Full Breakdown
Puerto Rico’s Tax Agency Exposes Millions of Social Security Numbers via Property Map
7/10/2026, 3:04:54 PM
CRIM Property Map Exposes SSNs
The Municipal Revenue Collection Center (CRIM) — the agency that collects property taxes in Puerto Rico — unintentionally made the Social Security numbers of roughly 1 million residents accessible through its online “Catastro Digital” property map. The vulnerability allowed anyone with technical knowledge to download unprotected personal data without authentication. After being alerted in mid-June by Centro de Periodismo Investigativo and ProPublica, the agency patched the server folders, though it continued to deny any breach of confidential taxpayer information.
Background & Context
The incident adds to a pattern of cybersecurity failures in Puerto Rico’s government. PRITS data show more than 2 million attempted cyberattacks this year, half classified as critical. Prior incidents include a March attack that delayed driver-license appointments, a 2022 unauthorized access to the Justice Department’s criminal records database, and a 2023 ransomware breach of the island’s water utility. In response, lawmakers passed Act 40 in 2024, mandating minimum cybersecurity standards, annual risk assessments, and penalties for non-compliance. However, three cybersecurity experts note that most agencies have not fully implemented these standards, remaining reactive rather than proactive.
Official Statements & Responses
CRIM Executive Director Javier García Cintrón asserted that a review found “NO breach of confidential personal taxpayer information,” adding that the platform “does NOT contain or display the type of information alluded to.” He also claimed that “no protected information was at risk” and refused to notify affected individuals. A PRITS spokesperson declined to comment, citing the island’s public-information law.
Criticism & Opposition
Cybersecurity specialist Carlos Pérez, director of security intelligence at TrustedSec, warned that agencies are “addressing the symptom but not the disease.” A former government IT employee, speaking anonymously, said Act 40 lacks unified standards, allowing each agency to set its own data-protection rules, which hampers consistent security across the government.
Verbatim Quotes
- “Following a review of the Catastro Digital platform, it was determined that there was NO breach of confidential personal taxpayer information, as the Catastro Digital does NOT contain or display the type of information alluded to,” — Javier García Cintrón, CRIM Executive Director
- “no protected information was at risk.” — Javier García Cintrón
- “We are addressing the symptom but not the disease,” — Carlos Pérez, Director of Security Intelligence, TrustedSec
