
According to Centro de Periodismo Investigativo and ProPublica, the government agency that collects property taxes in Puerto Rico unintentionally exposed the Social Security numbers of nearly 1 million people.
It was the government of Puerto Rico’s latest security lapse, which has seen systems breaches disrupt government services, shut down websites, and result in users ‘ personal information being published on the dark web in the last three years.
CPI and ProPublica notified the company in mid-June about the vulnerability that was posed by the Municipal Income Collection Center’s engaging house map, known as the Catastro Digital.
For every registered house on the island, the website application provides details such as length, boundaries, tax evaluation, sale price, owner’s name, and other details.
Without a username or password, everyone who understands how websites obtain personal information like Social Security numbers could get sensitive information if a quick search of the map didn’t show it.
The news agencies were able to identify the security flaw and provided CRIM, a detailed explanation of the problem that included the specific site and folders that the compromised data contained.
Despite the alert, CRIM has frequently denied that its system had any issues.
According to a review of the Catastro Digital system, it was determined that there was NO violation of personal personalized taxpayer information because it did not contain or show the type of information that was mentioned, according to CRIM Executive Director Javier Garca Cintrón.
The media agencies were allowed to see that the security flaws had been fixed a few days after CPI and ProPublica spoke with CRIM.
Garca refuted that, saying that there was no need to fix the issue. A violation of Puerto Rico law requires any person, including government organizations, to immediately inform customers if their private information has been compromised. However, Garca claimed that the organization would not contact people to let them know that their Social Security numbers might be exposed because” no guarded information was in danger.”
Additionally, CRIM failed to inform PRITS, the Puerto Rico Innovation & Technology Service, which manages all authorities information technology techniques. In accordance with the government’s cybersecurity process, PRITS must be informed of “any suspected protection incident.”
A PRITS representative declined to respond to inquiries and stated that they must be made in accordance with Puerto Rico’s open information law, which prohibits responding to press inquiries.
According to PRITS data, more than 2 million attempted attacks have been reported for the Puerto Rico state so far this year. According to the organization, the firm described the majority of these as” critical incidents,” which involve” significant impact on critical operations, the sacrifice of sensitive data, or an immediate threat to firm safety or government data.”
Following an intended attack on the Transportation Department’s techniques in March, citizens saw their appointments for driver’s license and registration delayed. Puerto Ricans were unable to check their criminal history status, which they needed for employment, for about a week last year due to an “unauthorized access” to the nearby Justice Department’s criminal records database. After a ransom attack, Puerto Rico’s water value clients and employees saw their private details published on the dark web in 2023.
In response to a rise in attacks, Puerto Rico lawmakers in 2024 passed Act 40, a thorough cybersecurity law that mandated that all government agencies apply least cybersecurity standards and principles. Additionally, it forbade those who don’t comply and required all federal agencies to carry a risk assessment at least once every year.
However, three cybersecurity experts claim that even as attacks get more regular and powerful, organizations have failed to fully adhere to the security standards set forth by the law. Companies are reactive, they said, rather than constantly assessing and addressing vulnerabilities that prevent these attacks.
90 local government agencies were found to have flaws in a late last month report from the Puerto Rico Inspector General Office, with 60 % of them failing to do risk assessments of their IT systems.
Carlos Pérez, a security expert in Puerto Rico and director of safety cleverness at TrustedSec, a consulting firm that works with governments and secret companies, said the government may be “much better” if it focused on staff training and implemented tools like stochastic authentication on the front end.
He claimed that the disease is being addressed rather than the sign.
A former state IT employee who requested anonymity because he feared expert repercussions claimed that in the majority of cases, the cybersecurity law does not impose integrated standards across the government. Organizations can now choose how to protect private information on their own because there isn’t a second set of standards.
Garca explained that the organization uses credentials, names, and text messages to verify individuality as part of CRIM’s safety procedures. He disputed the claim that anyone could use the common website to conduct specific searches without a password to access the Catastro Digital database.
Given the spread of private businesses that sell Puerto Rico real property data obtained from public databases like Catastro Digital, the ability to get Social Security numbers via CRIM’s home map raises concerns. Any of those businesses may include accessed the information, including private information.
CPI and ProPublica contacted at least three home listing companies, who claimed they had no knowledge of any vulnerabilities or had not accessed the sensitive information.
The second article on ProPublica: A Puerto Rico Government Agency Exposed 1 Million Social Security Numbers.




