
THE Texas Parks and Wildlife Department announced on 19 June 2026 that a security incident at a third‑party vendor had exposed the personal information of over three million Texans, according to the department’s notice. The compromised data may include passport numbers, driver’s licence details, email addresses, phone numbers and residential addresses. The agency said that social security numbers and financial records were not affected.
The breach originated from a vendor that manages the sale of hunting and fishing licences for the department, allowing attackers to gain unauthorised access to the licence management system, as reported by Malwarebytes. Although the exact method of intrusion has not been disclosed, the incident did not involve any known software vulnerabilities, so no CVE identifiers are associated with the event. The exposed fields are limited to identity documents and contact details, with no evidence that banking information or social security numbers were taken.
TPWD first detected the activity on 19 June 2026 and the indicator of compromise persisted until 23 June 2026, according to timestamps supplied in the notice. No threat actor has been publicly linked to the incident, and the agency has not attributed the breach to any specific group. The event adds to a string of large‑scale data exposures in Texas, following earlier leaks of millions of driver records that prompted similar warnings about identity theft.
In response, the department is offering affected individuals one year of free credit monitoring and has advised them to consider placing a freeze on their credit files to prevent unauthorised new accounts. Users should also review their financial statements for irregularities and remain alert to phishing attempts that could reference the compromised data, as highlighted in SecurityAffairs’ coverage.
Organisations that rely on third‑party providers for critical services should review their vendor management programmes, ensuring that contracts enforce strict security standards and that access to sensitive systems is granted on a least‑privilege basis. Regular monitoring of vendor network traffic for anomalous behaviour can help detect intrusions early, a step that TPWD says it is taking together with its supplier.
The incident highlights the need for continuous oversight of supply chain risk, especially when personal identifiers such as passport and driver licence numbers are involved. While TPWD has strengthened access controls following the breach, affected residents are encouraged to enroll in the offered credit monitoring service and to update any passwords that may have been reused across online services.