CSIDB logo
Incident

Matagorda County

Incident posture

Attack window
Jan 2025
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-09-03 10:05

Linked entities

Victim
Matagorda County
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Jan 2025
Disclosed
Jan 2025
Resolved
Pending

Summary

Matagorda County officials declared a disaster after discovering a cyberattack that involved a virus affecting several internal systems and originated from an unauthorized access point disrupting various department operations. The breach was contained to internal networks with assistance from cybersecurity professionals, the Department of Public Safety Cybersecurity Division, the Texas Department of Emergency Management, the Department of Informational Services, and the FBI. While emergency services remained unaffected, online services were partially restored and drop boxes were set up for tax payments as in‑person transactions were suspended. Investigations continue into the source, and no hacking group has claimed responsibility.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Friday morning, Matagorda County, a Texas county located roughly an hour and a half from Houston and home to more than 37,000 residents, discovered a cybersecurity breach involving a virus that affected several internal systems. The breach was sourced to an unauthorized access point that impacted various departments and disrupted some operations. County officials, working with cybersecurity professionals, the Department of Public Safety Cybersecurity Division, the Texas Department of Emergency Management, and the Department of Informational Services, indicated that the breach appeared to be contained to internal county systems. Matagorda County Judge Bobby Seiferman subsequently issued a formal declaration of disaster in response to the security breach, and the county's Emergency Operation Center published a public statement warning of the incident. The FBI was also notified. While the exact technical nature of the intrusion was still being investigated, the incident was characterized as a virus-based attack rather than a publicly attributed ransomware deployment, and no hacking group had publicly claimed responsibility at the time of reporting.

In response to the disruption, the county took a series of operational and communicative actions over the following days. Judge Seiferman emphasized that officials were "taking this incident very seriously" and were "working around the clock with cybersecurity professionals to fully secure our systems and ensure the protection of sensitive information," while also committing to providing transparent updates as the situation evolved. Because in-person payments at government offices could not be conducted during the outage, the county arranged alternative methods for residents to meet pressing financial obligations; drop boxes were placed near the Matagorda County tax office to accept tax payments due at the end of January, and residents were instructed that they could mail in checks. Emergency services were not impacted by the incident, and officials stressed that the disruption was limited to internal county operations rather than public safety functions. By Sunday, the county reported that it had made progress in restoring some online services, signaling an incremental return of normal functionality as remediation efforts continued. The cause of the disruption remained under investigation at the time of the report, with authorities continuing to work alongside state and federal partners to determine how the unauthorized access was obtained and to ensure that affected systems were fully secured.

Sources

Sources available to members: 1 source.

CSIDB