FEDERALItem 8.01 · voluntaryHackingSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowActive
BANCO POPULAR DE PUERTO RICO
bd_ebafd185592a4bd8 · schema v1 · pii pii-v1
Full breach record for BANCO POPULAR DE PUERTO RICO →Popular, Inc. filed an 8-K on June 9, 2026, disclosing a cybersecurity incident affecting its Puerto Rico banking subsidiary, Banco Popular de Puerto Rico (BPPR). The incident was caused by a third-party service provider, Evertec, Inc., which experienced unauthorized access to client data. The compromised data included BPPR customer debit card numbers and other personal information. Popular's own systems were not accessed. The company has implemented enhanced fraud monitoring and notified regulators.
SEC clockMateriality determined Jun 9, 2026 → Filed Jun 9, 20260d ✓ SEC 4-day OK25 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/763901/000119312526263044/d46942d8k.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 9, 2026
- Raw hash
- 524b21dbba8cfe09f7834d254890b6bcbbc209365a9c7c6df342975d485e1b2c
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- POPULAR, INC.norm: popular
- SEC CIK
- 0000763901
Victim entity
- Name
- BANCO POPULAR DE PUERTO RICOnorm: banco popular de puerto rico-pr
Incident
- Discovered
- May 15, 2026
- Materiality determined
- Jun 9, 2026
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- notified applicable regulators
- Third party
- via Evertec, Inc.
- Initial access
- supply_chain
Compliance
- Time to disclose
- 25 days(25 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 0d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jun 9, 2026→ Filed: Jun 9, 20260d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.