Skip to content

Truenorth cyberattack affects Puerto Rico agencies

Summary

Truenorth Corporation logo

A cyberattack on Puerto Rico IT contractor Truenorth Corporation during Thanksgiving week 2025 affected systems at the Department of Education, Health Insurance Administration and State Insurance Fund Corporation. Officials said agency staff and PRITS restored affected databases and systems from backups without reported interruption to public-facing services. Independent reporting described ransomware, which officials did not confirm.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that an attack against Truenorth Corporation caused internal system disruption at three Puerto Rico agencies in late November 2025. Our Dec. 3 report combined the government briefing with local reporting. Primera Hora’s account of the Dec. 2 briefing quotes the secretary of the governorship saying the vendor attack affected Education, ASES and CFSE, and that some databases and systems were restored from backups.

Operational significance

The affected agencies’ staff and Puerto Rico Innovation and Technology Service worked through the Thanksgiving weekend to restore systems. The secretary said agency operations and public-facing services continued and citizen data was not accessed or exfiltrated. Separate reporting by InDiario describes intermittent system availability and more extensive server effects, but those details rely on an unnamed source and were not independently verified here.

Current status

At the Dec. 2 briefing, officials said the affected systems had been restored. The investigation into how the vendor was breached continued. The incident is recorded as resolved for the documented operational impact, without asserting that every forensic question was closed.

Confidence and uncertainty

The official briefing supports the vendor-to-agency incident chain and restoration work. InDiario called it ransomware and described compromised privileged credentials; the government did not confirm that mechanism and said databases were not encrypted for ransom. Ransomware and initial access therefore remain unresolved in this record.

Analytic gaps

Initial access, full system scope, any vendor data exposure, and final forensic conclusions remain unresolved.

Organizations involved

Impacted locations

  • Puerto Rico

    Three territory-wide agencies were affected; officials said public-facing services continued.

  • San Juan, Puerto Rico

    Medium Confidence

    San Juan anchors the affected Puerto Rico government agencies; this does not assert every agency facility lost service.

Sources

Cyberattack on Puerto Rico IT vendor Truenorth hits 3 agencies

We reported Puerto Rico officials’ confirmation that a cyberattack on Truenorth affected Education, ASES and CFSE systems, while officials said public services continued and systems were restored.

Hackeo ransomware golpea al gobierno de Puerto Rico y nadie dice nada

InDiario reported, citing an unnamed cybersecurity source, that a Nov. 25 ransomware attack on Truenorth caused intermittent availability and server disruptions at the three agencies; officials did not confirm ransomware.

Tres agencias afectadas por ataque cibernético en semana de Acción de Gracias

At a Dec. 2 briefing, Secretary Francisco Domenech said Truenorth was attacked, three agencies were affected, some databases and systems were restored from backups, and citizen-facing services continued.

See something that needs correction?

Signed-in members can report an error, update, or missing source.