Breach taxonomy
Summary
EVERTEC learned on May 13, 2026 of unauthorized access to customer data. An unauthorized party obtained, through a third-party support platform, financial institution clients' information including transaction records, payment card numbers and in some cases customer names and contact information, primarily affecting financial institution clients in Puerto Rico and their customers. EVERTEC contained the incident and believes the unauthorized party no longer has access. Filed under Item 8.01; materiality not determined as a 1.05 incident.
Tagging rationale
ThreatUnknown
Filing refers only to 'an unauthorized party' with no attribution -> UNKNOWN.
MethodsData ExfilSupply Chain
An unauthorized party 'obtained, through a third-party support platform,' client data -> DATA-EXFIL + SUPPLY-CHAIN.
AssetsPersonal DataCo Owned Data
Obtained data includes 'transaction records, payment card numbers of some customers and, in some instances, customer names and contact information' belonging to financial institution clients -> PERSONAL-DATA + CO-OWNED-DATA.
EffectsInfo Privacy Loss
Only disclosed effect is compromise of client customer payment card and personal data with no operational disruption -> INFO-PRIVACY-LOSS.
Business continuityNot Required
No operational disruption described; response was containment and forensic investigation -> Not Required.
Impact
Payment card numbers and transaction records of multiple financial institution clients' customers in Puerto Rico were obtained -> score 3.
InsuranceNot disclosed
Filing makes no mention of insurance -> null.
Read the original SEC filing excerpt
Item 8.01 Other Events. On May 13, 2026, EVERTEC, Inc. ("Evertec" or the "Company") learned of potential unauthorized access to customer data. The Company promptly initiated its cyber incident response protocols to contain the intrusion, assess and investigate the nature and scope of the incident, and implement appropriate remedial measures. The Company also notified federal law enforcement authorities and engaged external cybersecurity experts to assist in the investigation and response efforts. While the full scope of impacted data remains under forensic investigation and is subject to change as the assessment continues, at this time the Company believes that an unauthorized party obtained, through a third-party support platform, certain of our financial institution clients' information related to transaction records, payment card numbers of some customers and, in some instances, customer names and contact information. Based on our current understanding, the Company believes that the incident has primarily impacted our financial institution clients in Puerto Rico and their respective customers. The Company has taken steps to contain the incident and secure our systems, and believes that the unauthorized party no longer has access to the third-party platform.