Breach taxonomy
Summary
Popular, Inc. was notified on May 15, 2026 by Evertec, its third-party core financial transaction processing provider, that Evertec had experienced a cybersecurity incident affecting client data, including that of Banco Popular de Puerto Rico. Affected data includes personal information of certain BPPR customers, including debit card numbers. Popular's own systems were not accessed; the bank implemented enhanced fraud monitoring and has a contractual right to be covered by Evertec for losses. Filed under Item 8.01; company does not believe the incident is material.
Tagging rationale
ThreatUnknown
Filing does not attribute the incident to a specific actor -> UNKNOWN.
MethodsData ExfilSupply Chain
Breach occurred at third-party processor Evertec and compromised BPPR customer data held there -> DATA-EXFIL + SUPPLY-CHAIN (Evertec).