Legal Updates for Privacy and Data Security
Vendor Cyber Attack Compromises PII of More Than 3 Million Hunting and Fishing License Holders in Texas
June 30, 2026
The Texas Parks & Wildlife Department (TPWD) announced earlier this month that one of its vendors which handles the sale of state hunting and fishing licenses was the victim of a cybersecurity attack. The threat actor appears to have exfiltrated personal driver’s license information, passport numbers, email addresses, phone numbers and addresses of over 3 million hunting and fishing license holders.
The State Parks Department advised that the attack did not compromise social security numbers, dates of birth or financial information. Texas Cyber Command, the state’s new cybersecurity authority formed to protect critical infrastructure and coordinate threat responses across state and local government, reportedly assisted in detecting and containing the attack.
TPWD has already set up free credit monitoring for those impacted through Kroll. According to press reports, no specific group has yet been identified as the perpetrator of the theft. TPWD also advised that business has not been interrupted and license sales were continuing.
This incident once again demonstrates that cybersecurity is only as strong as the weakest link in the supply chain. Businesses must prioritize security across their own environments and those of their vendors and contractors as well.
