CSIDB logo
Incident

State Bar of Texas

Incident posture

Attack window
Jan 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 18:40

Linked entities

Victim
State Bar of Texas
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jan 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The State Bar of Texas, the second-largest bar association in the United States with over 100,000 licensed attorneys, reported a data breach after unauthorized access to its network. The intrusion, which occurred over several weeks, allowed threat actors to exfiltrate files including legal case documents, and the INC ransomware gang later claimed responsibility and posted samples of the alleged data on its extortion site.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

The State Bar of Texas is the second-largest bar association in the United States, with over 100,000 licensed attorneys. It regulates the legal profession in Texas by overseeing licensing, continuing legal education, ethical compliance, and disciplinary actions. In a notification letter sent to affected members, the organization states that it suffered a security breach between January 28 and February 9, 2025. The breach was only discovered on February 12, 2025. Through the investigation, the State Bar determined that there was unauthorized access to its network during that period. During the unauthorized access, the actor was able to take certain information from the network. The notice does not provide much information about the hacking group responsible for the breach.

On March 9, 2025, the INC ransomware gang claimed an attack against the State Bar of Texas by adding the organization to its dark web extortion page. The threat actors have already leaked samples of allegedly stolen files, including legal case documents. BleepingComputer could not verify if the leaked data came from the organization's networks or whether the information was private or publicly available. The State Bar's notification letter informed recipients of the breach and the potential exposure of their data.

As part of its response, the State Bar offered affected members free-of-charge credit and identity theft monitoring service coverage through Experian. Enrollment in the monitoring service was made available until July 31, 2025, using an activation code enclosed in the notification. BleepingComputer's inquiry to the State Bar of Texas regarding the incident has so far gone unanswered. No further details about containment, eradication, or recovery efforts were disclosed in the available sources.

Sources

Sources available to members: 1 source.

CSIDB