PUERTO RICO — The Municipal Revenue Collection Center (CRIM) inadvertently exposed the Social Security numbers of approximately 1 million individuals through a security flaw in its interactive property map system, Catastro Digital. Centro de Periodismo Investigativo and ProPublica became aware of this vulnerability in mid-June.

The Catastro Digital online tool provides information including property size, boundaries, tax assessment, sale price, and the owner's name for every registered property in Puerto Rico. Individuals with technical knowledge of website data requests could download unprotected personal information, including Social Security numbers, from the map without requiring a username or password. The news organizations provided CRIM with a detailed description of the security issue.

CRIM Executive Director Javier García Cintrón said, "Following a review of the Catastro Digital platform, it was determined that there was NO breach of confidential personal taxpayer information, as the Catastro Digital does NOT contain or display the type of information alluded to." He denied that anyone could access the database without a password, asserting access was limited to individual searches through the public website. García Cintrón stated that CRIM utilizes passwords, usernames, and text messages to validate identity.

Despite García Cintrón's statements that no fixes were necessary, the news organizations observed that the security vulnerabilities in the system were patched a few days after their notification. Puerto Rico law mandates that entities, including government agencies, promptly notify users if their personal information has been breached. García Cintrón stated that the agency would not notify users about the potential exposure of their Social Security numbers, based on his claim that no protected information was at risk.

CRIM did not notify the Puerto Rico Innovation & Technology Service (PRITS) of the security incident. Government cybersecurity protocols require informing PRITS of any suspected security incident. In 2023, a ransomware attack on the Puerto Rico water utility resulted in the personal information of clients and employees being published on the dark web. Puerto Rico lawmakers approved Act 40, a comprehensive cybersecurity law, in 2024. This act mandates that all government agencies implement minimum cybersecurity standards and conduct annual risk assessments. The law also established penalties for noncompliance. A report released in late 2024 by the Puerto Rico Inspector General Office found deficiencies across 90 local government agencies, noting that 60% of those reviewed failed to conduct vulnerability assessments of their IT systems.