Classaction Evertec Reports Data Breach Affecting Financial Clients in Puerto Rico
Article Content
- •Evertec reported unauthorized access to customer data affecting financial clients in Puerto Rico.
- •The breach involved transaction records and payment card numbers accessed through a third-party platform.
- •Evertec is cooperating with federal authorities and external experts to investigate the incident.
Evertec, Inc. disclosed a cybersecurity incident on June 9, 2026, revealing potential unauthorized access to customer data that occurred on May 13, 2026. The breach, attributed to a third-party support platform, impacted financial institution clients in Puerto Rico, including transaction records, payment card numbers, and customer names. The company has initiated cyber incident response protocols, notified federal authorities, and engaged external cybersecurity experts for investigation. Affected clients are being informed, and Evertec is mailing notification letters to those impacted. The incident has not yet caused operational disruptions, but the full scope of the breach is still under investigation. Evertec is expected to incur expenses related to the incident and has cybersecurity insurance, though the extent of liabilities is undetermined.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Evertec in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…