HackMyIP
← Back to News
2026-06-19 BleepingComputer

Texas Vendor Breach Exposes 3M Driver's Licenses in TPWD Hack

Data BreachSupply ChainPrivacy

The Texas Parks and Wildlife Department (TPWD) disclosed a data breach at its external license system vendor on June 19, 2026, compromising the personal information of more than 3 million individuals. The intrusion was discovered by the Texas Cyber Command, which immediately launched an investigation to assess the scope of unauthorized access. TPWD stated that the threat actor may have obtained driver's license information, passport numbers, email addresses, phone numbers, and residential addresses tied to 3,087,721 hunting and fishing license customers, though Social Security numbers, dates of birth, and financial data such as credit card information were not impacted in the incident.

Although no financial credentials were leaked, the exposed PII set is more than sufficient for targeted phishing and social engineering campaigns. Attackers could craft convincing impersonation messages posing as TPWD or the unnamed license vendor to harvest further sensitive data or distribute malware. The agency emphasized that there is no evidence customers under 18 were involved and that no specific demographic group was targeted. TPWD is currently coordinating with the third-party provider to deploy new safeguards and enhanced monitoring services, though the vendor's identity has not yet been publicly confirmed.

Impacted individuals are being offered one year of free credit monitoring and are advised to place a credit freeze or fraud alert with the major credit bureaus. TPWD also urged customers to remain vigilant against phishing attempts and impersonation scams, particularly any communications claiming to originate from the agency or its vendor. Anyone concerned their email may have been exposed in this or similar incidents can verify exposure using the email breach checker on hackmyip.com, and should immediately rotate any credentials associated with compromised addresses.

As a precaution, affected users should run a password checker to evaluate the strength of their existing credentials and consider a full privacy checkup to identify other digital exposures that could be chained with the leaked data. Given the driver's license and passport number exposure, identity theft monitoring should be treated as a long-term priority rather than a temporary concern.

Source: BleepingComputer →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →