Panama Papers Leak: The Cyber Security Angle

07 Apr 2016

Panama Papers Leak: The Cyber Security Angle

The headlines have been full of revelations about the activities of many of the world's rich and powerful after sensitive data leaked from Panama-based law firm Mossack Fonesca made its way into the hands of journalists.

Eleven million documents (2.6 terabytes of data) was leaked. To get an idea of how much data that is; 1 Gigabyte is proportionate to 1 metre of paperback book which means the breach could be represented as 2,600 metres of paperback book. In short, it is the largest public leak in history. Politicians, Bankers, Business people and many more have had their financial activities exposed to the public and the reputational damage to Mossack Fonesca will be high.

Mossack Fonesca has blamed the leak on hackers and has ruled out the possibility of it being an inside job.

"We rule out an inside job. This is not a leak. This is a hack, we have a theory and we are following it," said Ramon Fonseca, one of the founders of the law firm. 

As the fallout from the leak continues, people are now trying to discover how the leak happened and the implications that the data holds for individuals, organisations and nations.

PGI Intelligence has written an in-depth  report  on the leak and its implications for geopolitics.

According to Süddeutsche Zeitung, the newspaper that was contacted by the whistle-blower; "The source wanted neither financial compensation nor anything else in return, apart from a few security measures."

Despite Fonesca ruling out an inside job, the event is likely to raise awareness of the threat.

Insider threats come in two variations. The first is the malicious threat where an employee, former employee, contractor or business associate deliberately bring harm to an organisation. A good example is someone with insider knowledge of the organisations security systems hacking or exploiting said systems. Normally, the perpetrators of malicious insider threats are disgruntled employees. The second variation is accidental which can be due to a lack of awareness or training.

Whether the whistle-blower was a former employee, current employee or someone who managed to breach Mossack Fonesca’s security from the outside is not likely to be revealed. Exposing the secret financial dealings of the powerful means that the person or persons responsible will never willingly reveal their entity and like all good journalists, Süddeutsche Zeitung will never reveal the identity of their source.

Organisations will be scrutinising their systems, processes and people in light of this breach. The ability to identify an issue before it occurs can prevent incidents of this nature, especially when a combination of technology, processes and human education and behaviour is addressed. PGI’s approach to risk reduction follows this methodology.

One of PGI’s subsidiaries ( ) has developed a robust set of analytical algorithms called  Culture Metrics , that when applied on a regular basis, empowers organisations by monitoring the contentment levels of their staff.

Improved education of senior management and staff reduces the risks. PGI’s Cyber Security Awareness Course (CSA) for example provides a comprehensive syllabus for protecting a business’s online identity. 

Protective Monitoring

If the leak was indeed the result of a breach by an external party, questions will be asked Mossack Fonesca’s cyber security.

 A service such as PGI’s protective monitoring service, for example, helps keep an organisation's sensitive data safe. Protective monitoring is a structured, and cost-effective method of making sure your business network infrastructure is continually under surveillance, periodically tested and, most importantly, safe from cyber threats.

Using a combined approach and the use of effective cyber security education an organisation can greatly reduce the risks they face.

For more information contact PGI on +44 (0)207 887 2699 or email us at

For the latest PGI updates like our pages on LinkedIn –   PGIPGI Cyber   and Facebook –   PGIPGI Cyber

Share this article


Your free global geopolitical
risk dashboard

PGI’s Risk Portal tool provides daily intelligence feeds, country threat assessments and analytical insights, enabling clients to track, understand and navigate geopolitical threats.

The Risk Portal gives users up-to-date information and analysis on global affairs.

The Risk Portal allows users to visualise information in a unique and instantly understandable way. Mapping filters enable the visualisation of incidents by threat category, time period, perpetrator and target type.

Risk Portal users can upgrade their accounts to include the Report Builder and Country Profile Generator features. The Report Builder allows users to select information, data and images from the Risk Portal and create bespoke reports and emails.

Subscribers to PGI’s Bespoke services receive tailored analysis on specific sectors and geographies of interest, delivered at a frequency they determine.

Visit the Risk Portal

Subscribe to our Cyber Bytes Newsletter

Keep yourself in the loop with PGI by signing up to our Monthly Cyber Bytes email. You will receive updates, tips and narrative around what has been happening in the world of information security.

Get in touch today

For more information on how we can help you or your business, please contact us via:

Related News

CISMP, CISSP and CISM - what's in an acronym?

20 Mar 2017

There is a wide range of different security courses available, and a mind-boggling array of certific...

Read news article

International Womens Day - Pioneering Women in Tec...

08 Mar 2017

Pioneering Women in Technology – Katherine JohnsonThe Oscar season has been and gone. The...

Read news article

Law Firms and why they need cyber security

06 Mar 2017

Suffering a data breach can be devastating for any company but for law firms the impacts can be part...

Read news article
Back to the News Hub

Follow us

+44 (0)207 887 2699
©2017 PGI - Protection Group International Ltd. All rights reserved.
PGI - Protection Group International Ltd is registered in England & Wales, reg. no. 07967865
Registered address: Cascades 1, 1190 Park Avenue, Aztec W, Almondsbury, Bristol BS32 4FP