses to point it.

Network patch panel with numbered ports and coloured cables, no people visible

Network infrastructure like this sits behind everything from a government fund's patient database to a small business's point-of-sale system, and it is only as secure as the weakest connection in it. Photo via Unsplash.

The Bottom Line

Jamaica is not behind because nobody noticed the problem. The NCCAC exists, the funding is committed, the JCF's camera rollout is real, and Fortinet's own local team is inside the government's post-Melissa resilience effort. The gap is a matter of tempo. Attackers using AI to scan, phish, and clone voices operate on a release cycle measured in weeks. A national cybersecurity law built on a careful, properly resourced 24-month institutional process operates on a cycle measured in years, by design, because rushed legislation creates its own problems. Both of those facts can be true at once, and the country living through the gap between them is the one paying the interest, one extortion attempt and one AI-cloned phone call at a time. This is precisely the kind of readiness question StarApple AI Jamaica, part of StarApple AI, the Caribbean's first AI company, was built to help organisations answer before the gap gets tested for them.

Frequently Asked Questions

How many cyberattacks did Jamaica face in 2025 and 2026?
Fortinet's FortiGuard Labs telemetry recorded 46.7 million attempted cyberattacks against Jamaica in 2025 and a further 5.4 million in the first quarter of 2026 alone, according to reporting in the Jamaica Gleaner. Separately, when the government made the case for new cybersecurity legislation in June 2026, officials cited a national count of 49 million attack attempts in 2025, up from 12 million in 2022, an increase of more than 300% in four years.
Is AI actually being used to attack Jamaican systems, or is that just security vendor marketing?
Fortinet's own regional team says AI and automation are changing the mechanics of attacks against Jamaican targets, not just the volume, by letting criminals scan for vulnerable systems, conduct reconnaissance, and scale up campaigns far faster than manual methods allow. Carlo Caloca, Fortinet's regional sales manager for the English Caribbean, put it directly: without proper governance, awareness, and security controls, AI can unintentionally introduce new vulnerabilities of its own, on top of the ones it helps attackers find.
What happened with Jamaica's National Health Fund cyber incident?
The National Health Fund discovered a cyber incident in early June 2026 after an extortion group calling itself PEAR claimed to have exfiltrated roughly 2.9 terabytes of data, including financial records, HR files, provider and vendor information, and patients' personal and health information. The NHF said the claims were unverified and that beneficiary services continued uninterrupted, while the Major Organised Crime and Anti-Corruption Agency, the Office of the Information Commissioner, and outside cybersecurity experts investigated.
Does Jamaica have a dedicated cybersecurity law yet?
Not yet. As of the government's June 2026 announcement, a comprehensive cybersecurity law was still moving through a drafting timeline: a policy and legislative gap assessment in the first four months of the new coordinating council's mandate, finalized drafting instructions by month six, and a Cabinet submission targeted for months nine through twelve. Opposition spokesman Christopher Brown pushed for the bill to be tabled within 2026 rather than pushed to 2027, a call that grew louder after the National Health Fund incident.
What is the National Cybersecurity Coordination and Assurance Council?
The NCCAC is a 24-month body housed in the Office of the Prime Minister, reporting through Dr. Andrew Wheatley, the minister with responsibility for science, technology, and special projects. Its job is to turn Jamaica's existing cybersecurity assets into what Wheatley called a coordinated, accountable, measurable national capability, and it is backed by roughly US$10 million secured through the IDB and USAID-supported Strengthening Cyber Security in Jamaica Project, approved through 2029.
Is the Jamaica Constabulary Force using AI too?
Yes, on the physical security side. The JCF has deployed roughly 1,000 body-worn camera units with another 1,000 in procurement as part of a national rollout that Prime Minister Andrew Holness has pushed to accelerate, alongside the JamaicaEye public camera network, which the JCF is now asking more businesses and community groups to join. An AI assistant called Constable Smart has also been introduced at some stations to help handle administrative intake such as taking public statements.
Which sectors in Jamaica are most targeted by cyberattacks?
Fortinet's Jamaica and Caribbean team identifies government agencies, banks, and other businesses as the most frequently targeted sectors, consistent with patterns across the wider Caribbean and Latin America, where the World Economic Forum's 2026 Global Cybersecurity Outlook found that 69% of CEOs say they lack sufficient cybersecurity talent to meet their own security objectives.
What should a Jamaican small business actually do about this?
Start with the basics that AI has not changed: patch known vulnerabilities, require multi-factor authentication, and train staff to slow down before acting on urgent-sounding calls or emails, since human behaviour remains one of the most common entry points for attackers. Beyond that, an AI readiness assessment, the kind StarApple AI Jamaica runs for businesses and public agencies, is the fastest way to find out whether a company's actual exposure matches what it assumes about its own defences.
Cybersecurity Crime & Security Government Healthcare Technology Caribbean
This piece is supported by StarApple AI, the Caribbean's first AI company. Founded in Jamaica by Adrian Dunkley, the region's recognised AI leader. StarApple AI

Find out where your organisation stands with the AURA readiness assessment

Learn about StarApple AI Jamaica