Texas Parks & Wildlife Department
Incident posture
Linked entities
- Victim
- Texas Parks & Wildlife Department
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
The Texas Parks & Wildlife Department experienced a breach of its third‑party vendor system that processes hunting and fishing license transactions, resulting in the exposure of driver’s license numbers, passport numbers, email addresses, phone numbers and residential addresses for over three million individuals. The incident was identified by the state’s cybersecurity unit and later disclosed publicly, with no evidence of malware, ransomware or specific threat actor involvement. Attackers gained unauthorized access to the vendor’s data repositories, extracting the personal information through a supply chain compromise. The exposed data increases the risk of identity theft, fraud and phishing for those affected.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On May 13, 2026, the Texas Parks & Wildlife Department notified Texas Cyber Command after discovering a breach involving an unnamed third-party vendor that processes hunting and fishing license transactions. The breach was initially identified by the state’s cybersecurity unit. On June 12, 2026, TPWD published a Notification of Data Security Incident. On June 18, 2026, the breach was publicly disclosed, confirming that over three million individuals were affected. The Texas Attorney General’s Office confirmed the requirement for public disclosure and notification to affected individuals. Additional technical and news coverage on June 19, 2026 corroborated the scope and impact of the breach.
The compromised data included driver’s license numbers, passport numbers, email addresses, phone numbers, and residential addresses of individuals who had purchased hunting and fishing licenses through the third‑party vendor system. No evidence of malware, ransomware, or specific threat actor attribution has been disclosed. Technical analysis indicates the attack vector was a supply chain compromise, classified as MITRE ATT&CK technique T1195, whereby the attacker gained unauthorized access to the vendor’s information repositories. The attacker’s actions corresponded to collection (T1213) and exfiltration (T1041 or T1030) of the stored personal data. No technical indicators of compromise such as file hashes, command‑and‑control infrastructure, or malware signatures have been published. The specific method of initial access—whether credential theft, vulnerability exploitation, or misconfiguration—has not been disclosed by TPWD or any reporting entity.
The breach impacted all license holders whose data was processed by the vendor during the period leading up to the incident, although the exact dates of compromise remain unspecified. Regulatory scrutiny followed, with the Texas Attorney General’s Data Security Breach Reports portal listing the breach and confirming the types of information compromised. TPWD’s notification to Texas Cyber Command and the subsequent public disclosure were part of the agency’s response to the incident. Law enforcement and regulatory bodies were engaged to support ongoing investigations and ensure compliance with breach notification requirements. No further details regarding containment, eradication, or specific remediation actions have been made publicly available.
Sources
Sources available to members: 1 source.