All Breaches
June 18, 2026 Verified Sensitive Record Government

Texas Parks and Wildlife Department 2026 Data Breach

The Texas Parks and Wildlife Department 2026 data breach is an incident in which unauthorized access at the third-party license-system vendor handling hunting and fishing license sales affected 3,087,721 customers. Texas Cyber Command detected the event, and the agency said driver's license information, passport numbers when provided, email addresses, phone numbers, and residential addresses may have been obtained.

TPWD's official security-incident notice is the primary source, while BleepingComputer independently reported the agency's statement and gave the affected-person total as 3,087,721. The official page describes the same scope as more than three million customers. LeakData records the exact figure reported from the agency data and does not import raw breach rows.

Where Did the Incident Occur?

The breach affected the license-system vendor that processes TPWD hunting and fishing license sales. The agency did not publicly name the third-party provider. This record therefore documents a vendor incident affecting Texas Parks and Wildlife Department customer data without presenting any particular software, cloud service, or company identity as confirmed.

Texas Cyber Command detected the unauthorized access and opened an investigation into its scope and impact. The public notice does not provide an initial-access date, attacker dwell time, exploited vulnerability, or exfiltration method. June 18, 2026 is the published update date on the official page and is not the technical start date of the attack.

Information That May Have Been Obtained

The investigation indicated that the attacker may have obtained driver's license information, passport numbers if supplied by the customer, email addresses, phone numbers, and residential addresses. These fields relate to Texas hunting and fishing license customers. A passport number was not necessarily required or present for every record; the agency explicitly limited it to information provided.

This combination can increase the risk of impersonation, targeted phishing, and fake official notices. Matching address and contact details with a driver's license or passport identifier can help an attacker create convincing scenarios. The record does not guess or add names, hunting-license numbers, or other fields that were not publicly disclosed.

Fields Confirmed as Unaffected

TPWD said Social Security numbers, dates of birth, and financial information, including credit-card details, were not obtained in the incident. The agency also said there was no evidence that customers under 18 were involved or that any particular group was specifically targeted. These exclusions come from the official investigative findings.

Confirming unaffected fields does not make the event insignificant; government-issued identifiers such as driver's license and passport numbers remain sensitive. LeakData nevertheless preserves the verified boundary and does not list Social Security numbers, birth dates, payment cards, or other financial data. The risk analysis is limited to the disclosed fields.

Affected-Person Count

BleepingComputer reported that 3,087,721 Texas hunting and fishing license customers were affected. TPWD's own page summarizes the same scope as more than three million customers. The two statements are consistent, and this record uses the published incident total instead of estimating a figure from the Texas population or annual license sales.

pwnCount represents people, not a total of accessed files, rows, documents, or data fields. Multiple licenses or contact records belonging to one customer are not independently multiplied as people. Because the sources describe the figure as customer scope, LeakData uses 3,087,721 while providing no downloadable breach dataset.

TPWD's Response

TPWD said it began working with the license-system vendor to deploy new safeguards and enhanced monitoring. Access controls protecting customer-profile data were strengthened immediately, and additional security features were planned. The agency said August license sales and the following license year would continue on schedule.

Affected customers were offered one year of free credit monitoring through Kroll. The agency advised monitoring credit reports and financial accounts, remaining alert to suspicious communications, and considering a credit freeze or fraud alert when appropriate. This service does not mean financial data was stolen; it is a precaution against secondary identity risk.

How to Interpret This LeakData Record

This record does not cover every driver's license holder in Texas or all state-government systems. The affected population consists of customers who bought hunting and fishing licenses through TPWD's third-party license system. Discovery by Texas Cyber Command does not imply that the entire Texas state network was the breached environment.

The verified conclusion is that an unauthorized actor at a license-system vendor may have obtained driver's license information, some passport numbers, and contact and address data for 3,087,721 TPWD customers. Social Security numbers, birth dates, financial data, under-18 customer impact, and targeting of a specific group were not confirmed; the vendor identity and technical attack method were not disclosed.

3.1 Million
Affected Accounts
5
Data Types
Critical
Severity
Yes
Verification

Exposed Data Types

5
Driver's license information
Passport numbers if provided
Email addresses
Phone numbers
Residential addresses

Additional Information

Added DateJuly 27, 2026
Breach DateJune 18, 2026
Domaintpwd.texas.gov
SourceThird-party hunting and fishing license system breach
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information