Desk live·
ForensicPost
Breaches/Public sector/File 26-0628

Texas Parks and Wildlife Vendor Breach Exposed Three Million Licence Holders

A third-party vendor breach exposed data for more than three million Texas hunting and fishing licence holders. Recreational permits carry the same identity fields as anything else a state issues.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetTexas Parks and Wildlife
ActorUnattributed
D. Kennedy7 min readConfidence: medium1 source reviewed

A breach at a third-party vendor exposed data belonging to more than three million holders of Texas hunting and fishing licences, reported in June 2026.

A recreational licence sounds like a low-sensitivity record. The application behind it is not: issuing one requires identity verification, address, date of birth and frequently payment details — the same set as anything else a state issues.

Compelled Disclosure, Delegated Custody

A person who wants to fish legally must supply this information to the state. They cannot negotiate the fields, decline collection, or select which vendor operates the system. The state procured that vendor, under a contract the licence holder never saw.

This is the same structure filed in 26-0731 and 26-0527, arriving from a third direction. Where collection is compelled and custody is delegated, the affected person has no lever at any point in the chain.

Low-Prestige Systems Get Low-Prestige Security

Government security attention follows perceived sensitivity, which is a reasonable heuristic that fails in a specific way: the identity fields are identical across systems, but a recreational licensing platform will not attract the scrutiny given to a benefits or tax system.

The data does not know which system it is in. Three million identity records are three million identity records whether the application was for a tax refund or a fishing permit.

How we reported this

Compiled from public reporting, listed below. The vendor and the access route have not been consistently identified and we are not naming either. Corrections: corrections@forensicpost.com.

Sources
  1. List of recent data breaches in 2026Bright Defense
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary