Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
A cybersecurity incident involved the vendor that handles Texas Parks and Wildlife Department hunting and fishing license sales. [2]
Impact
Potential acquisition of identity-document and contact information belonging to license customers. [2]
Documented data types include:
- Contact information — Email addresses, phone numbers, and residential addresses. [1][2]
- Passport numbers — Passport numbers if provided. [1][2]
- Names — Reported in Texas Attorney General report BR-0005135; the first-party page does not separately enumerate names. [1][2]
- Driver’s license numbers [1][2]
A cited record reports 3,087,721 individuals (Texans affected according to Texas Attorney General report BR-0005135; as of 2026-06-26). [1][2]
A cited record reports 3,187,000 individuals (Total individuals affected field in Texas Attorney General report BR-0005135; distinct from the Texas-resident count; as of 2026-06-26). [1][2]
TPWD’s current notice says financial information, including credit-card details, was not obtained. [2]
Timeline
Discovery
Detection date in Texas Attorney General report BR-0005135.
[1]Documented event
First-party public notice validity date; the Texas regulator later published report BR-0005135 on June 26.
[2]Public disclosure
The first-party page metadata makes the incident notice valid from June 18, 2026.
[2]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
TPWD offered affected customers one year of Kroll credit monitoring with a September 14, 2026 enrollment deadline. TPWD said license sales would continue on schedule for August and the next license year. TPWD reported no evidence that customers under 18 were involved or that a specific group was targeted. TPWD reported that the incident involved its unnamed license-system vendor, which handles hunting and fishing license sales. TPWD’s investigation indicated that an unauthorized actor may have obtained customer identity-document and contact information. TPWD reported implementing additional safeguards and monitoring and strengthening access controls for customer-profile data. The evidence ledger retains 2 disputed claims with the original citations rather than silently resolving the conflict. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]
