Breach taxonomy
Summary
Popular, Inc. was notified on May 15, 2026 by Evertec, its third-party core financial transaction processing provider, that Evertec had experienced a cybersecurity incident affecting client data, including that of Banco Popular de Puerto Rico. Affected data includes personal information of certain BPPR customers, including debit card numbers. Popular's own systems were not accessed; the bank implemented enhanced fraud monitoring and has a contractual right to be covered by Evertec for losses. Filed under Item 8.01; company does not believe the incident is material.
Tagging rationale
ThreatUnknown
Filing does not attribute the incident to a specific actor -> UNKNOWN.
MethodsData ExfilSupply Chain
Breach occurred at third-party processor Evertec and compromised BPPR customer data held there -> DATA-EXFIL + SUPPLY-CHAIN (Evertec).
AssetsPersonal Data
Affected data 'includes personal information of certain BPPR customers, including debit card numbers and certain other information' -> PERSONAL-DATA.
EffectsInfo Privacy Loss
Only effect on Popular is exposure of customer personal/debit card data; 'the Corporation's systems were not accessed in or otherwise affected by this incident' -> INFO-PRIVACY-LOSS.
Business continuityNot Required
No operational disruption; Popular's own systems were not accessed -> Not Required.
Impact
Customer debit card and personal data exposed via vendor, but no system impact and losses contractually recoverable from Evertec -> score 2.
InsuranceNot disclosed
Filing mentions a contractual indemnification right against Evertec, not insurance coverage -> null.
Read the original SEC filing excerpt
Item 8.01. Other Events. On May 15, 2026, Popular, Inc. (the "Corporation") was notified by Evertec, Inc. ("Evertec"), a third-party core financial transaction processing and information technology services provider of the Corporation, that Evertec had experienced a cybersecurity incident affecting certain data of its clients, including that of Banco Popular de Puerto Rico ("BPPR"), the Corporation's Puerto Rico banking subsidiary. Subsequent to its initial notification, Evertec notified the Corporation that it had identified additional data from BPPR that had been compromised. Based on information gathered to date, the affected data includes personal information of certain BPPR customers, including debit card numbers and certain other information. The Corporation is assessing the situation closely with Evertec and has implemented enhanced fraud monitoring measures to further protect its customers. The Corporation has a contractual right to be covered by Evertec for losses resulting from, and reasonable and customary costs and expenses related to, the incident. The Corporation promptly initiated its cybersecurity incident response protocols and has notified applicable regulators. Affected customers will be notified directly, as appropriate. The Corporation's systems were not accessed in or otherwise affected by this incident.