Kaufman County, Texas, experienced two separate cybersecurity incidents in October, with the most recent attack confirmed on October 20. County officials acknowledged that personal information, including names and Social Security numbers, may have been accessed during the earlier breach, prompting notifications to affected residents and the offer of complimentary identity protection services. While there is no evidence of misuse of the compromised data, concerns have been raised about the adequacy of the county's cybersecurity measures following these repeated incidents.
The latest cyber intrusion resulted in the shutdown of various county systems, including courthouse computers, though emergency services and the Sheriff's Office remained operational. These attacks on Kaufman County occurred alongside other cyber incidents affecting government services in Tennessee and Indiana, highlighting a broader trend of increased cyber threats to local governments amid reduced cybersecurity resources and support at the federal level.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
Following confirmation of the second breach, Kaufman County notified affected residents through Cyberscout and offered 24 months of complimentary identity-protection services via TransUnion. Officials said there was no evidence of misuse at the time and advised residents to monitor their credit reports.
A second, separate cybersecurity incident affecting Kaufman County was confirmed on October 20, 2025. County officials indicated that personal information, including names and Social Security numbers, may have been accessed.
Kaufman County, Texas, experienced an initial cybersecurity incident in early October 2025, the first of two separate attacks reported within a three-week span. Public reporting does not identify the threat actor or attack method for this first incident.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.