State Government: In 2025, the Texas Department of Information Resources reported that its cyber operations and statewide partners blocked more than 1 trillion unwanted communication attempts and added more than 17 million indicators of compromise to defensive
tools protecting state systems. Texas has since established the Texas Cyber Command to centralize statewide cybersecurity operations, incident response, threat intelligence, and digital forensics.
Texas state agencies are not immune to cyber threats. In 2025, Texas cybersecurity operations and statewide partners reported blocking
enormous volumes of malicious and unwanted network activity while continuing to expand statewide threat detection, incident response, and digital-forensics capabilities.
One of the most significant recent examples involved the Texas Parks and Wildlife Department (TPWD). Texas Cyber Command detected a cybersecurity incident involving the third-party vendor responsible for
TPWD’s hunting and fishing license system. According to TPWD, an unauthorized actor may have obtained personal information belonging to more than 3 million Texas hunting and fishing license customers. Potentially compromised information included driver license information, passport numbers when provided, email
addresses, telephone numbers, and residential addresses. TPWD stated that Social Security numbers, dates of birth, and financial information—including credit-card details—were not obtained in the
incident.
The incident is especially important for law-enforcement training because it demonstrates how a cyberattack against a government contractor or technology vendor can expose millions of citizens even
when the government agency itself is not the initial point of compromise. TPWD reported strengthening access controls, enhancing monitoring, and working with the vendor to implement additional safeguards following the incident.
More than 3 million Texans potentially affected by one government related cyber incident. Cities & Municipal Government: In February 2025, ransomware encrypted the City of Mission's entire computer network and backup servers, affecting every city department and temporarily preventing access to records including police reports, birth certificates, contracts, and personnel files. Later that year, the City of Greenville reported that
ransomware left it unable to access police and other government records.
County Government: The Texas Association of Counties reported in early 2026 that 85% of cyber claims within its Risk Management Pool involved business email compromise, while another 7% involved ransomware. Cyber claims were also on track in 2025 to exceed the
previous year's peak. One 2025 business-email-compromise attack against Nueces County involved nearly $2 million in fraudulent transactions, although officials expected much of the money to be
recovered. Texas Schools: In 2025, the Texas Attorney General reported that the PowerSchool breach exposed information belonging to more than 880,000 Texas school-aged children and teachers. In 2026, Alamo
Heights ISD disclosed a separate cyberattack affecting more than 26,000 individuals. College Campuses: Higher education remains in the threat environment as well. During the 2026 Canvas/Instructure incident, Texas institutions affected through the shared technology-provider pathway included UTSA, Alamo Colleges District, Texas State University, Baylor University, and the University of the Incarnate Word.
The University of Texas Regional Security Operations Center noted that third-party and vendor compromises remain a significant exposure for Texas higher education. Hospitals & Healthcare: Federal HHS breach records continue to document hacking incidents against Texas healthcare organizations. A 2025 hacking/IT incident involving Doctors Hospital at Renaissance was reported to HHS, while 2026 reports included incidents affecting
62,150 individuals at Blue Fish Pediatrics and 29,774 at the Texas Hearing Institute. Sabine County Hospital also disclosed a 2025 email account compromise involving patient information. Banking & Financial Services: A cyber incident involving Frost Bank data was reported in 2026 as affecting approximately 191,848 Texans. Separately, Texas-based financial technology provider Marquis disclosed that its 2025 ransomware attack ultimately affected more than 672,000 people nationwide and disrupted services involving 74
banks, with more than half of those affected residing in Texas. Texas Businesses: A September 2025 phishing attack against Sugar Land-based Gulshan Management Services led to unauthorized network access and affected information associated with more than
377,000 customers and employees. The company operates gas stations, restaurant franchises, convenience-store operations, and related business services—an example of how one compromised
credential can affect a large customer and employee population. Private Citizens: The FBI's 2025 Internet Crime Report ranked Texas #2 in the nation for both reported cybercrime complaints and reported losses. Texans filed 97,912 complaints and reported approximately $1.826 BILLION in losses in 2025 alone. Texans age 60 and older accounted for 14,410 complaints and approximately $678.6
million in reported losses. Cryptocurrency-related complaints from Texas totaled 13,965, representing more than $1.016 billion in reported losses.
This is why cybercrime investigation cannot remain a specialty understood by only a handful of investigators.
Today's patrol officer, detective, financial-crimes investigator, intelligence officer, supervisor, prosecutor, and digital-forensics professional may encounter cyber evidence during almost any investigation—from fraud and identity theft to ransomware, cryptocurrency, phishing, business email compromise, account
takeover, online exploitation, and organized criminal activity. Cybercrime is no longer simply an IT problem—it is a public-safety, investigative, financial, and identity-theft issue that Texas law enforcement will increasingly encounter. Statistics reflect publicly reported complaints, incidents, breaches, or regulatory notices; actual cybercrime activity is likely higher because
not every incident is publicly reported.
REGISTER TODAY. Cybercrime is evolving. Our investigative capabilities must evolve with it.