TPWD Vendor Breach Exposes License Data
Coverage from Federman & Sherwood and others
Articles
65
Active Days
58
The Topic

Texas Parks and Wildlife Department reported that a cybersecurity incident at an unnamed third-party license-system vendor may have exposed personal information belonging to more than 3 million hunting and fishing license customers. The affected data may include driver’s license and passport information, email addresses, phone numbers, and residential addresses, while the department said there was no evidence that Social Security numbers, dates of birth, or payment information were accessed. TPWD and the vendor are strengthening access controls and monitoring, while affected individuals are being advised to watch for fraud and use offered credit-monitoring services.
First Article: 05/28/26
Latest Article: 07/24/26
Summary
- Texas Parks and Wildlife’s license-system vendor was breached, potentially affecting more than 3 million customers.
- Potentially exposed information includes driver’s license details, passport numbers, email addresses, phone numbers, and home addresses.
- TPWD reported no evidence that Social Security numbers, dates of birth, credit-card data, or other financial information were accessed.
- Texas Cyber Command detected the incident; the vendor’s identity, attacker, and precise incident timing remain undisclosed.
- The exposed contact and identification data could support phishing, impersonation, and social-engineering attempts.
- TPWD and the vendor are adding access controls, monitoring, and other safeguards; affected customers were offered one year of credit monitoring.
History
The update mainly sharpens the TPWD breach details: the vendor remains unnamed, but Texas Cyber Command is now explicitly tied to detection and the exposed data list is more specific. It also reframes the response as active mitigation, with TPWD and the vendor adding safeguards and offering credit monitoring.
The story has broadened from a single TPWD vendor breach to a second, separate Texas-related breach at Questo, shifting the focus from one large government-service exposure to a wider vendor-risk pattern affecting both public and consumer platforms. The TPWD incident also picked up more precise scope and access details, including the unnamed vendor and the specific data types not accessed.
