A cyberattack targeting a vendor used by the Texas Parks and Wildlife Department exposed personal data tied to 3,087,721 hunting and fishing license customers, the agency confirmed. Texas Cyber Command detected the incident, in which an unauthorized actor may have obtained data from customer profiles including driver license information, passport numbers, home addresses and phone numbers. Social Security numbers, dates of birth and financial data — including credit card details — were not obtained.
What Was and Was Not Compromised
The breach hit a third-party vendor that handles the sale of hunting and fishing licenses for TPWD; the agency did not publicly identify the vendor. Exposed information may include customer names, phone numbers, home addresses and license-related details, as well as driver license and passport numbers. TPWD says there is no evidence that customers under 18 were affected, and no specific group appears to have been targeted.
Despite the absence of financial data, the exposed profile information carries meaningful risk. A scammer armed with a name, address, phone number and license details can construct a convincing impersonation of a state agency or license vendor, lowering a target's guard through apparent familiarity.
Agency Response and Ongoing Operations
TPWD moved immediately to strengthen access controls for customer profile data and is working with the license system vendor to add further safeguards and enhanced monitoring. In a statement, TPWD said it "recognized the seriousness of this issue" and noted that many of its own staff are hunters and anglers who were among those affected. The agency said it believes current and future customer data are not at risk.
License sales will proceed on schedule for August and the upcoming license year, according to TPWD.
Steps for Affected Customers
Affected customers are eligible for one year of free credit monitoring. Enrollment requires a call to the dedicated response line at 844-959-7123; the deadline is September 14, 2026. The call center operates Monday through Friday, 8 a.m. to 5:30 p.m. CT.
Beyond monitoring, security professionals advise placing a free credit freeze with each of the three major bureaus — Equifax, Experian and TransUnion — separately. A one-year fraud alert, filed with any one bureau, requires that bureau to notify the other two. Because driver license information may have been exposed, customers should also watch for notices about duplicate licenses, address changes or government benefit activity they did not initiate.
The breach underscores how routine government transactions accumulate personally identifiable data. A hunting or fishing license purchase generates enough profile detail — address, license type, identification numbers — to make targeted social engineering viable long after the transaction closes.