Policy & Regulation
Texas Parks & Wildlife reports data breach affecting 3 million
A data breach at Texas Parks & Wildlife has exposed the driver’s license and passport information of more than 3 million people, according to the state attorney general.
The Texas Parks & Wildlife department, a Texas state government department, has confirmed that its cybersecurity unit recently detected a security incident. According to the Texas Attorney General, the state’s legal official who reported the details of the breach, this security incident resulted in a data breach that allowed hackers to access and take the driver’s license information and passport numbers of more than 3 million people.
The department disclosed the details of the incident in a data breach notice published on its official website. The state’s cybersecurity unit, which is the state agency responsible for digital security, recently detected the unauthorized access. According to the department’s notice, the security incident allowed hackers to gain access to the systems of its license system vendor. This third-party contractor is responsible for handling the digital sales of hunting and fishing licenses for the state department, making it a critical point of access for sensitive user data.
The compromised information includes highly sensitive personal identifiers alongside standard contact details. According to Texas Parks & Wildlife, the data breach exposed the following information belonging to the affected license holders:
- Driver’s license numbers
- Passport numbers
- Residential addresses
- Phone numbers
- Email addresses
This incident stands as one of the largest data breaches to affect the state of Texas this year, highlighting the ongoing vulnerabilities associated with third-party contractors handling state data. The Texas Parks & Wildlife department did not specify the exact nature of the security incident, nor did it disclose when the breach occurred. Additionally, the department did not name the license system vendor that was compromised. TechCrunch reported that the department did not respond to requests for comment regarding the incident, including whether the department has received any outreach or communication from the hackers.
Why it matters
This incident underscores the persistent vulnerability of state-level government infrastructure to cyberattacks, particularly regarding the security of third-party vendors handling sensitive citizen data. As government agencies increasingly rely on external contractors to manage public services, securing these supply chains remains a critical challenge for public-sector cybersecurity.