Skip to content

Puerto Rico DTOP cyberattack attempt

Summary

Puerto Rico Department of Transportation and Public Works logo

Puerto Rico security monitors detected and neutralized a cyberattack attempt against DTOP on March 23, prompting officials to disconnect systems and pause CESCO appointments across the territory. CESCO centers resumed regular operations March 26 except Utuado, which still required additional validation. Officials said resident information remained secure, and no stable public actor claim was identified.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • No known data impact

    Available evidence indicates that the incident did not materially affect the confidentiality, integrity, or availability of data.

Operational impacts

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Scheduling disruption

    Appointment, booking, reservation, dispatch, staffing, or other scheduling functions were unavailable or impaired.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

  • Complete service outage

    A primary service, system, platform, or operational capability became entirely unavailable.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

Puerto Rico security monitors detected and neutralized a cyberattack attempt against the Department of Transportation and Public Works on March 23, 2026. PRITS and DTOP disconnected affected systems as a precaution while technical teams evaluated the environment. The direct government characterization provides concrete cyber evidence, but the public record does not establish the specific attack mechanism or a responsible actor.

Operational significance

The shutdown paused appointments at Driver Service Centers, known as CESCO, across Puerto Rico, requiring affected visits to be rescheduled while systems were validated. Officials said there was no evidence that resident information had leaked or been compromised.

NotiCel reported that CESCO centers resumed regular operations March 26 after technical testing and validation. Utuado remained the only exception because it required additional checks. The affected geography is Puerto Rico territory-wide.

Current status

The incident is presumed resolved. March 26 is the last documented operational-impact date, and no later continuing impact was found. The public record does not provide a subsequent statement affirming that Utuado’s remaining validation was complete.

Confidence and uncertainty

Confidence is high that a cyberattack attempt triggered the preventive shutdown and territory-wide service interruption because DTOP and PRITS directly described the event and response. No known data impact was reported. Ransomware and attribution remain unresolved: searches using the department’s English and Spanish names, DTOP and dtop.pr.gov found no stable public actor claim, and officials did not identify ransomware, malware or an extortion demand.

Analytic gaps

The public record does not establish the access method, affected hosts, malicious tooling, persistence, responsible actor or whether Utuado required further recovery after March 26.

Organizations involved

Impacted locations

Sources

El DTOP fue blanco de un ataque cibernético, confirma PRITS

PRITS confirmed DTOP was targeted in a cyberattack and systems were disconnected while scope and restoration were evaluated.

DTOP anuncia restablecimiento de servicios en los CESCO tras ataque cibernético

DTOP and PRITS said CESCO centers resumed regular operations March 26 after technical testing and validation, except Utuado, which still required additional checks. Officials said resident information remained secure.

Gazetteer Files

The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.

See something that needs correction?

Signed-in members can report an error, update, or missing source.