A cyberattack forced Puerto Rico’s Department of Transportation to cancel all upcoming appointments for driver’s licenses, permits, and vehicle registrations after affected systems tied to the Centros de Servicios al Conductor (CESCO) were taken offline. The incident was detected by a security monitoring system, prompting the Puerto Rico Innovation and Technology Service (PRITS) to activate incident response protocols and work with transportation officials to contain the attack and restore services.
Officials said the attack was stopped and that there is currently no evidence of data theft, but services remain unavailable while technical testing continues. The disruption directly affected public-facing government operations and adds to a broader pattern of cyber incidents that have recently impacted Puerto Rico’s public sector, including prior ransomware-related disruptions.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
Following the attack, Puerto Rico's Department of Transportation canceled all upcoming appointments for driver's licenses, permits, and vehicle registrations at CESCO. Officials said the attack had been stopped, there was no current evidence of data theft, but services remained unavailable pending technical testing.
Puerto Rico officials said a security monitoring system discovered a cyberattack on Monday affecting systems tied to the Department of Transportation and driver services. Incident response protocols were activated, affected systems were disconnected, and technical teams began working to contain the incident and restore services safely.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.