---
title: "Texas Parks and Wildlife license-vendor data incident"
description: "Evidence-backed account of Texas Parks and Wildlife license-vendor data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/texas-parks-wildlife-license-vendor-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/texas-parks-wildlife-license-vendor-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/texas-parks-wildlife-license-vendor-data-incident-2026/stix.json"
---

# Texas Parks and Wildlife license-vendor data incident

Cybersecurity incident involving the vendor that handles Texas hunting and fishing license sales. Potential acquisition of identity-document and contact information belonging to license customers.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

A cybersecurity incident involved the vendor that handles [Texas Parks and Wildlife Department](https://tpwd.texas.gov/) hunting and fishing license sales. [2](#source-2)

## Impact

Potential acquisition of identity-document and contact information belonging to license customers. [2](#source-2)

Documented data types include:

- Contact information — Email addresses, phone numbers, and residential addresses. [1](#source-1) [2](#source-2)
- Passport numbers — Passport numbers if provided. [1](#source-1) [2](#source-2)
- Names — Reported in Texas Attorney General report BR-0005135; the first-party page does not separately enumerate names. [1](#source-1) [2](#source-2)
- Driver's license numbers [1](#source-1) [2](#source-2)

A cited record reports 3,087,721 individuals (Texans affected according to Texas Attorney General report BR-0005135; as of 2026-06-26). [1](#source-1) [2](#source-2)

A cited record reports 3,187,000 individuals (Total individuals affected field in Texas Attorney General report BR-0005135; distinct from the Texas-resident count; as of 2026-06-26). [1](#source-1) [2](#source-2)

TPWD's current notice says financial information, including credit-card details, was not obtained. [2](#source-2)

## Timeline

### May 13, 2026 — Discovery

Detection date in Texas Attorney General report BR-0005135. [1](#source-1)

### June 18, 2026 — Documented event

First-party public notice validity date; the Texas regulator later published report BR-0005135 on June 26. [2](#source-2)

### June 18, 2026 — Public disclosure

The first-party page metadata makes the incident notice valid from June 18, 2026. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

TPWD offered affected customers one year of Kroll credit monitoring with a September 14, 2026 enrollment deadline. TPWD said license sales would continue on schedule for August and the next license year. TPWD reported no evidence that customers under 18 were involved or that a specific group was targeted. TPWD reported that the incident involved its unnamed license-system vendor, which handles hunting and fishing license sales. TPWD's investigation indicated that an unauthorized actor may have obtained customer identity-document and contact information. TPWD reported implementing additional safeguards and monitoring and strengthening access controls for customer-profile data. The evidence ledger retains 2 disputed claims with the original citations rather than silently resolving the conflict. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/texas-parks-wildlife-license-vendor-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Data Security Breach Reports — 2026 public records

regulatory · Office of the Attorney General of Texas

<https://www.texasattorneygeneral.gov/consumer-protection/data-breach-reporting>

<a id="source-2"></a>

### Notification of Data Security Incident

official · Texas Parks and Wildlife Department

<https://tpwd.texas.gov/about/notification-of-data-security-incident>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Affected Individual Count · 100% confidence · current**  
   Texas hunting and fishing license customer data exposure: 3,087,721 individual
2. **Resulted In · 100% confidence · current**  
   Texas hunting and fishing license customer data exposure: TPWD's current notice says financial information, including credit-card details, was not obtained.
3. **Resulted In · 100% confidence · current**  
   2026 TPWD license-system vendor incident: TPWD offered affected customers one year of Kroll credit monitoring with a September 14, 2026 enrollment deadline.
4. **Resulted In · 100% confidence · current**  
   2026 TPWD license-system vendor incident: TPWD public and affected-customer notification
5. **Affected Organization · 100% confidence · current**  
   2026 TPWD license-system vendor incident: Texas Parks and Wildlife Department
6. **Resulted In · 100% confidence · current**  
   2026 TPWD license-system vendor incident: TPWD said license sales would continue on schedule for August and the next license year.
7. **Occurred At · 100% confidence · current**  
   TPWD public and affected-customer notification: 2026-06-18
8. **Disclosed At · 100% confidence · current**  
   2026 TPWD license-system vendor incident: 2026-06-18
9. **Resulted In · 100% confidence · current**  
   2026 TPWD license-system vendor incident: TPWD reported no evidence that customers under 18 were involved or that a specific group was targeted.
10. **Affected Individual Count · 100% confidence · current**  
   Texas hunting and fishing license customer data exposure: 3,187,000 individual
11. **Resulted In · 100% confidence · current**  
   2026 TPWD license-system vendor incident: Texas hunting and fishing license customer data exposure
12. **Exposed Data Category · 100% confidence · disputed**  
   Texas hunting and fishing license customer data exposure: Dates of birth
13. **Exposed Data Category · 100% confidence · current**  
   Texas hunting and fishing license customer data exposure: Contact information
14. **Resulted In · 100% confidence · current**  
   2026 TPWD license-system vendor incident: TPWD reported that the incident involved its unnamed license-system vendor, which handles hunting and fishing license sales.
15. **Exposed Data Category · 100% confidence · current**  
   Texas hunting and fishing license customer data exposure: Passport numbers
16. **Resulted In · 100% confidence · current**  
   Texas hunting and fishing license customer data exposure: TPWD's investigation indicated that an unauthorized actor may have obtained customer identity-document and contact information.
17. **Resulted In · 100% confidence · current**  
   2026 TPWD license-system vendor incident: TPWD reported implementing additional safeguards and monitoring and strengthening access controls for customer-profile data.
18. **Discovered At · 100% confidence · current**  
   2026 TPWD license-system vendor incident: 2026-05-13
19. **Exposed Data Category · 100% confidence · current**  
   Texas hunting and fishing license customer data exposure: Names
20. **Exposed Data Category · 100% confidence · current**  
   Texas hunting and fishing license customer data exposure: Driver's license numbers
21. **Exposed Data Category · 100% confidence · disputed**  
   Texas hunting and fishing license customer data exposure: Social Security numbers

</details>
