Truenorth Corporation

A cyberattack on Puerto Rico IT contractor Truenorth Corporation during Thanksgiving week 2025 affected systems at the Department of Education, Health Insurance Administration and State Insurance Fund Corporation. Officials said agency staff and PRITS restored affected databases and systems from backups without reported interruption to public-facing services. Independent reporting described ransomware, which officials did not confirm.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
Internal business, administrative, operational, or staff-facing systems were unavailable.
The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
DysruptionHub assesses with high confidence that an attack against Truenorth Corporation caused internal system disruption at three Puerto Rico agencies in late November 2025. Our Dec. 3 report combined the government briefing with local reporting. Primera Hora’s account of the Dec. 2 briefing quotes the secretary of the governorship saying the vendor attack affected Education, ASES and CFSE, and that some databases and systems were restored from backups.
The affected agencies’ staff and Puerto Rico Innovation and Technology Service worked through the Thanksgiving weekend to restore systems. The secretary said agency operations and public-facing services continued and citizen data was not accessed or exfiltrated. Separate reporting by InDiario describes intermittent system availability and more extensive server effects, but those details rely on an unnamed source and were not independently verified here.
At the Dec. 2 briefing, officials said the affected systems had been restored. The investigation into how the vendor was breached continued. The incident is recorded as resolved for the documented operational impact, without asserting that every forensic question was closed.
The official briefing supports the vendor-to-agency incident chain and restoration work. InDiario called it ransomware and described compromised privileged credentials; the government did not confirm that mechanism and said databases were not encrypted for ransom. Ransomware and initial access therefore remain unresolved in this record.
Initial access, full system scope, any vendor data exposure, and final forensic conclusions remain unresolved.




Guaynabo anchors Truenorth's headquarters; vendor systems were attacked, but an office-specific outage is not asserted.
Three territory-wide agencies were affected; officials said public-facing services continued.
San Juan anchors the affected Puerto Rico government agencies; this does not assert every agency facility lost service.
We reported Puerto Rico officials’ confirmation that a cyberattack on Truenorth affected Education, ASES and CFSE systems, while officials said public services continued and systems were restored.
InDiario reported, citing an unnamed cybersecurity source, that a Nov. 25 ransomware attack on Truenorth caused intermittent availability and server disruptions at the three agencies; officials did not confirm ransomware.
At a Dec. 2 briefing, Secretary Francisco Domenech said Truenorth was attacked, three agencies were affected, some databases and systems were restored from backups, and citizen-facing services continued.
Signed-in members can report an error, update, or missing source.