CRIM’s Catastro Digital exposed about 1 million Social Security numbers
A Puerto Rico property-tax agency says there was no breach, even as a vulnerability let attackers download SSNs.

Puerto Rico’s Municipal Revenue Collection Center, CRIM, ran the Catastro Digital property map that Centro de Periodismo Investigativo and ProPublica found could expose Social Security numbers for about 1 million people. For decision-makers, it raises a board-level question: how can a “no breach” determination collide with patching, missed notifications, and an expanding cybersecurity enforcement gap.
A Puerto Rico government property-tax agency, CRIM, inadvertently exposed the Social Security numbers of approximately 1 million people, Centro de Periodismo Investigativo and ProPublica learned. The exposure came through an interactive online tool used to get property details island-wide: the Municipal Revenue Collection Center’s property map known as the Catastro Digital.
The critical part is how the data could be pulled. A simple search of the map would not reveal sensitive information, but anyone who understands how websites request data could download unprotected personal information such as Social Security numbers without a username or password. CPI and ProPublica notified CRIM in mid-June, verified the security hole, and provided a detailed description that included the specific server and folders that contained the compromised data.
After that notification, the story turned into a familiar cybersecurity pattern: denial, then patching, then more denial. CRIM Executive Director Javier García Cintrón repeatedly denied there were problems with its system. In a statement, García said that after reviewing the Catastro Digital platform it was determined there was “NO breach of confidential personal taxpayer information,” because the Catastro Digital “does NOT contain or display the type of information alluded to.” Yet shortly after CPI and ProPublica contacted CRIM, the news organizations were able to see that the security holes had been patched. García denied the need to fix any problem, even as the changes landed.
This matters because a Puerto Rico law requires entities, including government agencies, to promptly notify users if personal information has been breached. García said CRIM would not reach out to users to tell them their Social Security numbers were potentially exposed, because “no protected information was at risk.” That phrasing is doing a lot of work. The vulnerability, as described by CPI and ProPublica, suggests the sensitive data was accessible through the way the site was built and how it handled data requests, even if the public-facing search experience looked harmless.
CRIM also did not notify the Puerto Rico Innovation & Technology Service, known as PRITS, which oversees all government information technology systems. The government’s cybersecurity protocol requires informing PRITS of “any suspected security incident.” In response to questions, a PRITS spokesperson declined to answer and said submissions had to go through Puerto Rico’s public information law, a process intended to allow citizens to access government records rather than respond to press questions. That procedural friction can become its own risk: when incident reporting depends on internal channels that the public never sees, boards and auditors lose visibility at the exact moment they most need it.
The Catastro Digital incident lands inside a broader cybersecurity drumbeat in Puerto Rico. So far this year, more than 2 million attempted cyberattacks have been recorded within the Puerto Rico government, and PRITS data shows half were deemed critical incidents, defined as “severe impact on critical operations, the compromise of sensitive data, or an imminent threat to agency security or government data.” Earlier examples include citizens seeing driver’s license and registration appointments postponed after an attempted cyberattack on Transportation Department systems, and residents unable to verify criminal record status for almost a week after an “unauthorized access” to the Justice Department’s criminal records database. In 2023, Puerto Rico water utility clients and employees saw personal information published on the dark web after a ransomware attack.
Lawmakers responded to the frequency and scale of those events. In 2024, Puerto Rico lawmakers approved a comprehensive cybersecurity law, Act 40, which mandated minimum cybersecurity standards and principles for all government agencies, established penalties for noncompliance, and required annual risk assessments. Still, three cybersecurity experts said agencies have failed to fully implement the security standards, and that the system too often becomes reactive instead of preventive. A Puerto Rico Inspector General Office report released late last year found deficiencies across 90 local government agencies, with 60% failing to conduct vulnerability assessments of their IT systems.
For executives, the second-order implications are bigger than one agency’s denial language. One reason is the ecosystem risk: the ability to access Social Security numbers through CRIM’s property map raises concerns given the proliferation of private companies that sell Puerto Rico real estate information obtained from public databases like Catastro Digital. Even if property listing companies contacted by CPI and ProPublica said they were not aware of any vulnerability and did not access sensitive data, the pathway to do so was theoretically open. Another reason is operational governance: García said CRIM’s security measures rely on passwords, usernames, and text messages to validate identity, and he denied access to the database without a password except to conduct individual searches through the public website. But the reported vulnerability suggests that “search-only” protections are not the same thing as “data-access” protections.
Carlos Pérez, a cybersecurity expert in Puerto Rico who is director of security intelligence at TrustedSec, said organizations are addressing the symptom but not the disease, pointing toward gaps like employee training and tools such as multifactor authentication on the front end. A former government IT employee, who asked not to be named due to fear of professional repercussions, said the cybersecurity law falls short by not requiring unified standards across the government. That lack of a single set of standards, the source suggests, lets agencies decide on their own how they protect personal data, creating uneven implementation even under the same legal umbrella.
Put bluntly, the Catastro Digital case is a stress test of how public-sector cybersecurity governance actually works under pressure. The stake for other executives, whether in government or any data-heavy industry, is not just whether a site gets patched after notification, but whether the incident definitions, reporting requirements, and user communication practices match the reality of how data can be extracted. When million-record exposures can be argued as “no breach,” decision-makers should expect scrutiny to sharpen, regulators to tighten requirements, and boards to demand evidence that security controls are preventing access, not just preventing obvious browsing.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Business

Anthropic’s Levant Alpöge cracks the Jacobian conjecture after 87 years
A Harvard valedictorian used Claude to hit a 1939 breakthrough, but the missing “why” is the real problem.

Uber buys Delivery Hero for nearly $15B, vaulting to top food delivery outside China
The deal doubles Uber's dual-services footprint and pushes a ride-and-eats bundling play into 50 more markets.

Epic and Google drop settlement bid, forcing rival Android app stores by July 22
Google told the court it is ready to carry third-party app stores starting Wednesday, July 22.

