Item 8.01 Other Events
On May 13, 2026, EVERTEC, Inc. ("Evertec" or the "Company") learned of potential unauthorized access to customer data. The Company promptly initiated its cyber incident response protocols to contain the intrusion, assess and investigate the nature and scope of the incident, and implement appropriate remedial measures. The Company also notified federal law enforcement authorities and engaged external cybersecurity experts to assist in the investigation and response efforts. While the full scope of impacted data remains under forensic investigation and is subject to change as the assessment continues, at this time the Company believes that an unauthorized party obtained, through a third-party support platform, certain of our financial institution clients' information related to transaction records, payment card numbers of some customers and, in some instances, customer names and contact information. Based on our current understanding, the Company believes that the incident has primarily impacted our financial institution clients in Puerto Rico and their respective customers. The Company has taken steps to contain the incident and secure our systems, and believes that the unauthorized party no longer has access to the third-party support platform. The Company also is communicating with affected financial institutions and providing support as it continues to assess the full scope of impacted information.
To date, this incident has not resulted in operational disruption or interruption in service to any customers. While the investigation remains ongoing, as of the date of this filing, the Company has not yet determined the full impact of the incident. Among other things, the Company expects to incur expenses related to the investigation and remediation of this matter. Although the Company maintains cybersecurity insurance, it has not yet determined the extent of any potential liabilities associated with this matter or the applicability of insurance coverage.