Key developments
Texas vendor breach exposes 3.1 million IDs
Security Boulevard’s John Kevin Hao reported that the Texas Parks and Wildlife Department disclosed unauthorized access at an external hunting and fishing license vendor affecting 3,087,721 customers. Potentially exposed data included driver’s license information, passport numbers, email addresses, phone numbers, and residential addresses; TPWD said Social Security numbers, dates of birth, and credit card data were not impacted. Tech Times reported the incident was detected by Texas Cyber Command, with TPWD notification on May 13, formal notice on June 12, and public disclosure on June 18.
Why it matters
Government-issued ID numbers are difficult to replace, making the breach a long-tail identity theft and vendor-risk event.
Sources & driving stories
SECURITY BOULEVARD · John Kevin Hao
Security Boulevard coverageTECH TIMES
Tech Times coverageSection 702 lapses after Congress stalls
The Plumbline reported that Section 702 of the Foreign Intelligence Surveillance Act was set to lapse at 12:01 a.m. after Congress failed to extend the warrantless foreign-intelligence collection authority. The immediate political trigger was opposition following President Trump’s move to temporarily install Bill Pulte as director of national intelligence. Legal experts disputed the operational impact because the Foreign Intelligence Surveillance Court recertified the program through March, but providers may face uncertainty over continued compliance with compelled data handovers.
Why it matters
The lapse reopens unresolved privacy questions over warrantless searches of Americans’ communications incidentally collected under foreign surveillance programs.
Sources & driving stories
THE PLUMBLINE
The Plumbline coverageNintendo employee data stolen through TinyPulse
Rescana reported that Nintendo of America confirmed on June 18 that internal employee survey data was stolen after a cyberattack on TinyPulse, a WebMD Health Services-owned SaaS employee engagement platform. Nintendo said its own systems were not accessed and customer or financial data was not compromised. The threat actor Shadowbyt3$ claimed about 1GB of data, including employee names, email addresses, survey and analytics data, bank statements, W-9 forms with employee IDs, progress plans, and reports from 2016 to 2026, and demanded $2 million.
Why it matters
The incident shows how HR SaaS platforms can expose sensitive employee records even when an organization’s internal network remains uncompromised.
Sources & driving stories
RESCANA
Rescana coverageWorth noting
WORTH NOTING
Google keyword warrant unsealed
Reclaim The Net’s Ken Macon reported that unsealed records show DOJ forced Google to identify 311 users who searched for political party office addresses around the January 2021 pipe-bomb investigation.
WORTH NOTING
Klue OAuth victim list grows
Databreaches reported that Klue confirmed theft of OAuth tokens tied to Salesforce integrations, with Huntress and ReliaQuest saying attackers abused Klue Battlecards integrations to steal CRM data from multiple organizations.
WORTH NOTING
California ALPR lawsuits accelerate
Mondaq reported that Bartholomew v. Parking Concepts and the California Supreme Court’s May 13 denial of review have triggered class actions against commercial automated license plate reader deployers facing $2,500 statutory damages per violation.
Still unclear
OPEN QUESTION
Will providers cooperate during the Section 702 lapse?
Court recertification may preserve legal cover, but the practical willingness of telecom and technology companies to continue compelled data handovers remains uncertain.
OPEN QUESTION
Who bears accountability for vendor-held sensitive data?
The Texas and Nintendo incidents both involved third-party systems, raising unresolved questions about vendor security controls, disclosure duties, and downstream identity-risk mitigation.
