8-K: Popular, Inc. Reports Cybersecurity Incident via Third-Party Provider
Other Events
Popular, Inc. disclosed a cybersecurity incident affecting its subsidiary Banco Popular de Puerto Rico, stemming from a breach at its third-party processor, Evertec, Inc.
Summary
- Popular, Inc. was notified by Evertec, Inc., a core financial transaction processing and IT services provider, about a cybersecurity incident.
- The incident affected certain data of Evertec's clients, including Banco Popular de Puerto Rico (BPPR), Popular's Puerto Rico banking subsidiary.
- Additional compromised data from BPPR has been identified by Evertec.
- The affected data includes personal information of certain BPPR customers, such as debit card numbers.
- Popular is working with Evertec, has implemented enhanced fraud monitoring, and notified regulators.
- The company's own systems were not accessed.
- Popular does not believe the incident will materially impact its operations, financial condition, or results.
- The company has a contractual right to be covered by Evertec for losses and expenses related to the incident.
Sentiment
Score: 5
Explanation: StockSavvy.ai views this as a neutral to slightly negative event due to the cybersecurity incident, but the company's assessment of no material impact and contractual protections temper the immediate concern.
Positives
- Popular, Inc.'s own systems were not accessed or affected by the incident.
- The company has a contractual right to be covered by Evertec for losses and expenses related to the incident.
- Enhanced fraud monitoring measures have been implemented to protect customers.
- Applicable regulators have been notified promptly.
- The company does not believe the incident is reasonably likely to have a material impact on operations, financial condition, or results.
Negatives
- A cybersecurity incident occurred at Evertec, Inc., affecting data of Popular's subsidiary, Banco Popular de Puerto Rico.
- Personal information of certain BPPR customers, including debit card numbers, was compromised.
- Additional compromised data from BPPR has been identified by Evertec.
- The incident may lead to regulatory scrutiny.
- There are risks related to the availability of cost and expense reimbursement and insurance coverage.
Risks
- Results of Evertec's analysis of the scope and details of the cybersecurity incident and the discovery of new or additional information.
- Any potential adverse impact of the cybersecurity incident on Popular's operations, financial condition, or results of operations.
- Diversion of management's attention from operations to address the cybersecurity incident.
- Potential adverse effects on relationships with customers and other third parties.
- Regulatory scrutiny of the cybersecurity incident.
- Risks related to the availability of cost and expense reimbursement and insurance coverage.
Future Outlook
The company does not believe the incident is reasonably likely to have a material impact on its operations, financial condition, or results of operations. However, potential factors, some of which are beyond the Corporation's control, could cause actual results to differ materially from forward-looking statements.
Management Comments
- The Corporation is assessing the situation closely with Evertec and has implemented enhanced fraud monitoring measures to further protect its customers.
- Based on the information currently available, the Corporation does not believe that the incident is reasonably likely to have a material impact on the Corporations operations, financial condition or results of operations.
Industry Context
StockSavvy.ai notes that this incident highlights the increasing risk of third-party vendor breaches in the financial services sector, where reliance on external IT providers is common. Companies must maintain robust vendor risk management programs and incident response plans.
Stakeholder Impact
- Shareholders: Potential for reputational damage and uncertainty regarding the full impact of the incident, though management states no material impact is expected.
- Customers: Risk of personal information compromise, including debit card numbers, necessitating vigilance and potential direct notification.
- Regulators: Increased scrutiny due to the data breach affecting a financial institution's customers.
Next Steps
- Evertec will continue its analysis of the cybersecurity incident.
- Popular will continue to assess the situation with Evertec.
- Affected customers will be notified directly, as appropriate.
- Popular will continue to implement enhanced fraud monitoring measures.
- Popular has notified applicable regulators.
Key Dates
| Date | Description |
|---|---|
| 2026-05-15 | Popular, Inc. was notified by Evertec, Inc. of a cybersecurity incident. |
| 2026-06-09 | Date of Report (Date of earliest event reported). |
Recommendation
holdThe filing reports a cybersecurity incident at a third-party provider impacting customer data. While management states no material impact is expected and contractual protections exist, the uncertainty surrounding the full scope and potential long-term effects, including regulatory scrutiny and customer relations, warrants a 'hold' recommendation pending further clarity.
Keywords
cybersecurity incident, Evertec, Banco Popular de Puerto Rico, data breach, third-party risk, fraud monitoring, regulatory notification, Popular, Inc.
Disclaimer:The information provided here is for general informational purposes only and does not constitute financial advice, recommendation, or endorsement of any kind. It may contain errors or omissions. You should not rely on this information to make financial decisions. Always seek the advice of a qualified financial professional before making any investment or financial decisions. Use of this information is at your own risk.