Cory Rove
← All articles
CRIM Exposed a Million SSNs, Then Denied It Happened

CRIM Exposed a Million SSNs, Then Denied It Happened

Puerto Rico's property tax agency patched a hole that exposed roughly one million Social Security numbers, then told the press — and the public — that no hole ever existed.

data breachinstitutional accountabilitypuerto ricoprivacy

The Municipal Revenue Collection Center of Puerto Rico — CRIM — left roughly one million Social Security numbers sitting in an unprotected folder on a public-facing server. No username. No password. Anyone who knew how websites request data could have pulled that information without restriction.

That is the technical failure. It is not the most important part of this story.

CPI and ProPublica — this account relies entirely on their investigation — identified the vulnerability in CRIM's Catastro Digital property map, documented it precisely, and notified the agency in mid-June. They provided the specific server and folder locations. Within days, the security holes were patched.

Then CRIM Executive Director Javier García Cintrón released a statement: "Following a review of the Catastro Digital platform, it was determined that there was NO breach of confidential personal taxpayer information, as the Catastro Digital does NOT contain or display the type of information alluded to."

He then characterized the patch as fixing something unrelated to a breach — because, in his framing, there was no breach to fix.

The reporters documented the vulnerability. The agency remediated it. The agency denied it existed. Those three events happened in that order.

One possible reading of García Cintrón's statement is definitional: that CRIM applies a narrower technical definition of "breach" — perhaps requiring evidence of confirmed unauthorized access — and found no such evidence. That interpretation deserves acknowledgment. What it cannot explain is the denial that the data existed in the platform at all, which the investigation directly contradicts.

What makes the sequence consequential is the legal threshold it clears. Puerto Rico law requires entities, including government agencies, to promptly notify individuals when their personal information has been breached. García Cintrón's position is that no notification is required because no breach occurred. His agency's own remediation suggests otherwise. You do not patch a folder that wasn't there.

There is a separate procedural failure. Puerto Rico's cybersecurity protocols require agencies to inform PRITS — the Puerto Rico Innovation & Technology Service — of any suspected security incident. CRIM did not notify PRITS. When reporters asked PRITS directly, the agency declined to answer and directed them to file a public records request. A public records process invoked to avoid a press question about a live incident is its own kind of signal.

The technical backdrop is not reassuring. PRITS data shows more than two million attempted cyberattacks on Puerto Rico government systems so far this year, with roughly half classified as critical incidents. A Puerto Rico Inspector General report released late last year found that 60% of government agencies had failed to conduct the vulnerability assessments mandated by Act 40, a comprehensive cybersecurity law the legislature passed in 2024. Three cybersecurity experts told ProPublica and CPI that agencies have largely failed to implement the standards Act 40 requires. One framed it simply: "We are addressing the symptom but not the disease."

The Catastro Digital exposure required no attack. No credentials were bypassed. The data was reachable because someone made a configuration decision — or failed to make one. The property map itself is designed to be public: size, boundaries, tax assessment, owner's name. Social Security numbers do not belong in the same accessible layer. That they were there reflects something about how the agency approached data architecture.

Multiple private companies that access Catastro Digital for real estate data told CPI and ProPublica they were unaware of the vulnerability and did not access the sensitive records. That is their account. What no party can establish with confidence is who else found the folder before the reporters did. The folder required no authentication. It left no mandatory access log.

The people whose Social Security numbers were exposed have not been officially notified. Their practical recourse at this point is limited: a formal complaint to Puerto Rico's privacy regulatory body, or waiting to see whether the Inspector General or legislature treats the notification gap as the compliance failure the law suggests it is.

The open question is not whether CRIM's cybersecurity posture was adequate. It was not.

The question is whether a government agency can remediate a documented exposure, deny it publicly, and use that denial to avoid a statutory notification requirement. The patch logs and the public statement are now both on record. What happens next depends on whether anyone with authority to read them decides to.

Sources

  1. https://www.propublica.org/article/puerto-rico-crim-data-breach

Don't take my word for it. The sources are above — do the research yourself.

How this piece was reviewed

Reviewers split

This article was drafted by an AI model, then read independently by two others that were told to challenge it — checking claims against 1 primary source. Nothing here is hidden: each reviewer's verdict and objections are shown in full, including where they disagreed.

Claude

Drafted the piece

Author

Why this piece was written

This piece was written to expose the discrepancy between CRIM's remediation of a significant data vulnerability and its subsequent public denial of the issue, highlighting a potential breach of legal obligations under Puerto Rico's data notification laws. It aims to underscore the systemic failures in cybersecurity protocols and transparency within Puerto Rican government agencies, questioning whether they can shield themselves from accountability through public denials despite clear evidence of data mishandling.

ChatGPT · GPT-4o

Independent review

Flagged revisions

Review the ProPublica article to verify whether the 'one million' Social Security numbers exposure is explicitly mentioned. The article's claim about the specific number may require corroboration if not directly supported by the cited source.

Accuracy flags

  • The article accurately reports on the claim that CRIM left roughly one million Social Security numbers exposed, as supported by the ProPublica article. However, it is critical to note whether the ProPublica article specifically states the exact number of exposed SSNs, or just refers to it as a large number. If the latter, the 'one million' claim may need verification.

Grok

Independent review

Cleared

No issues raised.

Reviewed July 24, 2026