You do not have to look at a foreign retailer to understand the stakes. In the last year, Puerto Rico has watched its payment infrastructure, its government agencies, and its property records all get reached. Two of these cards describe the same Evertec event, because Popular was one of the downstream institutions.
May – June 2026 · payments infrastructure
Evertec
Evertec discovered potential unauthorized access on May 13, 2026, involving a third-party support platform, and disclosed it in a Form 8-K filed with the SEC on June 9, 2026.
The exposure included transaction records, some payment card numbers, and some names and contact details, primarily affecting Puerto Rico financial-institution clients and their customers. Public reporting identified proposed federal class actions; we have not verified the current docket count, so treat the number as reported rather than established.
⚠ entry point: a third-party support platform
June 2026 · downstream exposure
Banco Popular
Popular’s customers had data exposed through a third-party provider: the Evertec incident. Popular’s own 8-K states that its systems were not accessed.
That distinction matters, and it is exactly the point. An institution can run its own security well and still have its customers’ information exposed, because the data was sitting in a partner’s environment. Your customers do not experience that nuance. They experience a letter.
⚠ entry point: a vendor holding your customers’ data
November 25, 2025 · government services
TrueNorth
Puerto Rico officials publicly confirmed a ransomware attack involving TrueNorth Corporation, an IT vendor, affecting three government agencies: the Department of Education, ASES, and the CFSE. Officials also said no citizen data was lost.
Beyond that, the detail is reporting rather than a public forensic finding. According to reporting that cited an internal government report, attackers used compromised vendor credentials and more than 150 CFSE servers were affected. We are flagging the sourcing because the distinction matters: one vendor relationship becoming three agencies’ outage is the pattern worth learning from, and it rests on a document nobody outside government has seen.
⚠ reported entry point: compromised vendor credentials
July 2026 · public records
CRIM’s Catastro Digital
CRIM’s Catastro Digital property map exposed roughly one million Social Security numbers, downloadable without any authentication. The hole was patched within days.
The agency denied that a breach had occurred and did not notify the affected citizens. Reported by ProPublica on July 9, 2026.
⚠ entry point: no authentication at all
the pattern, if you squint:
Read the four cards as three incidents. Popular and the three agencies were downstream victims of somebody else’s compromise. Evertec was itself compromised, through a third-party support platform. CRIM was a direct exposure of its own system. The pattern worth taking is the downstream one: a support platform, a vendor’s credentials, a partner’s environment. You inherit the security of every vendor and every platform in your stack: their patch discipline, their access hygiene, their incident response, whether you ever met their engineers or not. Which is the whole argument for knowing exactly what your stack is made of, and owning the parts that hold anything you would hate to lose.