State Bar of Texas
Incident posture
Linked entities
- Victim
- State Bar of Texas
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
The State Bar of Texas, the second-largest bar association in the United States with over 100,000 licensed attorneys, reported a data breach after unauthorized access to its network. The intrusion, which occurred over several weeks, allowed threat actors to exfiltrate files including legal case documents, and the INC ransomware gang later claimed responsibility and posted samples of the alleged data on its extortion site.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
The State Bar of Texas is the second-largest bar association in the United States, with over 100,000 licensed attorneys. It regulates the legal profession in Texas by overseeing licensing, continuing legal education, ethical compliance, and disciplinary actions. In a notification letter sent to affected members, the organization states that it suffered a security breach between January 28 and February 9, 2025. The breach was only discovered on February 12, 2025. Through the investigation, the State Bar determined that there was unauthorized access to its network during that period. During the unauthorized access, the actor was able to take certain information from the network. The notice does not provide much information about the hacking group responsible for the breach.
On March 9, 2025, the INC ransomware gang claimed an attack against the State Bar of Texas by adding the organization to its dark web extortion page. The threat actors have already leaked samples of allegedly stolen files, including legal case documents. BleepingComputer could not verify if the leaked data came from the organization's networks or whether the information was private or publicly available. The State Bar's notification letter informed recipients of the breach and the potential exposure of their data.
As part of its response, the State Bar offered affected members free-of-charge credit and identity theft monitoring service coverage through Experian. Enrollment in the monitoring service was made available until July 31, 2025, using an activation code enclosed in the notification. BleepingComputer's inquiry to the State Bar of Texas regarding the incident has so far gone unanswered. No further details about containment, eradication, or recovery efforts were disclosed in the available sources.
Sources
Sources available to members: 1 source.