The TPIS Industrial Services 2026 data breach was an incident affecting company systems on March 19–20, 2026 and involving information about 2,359 people, according to the Texas Attorney General. The official record says 2,123 of those people were Texas residents and that notice was provided by U.S. mail.
The Texas filing lists names, addresses, Social security numbers, driver’s license numbers, medical information, and health insurance information as involved data types. The incident was discovered on June 16, 2026, and the regulator published its record on July 17, 2026. The public entry does not explain whether the categories varied from person to person.
How Was the TPIS Industrial Services Breach Confirmed?
The primary source is Texas Attorney General data security breach record BR-0005179. It identifies the company as TPIS Industrial Services, Inc. at its Pasadena, Texas address and publishes the start and end of the breach, discovery date, notification method, affected data categories, Texas resident count, and nationwide total in separate fields.
The second source is ClaimDepot’s incident summary. It reports the 2,123-person Texas count and official data fields and says the PLAY ransomware group listed TPIS on its leak site on March 26, 2026. The company’s official website independently confirms the entity, Pasadena office, and industrial-services business. This entry relies on the Texas regulator—not a threat-actor claim—for the affected population and confirmed data types.
What Happened on March 19–20, 2026?
The notice submitted to the Texas Attorney General gives March 19, 2026 as the breach start and March 20 as the end. The public record says the event was discovered on June 16, but does not disclose the initial access method, whether access was strictly limited to those two days, which systems were involved, or when the investigation was completed.
ClaimDepot says PLAY claimed on March 26 that it had obtained TPIS data and intended to publish it. That date is six days after the breach period in the regulatory record and is temporally consistent with the incident. A criminal group’s statement is not an independent forensic finding, however, so this entry does not conclude that every claimed file was taken, published, or verified.
What Personal and Health Information Was Involved?
The verified categories in the Texas record are an individual’s name, address, Social Security number, driver’s license number, medical information, and health insurance information. The filing does not mark birth dates, passports, payment cards, bank accounts, email passwords, or user accounts as affected fields, and the threat actor’s broader claims are not added to the official list.
A Social Security number and driver’s license number can support impersonation or attempts to open new accounts. Address, medical, and insurance details can also make targeted phishing appear consistent with a real employment or treatment context. Not every recipient necessarily had all six categories in the affected material; an individual notification letter is the controlling source for that person’s specific exposure.
What Does the PLAY Ransomware Claim Mean?
ClaimDepot reports that PLAY’s dark-web post claimed access to private and confidential data, client documents, budgets, payroll information, identification, tax records, and financial information. That is the attacker’s allegation and does not carry the same evidentiary weight as the fields published by the Texas Attorney General. The ransomware connection is therefore presented as context without treating every claimed category as confirmed.
The official filing does not say whether a ransom was paid, whether malware encrypted systems, whether data samples were ultimately released, or whether the company communicated with the threat actor. The public evidence confirms a real breach and mailed consumer notifications, but it does not describe the rest of the technical attack chain, so the missing details are not filled by inference.
How Is the Total of 2,359 People Calculated?
The Texas Attorney General portal provides two distinct numbers: 2,123 affected people in Texas and 2,359 affected people across the United States. Those values indicate that at least 236 affected people were outside Texas. ClaimDepot’s approximate “2k” headline and its 2,123 figure refer to the Texas subset, not the nationwide population.
The displayed total is consequently 2,359, taken from the official field labeled “Total Number of Individuals Affected.” The Texas count remains visible in the explanation but is not added again. If the regulator later amends its entry, the population and data categories can be reviewed; on the present evidence, 2,359 is the exact published overall total.
What Should Affected People Do?
A recipient should check the TPIS letter for the data fields that apply to them and any enrollment deadline attached to offered assistance. If a Social Security number or driver’s license number was involved, review credit reports, consider a free fraud alert or credit freeze, and monitor the relevant government identity account for an unexpected change.
People whose notices identify medical or health insurance information can review explanation-of-benefits statements and health accounts for an unfamiliar service, provider, or claim. Do not disclose a password, payment detail, or one-time code in an unexpected message using the TPIS, insurer, or assistance-provider name. Direct questions through a contact channel independently verified in the letter or on the company’s current official website.