A breach at a third-party vendor exposed data belonging to more than three million holders of Texas hunting and fishing licences, reported in June 2026.
A recreational licence sounds like a low-sensitivity record. The application behind it is not: issuing one requires identity verification, address, date of birth and frequently payment details — the same set as anything else a state issues.
Compelled Disclosure, Delegated Custody
A person who wants to fish legally must supply this information to the state. They cannot negotiate the fields, decline collection, or select which vendor operates the system. The state procured that vendor, under a contract the licence holder never saw.
This is the same structure filed in 26-0731 and 26-0527, arriving from a third direction. Where collection is compelled and custody is delegated, the affected person has no lever at any point in the chain.
Low-Prestige Systems Get Low-Prestige Security
Government security attention follows perceived sensitivity, which is a reasonable heuristic that fails in a specific way: the identity fields are identical across systems, but a recreational licensing platform will not attract the scrutiny given to a benefits or tax system.
The data does not know which system it is in. Three million identity records are three million identity records whether the application was for a tax refund or a fishing permit.
Compiled from public reporting, listed below. The vendor and the access route have not been consistently identified and we are not naming either. Corrections: corrections@forensicpost.com.
- List of recent data breaches in 2026Bright Defense