More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
On June 18, Texas Parks and Wildlife Department (TPWD) revealed that attackers breached the systems of its hunting and fishing license vendor, exposing driver’s license numbers, passport numbers, email addresses, phone numbers and home addresses for 3,087,721 Texans. Passwords, credit cards and Social Security numbers were reportedly not taken, but conflicting filings suggest SSNs may have appeared in the data sent to the Texas Attorney General. TPWD won’t name the vendor, and investigators still don’t know how long the intruders had access or exactly when they broke in.
Threat intelligence firm Brinztech says the same hacker, known as “Wikkid,” offered a TPWD customer dataset on dark-web forums weeks before the public disclosure. Similar patterns have shown up in breaches of Virginia’s wildlife licensing system. A handful of software providers—Aspira Connect, PayIt Outdoors, Tyler Technologies—manage license sales for many states. If one platform is vulnerable, others could be too. No federal rule forces these vendors to meet a baseline security standard, and state contracts don’t always demand regular audits.
Under Texas law, TPWD had to notify the Attorney General within 30 days of discovering the breach and affected residents within 60 days. The department detected the breach around May 13, filed with the AG by June 12, and went public on June 18—meeting its deadlines. It also falls under the Texas Data Privacy and Security Act, but the AG hasn’t weighed in on whether the vendor’s security practices were “reasonable.”
Anyone who’s bought a Texas hunting or fishing license should enroll in TPWD’s free Kroll credit-monitoring service by September 14, 2026, and place a freeze on their credit with Equifax, Experian and TransUnion. Those steps help block new accounts from opening in your name and add an extra hurdle for identity thieves.
Questions about this article
No questions yet.