Texas Parks and Wildlife Data Breach Exposes Personal Data of 3 Million Hunting and Fishing License Holders

The Texas Parks and Wildlife Department (TPWD) has disclosed a data breach affecting more than three million individuals, stemming from a cyberattack on the third-party vendor that operates its hunting and fishing license system. The Texas Cyber Command identified the unauthorized access and conducted an investigation to assess the scope of the compromise. According to TPWD’s breach notification, the personal information of 3,087,721 customers who hold Texas hunting or fishing licenses may have been accessed by the threat actor.

The data potentially exposed includes driver’s license information, passport numbers, email addresses, phone numbers, and residential addresses. TPWD confirmed that Social Security Numbers, financial information, and credit card data were not affected. The department also stated there is no evidence that minors were among those impacted or that any specific demographic group was targeted. The identity of the third-party vendor has not been publicly disclosed; TPWD told BleepingComputer it had not yet provided a statement identifying the company.

This incident is a further illustration of the systemic risk posed by third-party vendors in government technology supply chains. While TPWD’s own systems were not directly breached, the combination of data types exposed — driver’s license numbers, passport details, home addresses, and contact information — is sufficient to enable convincing identity-based phishing campaigns, social engineering attacks, or identity fraud against affected individuals. Texas Game Wardens and hunting and fishing license holders represent a broad cross-section of the Texas population, meaning the potential impact on individuals is wide.

TPWD has advised affected customers to monitor their credit reports and financial accounts for unusual activity. Impacted individuals are eligible for one year of free credit monitoring through the department. The agency also recommends that customers consider placing a credit freeze or fraud alert with major credit bureaus, and warns them to remain alert to phishing emails or phone calls impersonating TPWD or other official entities. The department says it is working with the vendor to implement improved safeguards and enhanced monitoring following the incident.

Read the original report →