Texas Parks & Wildlife disclosed a data breach affecting more than 3 million people after the state’s cybersecurity unit detected unauthorized access involving the department’s license system vendor. The exposed data was tied to hunting and fishing license transactions and included driver’s license numbers, passport numbers, email addresses, phone numbers, and residential addresses, according to reporting and statements attributed to the Texas attorney general.
The agency said the intrusion involved a vendor system used to process license information, but it did not identify the vendor or disclose the exact timing or method of the compromise. Officials also did not say whether the attackers had contacted the department, leaving key questions unanswered as the incident stands as one of the largest reported data breaches affecting Texas this year.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A threat actor using the alias Shadowreaper was observed advertising the sale of what was claimed to be a full Texas Parks and Wildlife Department database exfiltration after the agency's breach disclosure. The listing, seen on June 23, 2026, included unverified claims of additional Social Security number, date-of-birth, and payment card data beyond what TPWD officially confirmed.
Texas Parks & Wildlife said affected Texas residents would receive one year of free credit monitoring through Kroll following the breach affecting hunting and fishing license customers. The agency also said it was strengthening access controls and network monitoring in response to the incident.
Texas Parks & Wildlife disclosed a data breach affecting more than 3 million people after unauthorized access involving the department's license system vendor was detected. Exposed data tied to hunting and fishing license holders included driver's license information, passport numbers, email addresses, phone numbers, and residential addresses.
Texas Parks and Wildlife said it notified Texas Cyber Command on May 13 after discovering a breach involving an unnamed third-party vendor tied to hunting and fishing license sales. The agency also said its investigation had not yet determined when the breach occurred.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
securitymagazine.com
Open sourcedarkwebinformer.com
Open sourcemalwarebytes.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcescworld.com
Open sourcetechcrunch.com
Open sourcetpwd.texas.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.