Texas Threat Intelligence

What We're Seeing
In the Field

Threat briefs, incident analysis, and attacker TTPs from CoreRecon's Texas SOC. Ungated. Updated with every major wave.

Vertical Threat Briefs

Eight Texas sectors.
One live threat picture.

Start with the intelligence stream for your industry, compare CoreRecon coverage, or request the gated PDF brief built for your operating environment.

Utilities

TX Utilities Cybersecurity 2026

Texas multi-utility operators (gas + electric + water combined MUDs, special utility districts, gas LDCs, multi-utility OES firms) face NERC CIP-002 through CIP-014 (CIP-008 IR plan tri-clock + CIP-014 physical security + CIP-013 supply-chain), AWIA §2013 Risk & Resilience Assessment + Emergency Response Plan on 5-yr cycle, TSA SD-Pipeline-2021-01D (top 100+ gas LDCs + LNG), 49 CFR Part 192/195 (gas distribution + transmission), EPA RRAN-aligned RRA/ERP, AWWA G430/J100/DWFR, RRC 16 TAC §3.70 pipeline damage prevention, TX PUC Substantive Rule §25.367 (96-hr electric cyber-incident clock to PUCT — concurrent with CIRCIA 72-hr for NERC-registered entities), TDPSA §541 (utility customer billing + usage data enumeration), Volt Typhoon IT/OT pre-positioning in U.S. energy + water since 2021 (CISA/NSA AA24-038A), Muleshoe TX water-tank overflow (Jan 2024, CyberArmyofRussia/Unitronics PLC), Halliburton TX $35M RansomHub (Aug 2024), Brazos Electric $2.1B Ch.11 (2021 aftermath), City of Dumas TX SCADA ransomware (Nov 2024). Shared-MSP / vendor-IT / AMI headend / SCADA recloser / GIS / customer-portal BEC attack surface. CoreRecon tri-clock parallel-narrative SOC deliverable at $89–$129/endpoint + $2,500+/mo Command tier with AWIA RRA/ERP authorship + CIP-014 audit support + CIP-013 supply-chain plan + TDPSA enumeration coverage. SDVOSB-certified, 30-min CIP-008 SLA, TX-resident analysts, federal-grant procurement eligible (DWSRF/BRIC/RUS/DOE OE-000).

96-hr + 72-hr
TX PUC §25.367 + CIRCIA concurrent clocks — TX electric utility tri-narrative reports in parallel after every CIP-008 IR event
UtilitiesNERC CIPAWIA
Dental Practices

TX Dental-TX Cybersecurity 2026

V54 Dental-TX anchor brief: MCNA Dental 8.9M records (TX Medicaid/CHIP dental administrator, 2023). Henry Schein BlackCat/ALPHV supply-chain (2023) — 1M+ records across Dentrix customer network, including TX practices. Change Healthcare 192M (Feb 2024). West Texas Oral Facial Surgery INC Ransom (Jun 2025). Pecan Tree Dental Grand Prairie TX — Sinobi variant confirmed Jan 2026. Professional Dental Alliance 170K+ via vendor phishing. Texas dental practices & DSOs face HIPAA Security Rule + TDPSA §541 + TX HB 300 (HSC Ch. 181) + TSBDE 22 TAC §108.7 record-retention four-layer compliance. DMS-attack surface: Dentrix / Eaglesoft / Open Dental / Curve Dental PMS credential paths, DSO multi-location shared-AD exposure, Weave / Demandforce patient-comms SaaS hijacking, DEXIS Imaging / Patterson file-server ACL gaps. Sentinel $89/ep, Fortress $129/ep, Command $2,500+/mo — SDVOSB-certified, TX-resident SOC, 30-min IR SLA. Includes V54 launch framing and the V54 Dental-TX gated-PDF CTA at /resources/threat-briefs/dental-practices.

8.9M records
MCNA Dental 2023 — TX Medicaid/CHIP dental administrator
DentalRansomwareHIPAA
Senior Living

TX Senior-Living-TX Cybersecurity 2026

V55 Senior-Living-TX anchor brief: Avamere Group 380,000+ records (ALPHV/BlackCat, 2023–2024, multi-state senior-living & SNF operator). Prospect Medical Holdings 1.3M records (Rhysida, 2023 — Texas-affiliated senior-care operations). Deer Oaks TX verified $225K ransom (2024, family-portal BEC pattern). Texas HHSC Medicaid breach (TX state-agency exposure path, 2024). Acuity Health 2.5M senior-care EHR supply-chain exposure (2024). Lifepoint Health TX senior-care multi-state breach (2024). Texas assisted-living facilities (ALFs), memory-care operators, and skilled-nursing facility (SNF) groups face five-layer compliance: HIPAA Security Rule + TX HSC §242 + TX HSC §247 (HHSC) + CMS Conditions of Participation (42 CFR §483) + TDPSA §541. Attack surface: MatrixCare / PointClickCare / American HealthTech credential paths, multi-facility shared-EHR-tenant segmentation gaps, family-portal BEC, MDS 3.0 eHR submission chain (CMS QIES ASAP), RUG score manipulation Medicare PDPM integrity, memory-care medication-management IoT devices. Sentinel $89/ep, Fortress $129/ep, Command $2,500+/mo — SDVOSB-certified, TX-resident SOC, 30-min IR SLA. Includes V55 launch framing and the V36 Senior-Living gated-PDF CTA at /resources/threat-briefs/senior-living.

380K records
Avamere Group — 380K records ALPHV/BlackCat (2023–2024, largest senior-living breach in U.S. history)
Senior LivingRansomwareHIPAA
Municipalities

TX Municipalities — CJIS v6.0 & SCADA

V56 Municipalities-TX anchor brief: City of Dallas Royal ransomware ($8.5M cost-recover, 2023 — CJI exposure triggering FBI notification). City of Mission / Borger / San Angelo Q4 2025 coordinated wave. Borger TX REvil-affiliate (2025, public works + utility systems). 22 municipalities hit by coordinated Q4 2025 ransomware campaign (collective $2.5M demand). Akbar 911-PSAP ransomware precedent (county 911 ComEx / CAD encryption). Muleshoe TX Unitronics PLC utility SCADA overflow (Jan 2024) re-applicable — most TX cities also run their own water/wastewater SCADA. Full four-track compliance pinch: FBI CJIS Security Policy v6.0 (auditing live Oct 2025; LEA audit enforcement Oct 1, 2027 deadline; 13 policy areas) + Tex. Gov't Code Ch. 552 (Texas Public Information Act breach liability + §552.136 PII exception) + Texas Business & Commerce Code §521.053 (TDPSA breach notification, 60-day clock) + federal CIRCIA 72-hr CISA reporting (where utility SCADA in scope). Attack surface: CJI admin plane (RMS/CAD/NCIC/III terminals), 911 CAD egress, city water/wastewater SCADA (DNP3/Modbus/Unitronics PLC), public-records-portal credential stuffing, citizen-payment BEC (utility billing / municipal court fines), SaaS scheduling platforms (the Mission TX 2025 vector). CoreRecon $89–$129/endpoint, $2,500+/mo Command tier, 30-min IR SLA, SDVOSB-certified, TX-resident analysts, CJIS-mapped SOC + offline CJI continuity playbook + TxDIR cooperative contracting posture. CTA at /v/municipalities-tx landing page.

22 municipalities
hit by coordinated Q4 2025 ransomware wave — CJIS v6.0 auditing live Oct 2025
MunicipalitiesCJISRansomware
Defense Contractors

TX Defense Contractors — ITAR & CMMC

Volt Typhoon (PRC state-sponsored) has pre-positioned inside the U.S. Defense Industrial Base since 2021 — Texas hosts the #2 US DIB and ~3,000 active TX defense suppliers per DoD OUSD(A&S) data. CMMC 2.0 32 CFR Part 170 Phase 2 enforcement begins November 2026. TX DIB ITAR §120–130 shop-floor angle: ITAR-tagged geometry on Solidworks / AutoCAD / Siemens NX / CATIA / Pro-E file servers represents the most frequent Volt Typhoon collection target — cyber exfiltration treated as a 22 CFR §127 unauthorized-export predicate. DFARS 252.204-7012 72-hr DIBNet clock from discovery (not detection) runs in parallel with a DDTC voluntary disclosure. DFARS 252.204-7021 makes CMMC certification a condition of award. DFARS 252.204-7019/7020 SPRS scoring ≤110 with 3-year refresh; DFARS 252.204-7020 sub-tier flow-down attaches prime CMMC + 22 CFR §127 exposure to Tier 2/3 ITAR incidents. NIST SP 800-171 Rev 2 — 110 controls across 14 families. False Claims Act qui tam exposure under 31 USC §§3729–3733 on unencrypted CUI per recent DoD cyber-fraud enforcement actions ($1.2M–$70M+ settlement range, 15–30% relator share). SDVOSB co-prime advantage counts toward DFARS 252.219-7003 SDVOSB utilization goals. CoreRecon $89–$129/endpoint, $2,500+/mo Command tier, 30-min IR SLA, SDVOSB-certified, TX-resident SOC, ITAR §120–130 DLP tagging on CAD/CAM file servers + DFARS 7012 72-hr disclosure workflow + DDTC voluntary disclosure workflow + sub-tier DFARS 7020 flow-down audit. CTA at /v/defense-contractors-tx landing page.

CMMC L2 Nov 2026
CMMC 2.0 32 CFR Part 170 Phase 2 enforcement begins — DoD will not award contracts if SPRS shows a gap
DefenseCMMCDFARS
Oil & Gas

TX Oil & Gas OT/ICS Cybersecurity 2026

V51 Oil-Gas-TX anchor brief: 935% YoY ransomware surge against oil & gas (Zscaler 2025). Halliburton TX $35M direct loss (RansomHub, Aug 2024 — SEC 8-K confirmed). Colonial Pipeline (Houston-origin) DarkSide attack — entire East Coast fuel shut down for the first time ever (May 2021). Newpark Resources Woodlands TX ransomware (Oct 2024). ENGlobal Corp Houston TX 6-week business outage (Nov 2024 – Jan 2025 SEC update). HSE/SCADA death-pile: Muleshoe TX Jan 2024 Unitronics PLC tank-overflow template applies 1:1 to pipeline SCADA valves; Hanna UT Pump Station TX PLC ransomware proof-point; Volt Typhoon IT/OT pre-positioning in U.S. energy targets (Dragos VOLTZITE tracking — 2024-2025). Downtime cost framing: Halliburton Aug 2024 invoice/PO processing offline = multi-million-dollar per-day crew & vendor idle cost. Regulatory stack: TSA SD-Pipeline-2021-01 series + TSA SD-02F (effective May 3, 2025) + SEC Item 1.05 4-business-day cyber-incident disclosure + CIRCIA 72-hr + TDPSA §541 + TCEQ air-permit + RRC 16 TAC §3.71. OT/IT convergence attack surface: Modbus / DNP3 / OPC-UA / EtherNet-IP engineering workstation exposure, cellular RTU/SCADA gateways (VOLTZITE vector), VPN-credential reuse (Colonial trigger), PI historian exfil, Emerson DeltaV / Honeywell Experion / Rockwell ControlLogix vendor remote-access. CoreRecon SCADA-aware SOC at $89–$129/endpoint + $2,500+/mo Command tier with pre-authorized SCADA isolation playbook + 30-min IR SLA beating TSA 12-hr CISA clock + SD-02F Cybersecurity Implementation Plan authorship + OT-aware threat hunts. CTA at /v/oil-gas-tx landing page.

$35M loss
Halliburton — RansomHub ransomware, Aug 2024 (SEC 8-K Item 1.05 confirmed direct charges)
Oil & GasOT/ICSSCADA
Community Banks

TX Community Banks — FFIEC CAT Sunsetting

FFIEC CAT retired Aug 31, 2025 — replacement is FFIEC CAT → NIST CSF 2.0 mapping per FIL-21-2025. Heartland Tri-State Bank $47.1M CEO-fraud collapse (Jul 2023 — social engineering + wire-authority escalation = total bank failure). Evolve Bank $185M LockBit demand / 7.6M records exfiltrated (2024 – public 2025; correspondent-banking / Pathward-Kemba impact). Texas Capital Bank class action filed Jul 2026 — 86,067 Texans affected by May 2026 breach. GLBA 16 CFR 314.4 nine-element Safeguards Rule (effective Jun 9, 2023; Qualified Individual required) + FDIC 12 CFR Part 304 36-hour computer-security-incident notification (effective May 1, 2022) + Texas Department of Banking SB 1961 cyber-incident reporting (effective Sep 1, 2025) + TDPSA §541 (60-day breach notice + 30-day cure + $50K flex-cap) + NIST CSF 2.0 (FFIEC replacement per FIL-21-2025) + FFIEC IT Examination Handbook InTRAC / CyFER. Pathward-Kemba / Kemba-Pathward fourth-party custodian / capital-stack / correspondent-channel vendor risk (voluntary receivership + waiver-of-successor-liability precedent). CDC CAL IC3 24k co $7 total community-bank-SEC top. CoreRecon $89–$129/endpoint, $2,500+/mo Command tier, 30-min IR SLA, SDVOSB-certified, TX-resident SOC, bank-aware 9-element GLBA artifact library + 36-hr FDIC notification workspace + correspondent-banking / core-processor / Pathward-Kemba fourth-party mapping + 14-day FFIEC-to-NIST CSF 2.0 posture delivery. V59 launch at /v/community-banks-tx → /verticals/tx-community-banks-tx.

$47.1M
Heartland Tri-State Bank CEO-fraud collapse — social engineering + wire-authority escalation = total bank failure
Community BanksFFIECGLBA
Law Firms

TX Law Firms — ABA 1.6(c) & IOLTA Wire Fraud

State Bar of TX hit by INC Ransom (Jan 2025) — 1.4M records. Orrick $8M OCR class-action settlement (2023). Mossing & Navarre Toledo ransomware. Bryan Cave Leighton Paisner CCG breach. ABA Model Rule 1.6(c) duty to make reasonable efforts + TX DR 1.05 + ABA Formal Opinion 483 (cyber incident response) + TDPSA §541 + IOLTA wire fraud kill chain (TX IOLTA §171.101–§171.203). Case management attack surface: Clio / MyCase / PracticePanther / iManage / NetDocuments credential paths. Ransomware targeting active case files, settlement escrow timing, and client trust accounts. 8 law-firm-specific controls. CoreRecon $89–$129/endpoint, $2,500+/mo Command tier, 30-min IR SLA, SDVOSB-certified, TX-resident SOC. CTA at /verticals/tx-law-firms-tx.

$8M settlement
Orrick Herrington — OCR class action settlement (2023), new professional-liability data-security standard
Law FirmsABA 1.6(c)IOLTA
Filter: 42 CFR Part 2 ABA 1.6(c) ABA FO 483 ALF ALPHV AWIA Accounting Agriculture Auto Dealers BEC BH Privacy Banking Behavioral Health Breach CDK CIRCIA CISA CJIS CMMC CMS CoP Cloud Community Banking Community Banks Compliance Construction Correspondent Banking Credential Compromise Credit Unions DEA CSOS DFARS DIB DSO Defense Defense Contractors Dental EPA ERCOT Electric Cooperatives Energy FDIC FERPA FFIEC FTC Safeguards Finance Financial Food & Ag GLBA HIPAA Halliburton Healthcare Higher Education IOLTA IRS WISP ITAR Law Firms Legal MUD Manufacturing MatrixCare Medicaid Mortgage Finance Muleshoe Municipalities NCUA NERC CIP NIST 800-171 NIST CSF NIST CSF 2.0 NMLS OT/ICS OT/SCADA Oil & Gas PMS Pharmacy Pipeline PointClickCare Professional Services Public Records Qilin RUS Ransomware RedSail Rhysida SAMHSA SB 1961 SCADA SEC SPRS SaaS & Tech Sandworm Senior Living Supply Chain TCEQ TDPSA TSA TSA Pipeline TSBDE TSBP TX DR 1.05 TX HB 300 TX HSC 247 TX HSC §247 TX PUC §25.367 Texas Texas PIA Threat Intelligence Trust Accounts Utilities V51 V54 V55 V58 V59 Veterinary Volt Typhoon Water Utilities Wire Fraud All
Related paths

Browse threat briefs for incident intelligence, or open industry guidance for the wider security picture.

Community Banks September 2026
Texas Community Banks Under Attack: Credential Compromise, Ransomware Disruption & Compliance Exposure in 2026
Credential compromise now reaches online banking, ACH and wire approval, privileged administration, core processors, and third-party access. For Texas community banks, ransomware can interrupt payments, branches, customer access, settlement, and recovery while triggering GLBA, FDIC, Texas Department of Banking, and TDPSA exposure.
36 hours
FDIC computer-security-incident notification window after discovery
Law Firms August 2026
Texas Law Firms & ABA Rule 1.6(c): Privileged-Client Exposure, IOLTA Wire Fraud & the 2026 Ransomware Reality
State Bar of TX hit by INC Ransom (Jan 2025) — 1.4M records. Orrick $8M OCR class-action settlement (2023). Mossing & Navarre Toledo ransomware. Bryan Cave Leighton Paisner CCG breach. ABA Model Rule 1.6(c) duty to make reasonable efforts + TX DR 1.05 + ABA Formal Opinion 483 (cyber incident response) + TDPSA §541 + IOLTA wire fraud kill chain (TX IOLTA §171.101–§171.203). Case management attack surface: Clio / MyCase / PracticePanther / iManage / NetDocuments credential paths. Ransomware targeting active case files, settlement escrow timing, and client trust accounts. 8 law-firm-specific controls. CoreRecon $89–$129/endpoint, $2,500+/mo Command tier, 30-min IR SLA, SDVOSB-certified, TX-resident SOC. CTA at /verticals/tx-law-firms-tx.
$8M settlement
Orrick Herrington — OCR class action settlement (2023), new professional-liability data-security standard
Community Banks August 2026
Texas Community Banks & FFIEC CAT: 2026 Compliance Reckoning + the Wire-Fraud / Core-Processor Attack Surface
FFIEC CAT retired Aug 31, 2025 — replacement is FFIEC CAT → NIST CSF 2.0 mapping per FIL-21-2025. Heartland Tri-State Bank $47.1M CEO-fraud collapse (Jul 2023 — social engineering + wire-authority escalation = total bank failure). Evolve Bank $185M LockBit demand / 7.6M records exfiltrated (2024 – public 2025; correspondent-banking / Pathward-Kemba impact). Texas Capital Bank class action filed Jul 2026 — 86,067 Texans affected by May 2026 breach. GLBA 16 CFR 314.4 nine-element Safeguards Rule (effective Jun 9, 2023; Qualified Individual required) + FDIC 12 CFR Part 304 36-hour computer-security-incident notification (effective May 1, 2022) + Texas Department of Banking SB 1961 cyber-incident reporting (effective Sep 1, 2025) + TDPSA §541 (60-day breach notice + 30-day cure + $50K flex-cap) + NIST CSF 2.0 (FFIEC replacement per FIL-21-2025) + FFIEC IT Examination Handbook InTRAC / CyFER. Pathward-Kemba / Kemba-Pathward fourth-party custodian / capital-stack / correspondent-channel vendor risk (voluntary receivership + waiver-of-successor-liability precedent). CDC CAL IC3 24k co $7 total community-bank-SEC top. CoreRecon $89–$129/endpoint, $2,500+/mo Command tier, 30-min IR SLA, SDVOSB-certified, TX-resident SOC, bank-aware 9-element GLBA artifact library + 36-hr FDIC notification workspace + correspondent-banking / core-processor / Pathward-Kemba fourth-party mapping + 14-day FFIEC-to-NIST CSF 2.0 posture delivery. V59 launch at /v/community-banks-tx → /verticals/tx-community-banks-tx.
$47.1M
Heartland Tri-State Bank CEO-fraud collapse — social engineering + wire-authority escalation = total bank failure
Oil & Gas August 2026
Texas Oil & Gas Cybersecurity 2026: OT/ICS Ransomware, Pipeline Operator Breaches & the Downtime Math
V51 Oil-Gas-TX anchor brief: 935% YoY ransomware surge against oil & gas (Zscaler 2025). Halliburton TX $35M direct loss (RansomHub, Aug 2024 — SEC 8-K confirmed). Colonial Pipeline (Houston-origin) DarkSide attack — entire East Coast fuel shut down for the first time ever (May 2021). Newpark Resources Woodlands TX ransomware (Oct 2024). ENGlobal Corp Houston TX 6-week business outage (Nov 2024 – Jan 2025 SEC update). HSE/SCADA death-pile: Muleshoe TX Jan 2024 Unitronics PLC tank-overflow template applies 1:1 to pipeline SCADA valves; Hanna UT Pump Station TX PLC ransomware proof-point; Volt Typhoon IT/OT pre-positioning in U.S. energy targets (Dragos VOLTZITE tracking — 2024-2025). Downtime cost framing: Halliburton Aug 2024 invoice/PO processing offline = multi-million-dollar per-day crew & vendor idle cost. Regulatory stack: TSA SD-Pipeline-2021-01 series + TSA SD-02F (effective May 3, 2025) + SEC Item 1.05 4-business-day cyber-incident disclosure + CIRCIA 72-hr + TDPSA §541 + TCEQ air-permit + RRC 16 TAC §3.71. OT/IT convergence attack surface: Modbus / DNP3 / OPC-UA / EtherNet-IP engineering workstation exposure, cellular RTU/SCADA gateways (VOLTZITE vector), VPN-credential reuse (Colonial trigger), PI historian exfil, Emerson DeltaV / Honeywell Experion / Rockwell ControlLogix vendor remote-access. CoreRecon SCADA-aware SOC at $89–$129/endpoint + $2,500+/mo Command tier with pre-authorized SCADA isolation playbook + 30-min IR SLA beating TSA 12-hr CISA clock + SD-02F Cybersecurity Implementation Plan authorship + OT-aware threat hunts. CTA at /v/oil-gas-tx landing page.
$35M loss
Halliburton — RansomHub ransomware, Aug 2024 (SEC 8-K Item 1.05 confirmed direct charges)
Municipalities August 2026
Texas Municipalities Cybersecurity 2026: CJIS v6.0, 911/Utility SCADA Exposure & Public-Records Breach Liability
V56 Municipalities-TX anchor brief: City of Dallas Royal ransomware ($8.5M cost-recover, 2023 — CJI exposure triggering FBI notification). City of Mission / Borger / San Angelo Q4 2025 coordinated wave. Borger TX REvil-affiliate (2025, public works + utility systems). 22 municipalities hit by coordinated Q4 2025 ransomware campaign (collective $2.5M demand). Akbar 911-PSAP ransomware precedent (county 911 ComEx / CAD encryption). Muleshoe TX Unitronics PLC utility SCADA overflow (Jan 2024) re-applicable — most TX cities also run their own water/wastewater SCADA. Full four-track compliance pinch: FBI CJIS Security Policy v6.0 (auditing live Oct 2025; LEA audit enforcement Oct 1, 2027 deadline; 13 policy areas) + Tex. Gov't Code Ch. 552 (Texas Public Information Act breach liability + §552.136 PII exception) + Texas Business & Commerce Code §521.053 (TDPSA breach notification, 60-day clock) + federal CIRCIA 72-hr CISA reporting (where utility SCADA in scope). Attack surface: CJI admin plane (RMS/CAD/NCIC/III terminals), 911 CAD egress, city water/wastewater SCADA (DNP3/Modbus/Unitronics PLC), public-records-portal credential stuffing, citizen-payment BEC (utility billing / municipal court fines), SaaS scheduling platforms (the Mission TX 2025 vector). CoreRecon $89–$129/endpoint, $2,500+/mo Command tier, 30-min IR SLA, SDVOSB-certified, TX-resident analysts, CJIS-mapped SOC + offline CJI continuity playbook + TxDIR cooperative contracting posture. CTA at /v/municipalities-tx landing page.
22 municipalities
hit by coordinated Q4 2025 ransomware wave — CJIS v6.0 auditing live Oct 2025
Defense Contractors August 2026
Texas Defense Contractors & CMMC 2.0 Phase 2: ITAR Exposure, Supply-Chain Risk & the November 2026 Deadline
Volt Typhoon (PRC state-sponsored) has pre-positioned inside the U.S. Defense Industrial Base since 2021 — Texas hosts the #2 US DIB and ~3,000 active TX defense suppliers per DoD OUSD(A&S) data. CMMC 2.0 32 CFR Part 170 Phase 2 enforcement begins November 2026. TX DIB ITAR §120–130 shop-floor angle: ITAR-tagged geometry on Solidworks / AutoCAD / Siemens NX / CATIA / Pro-E file servers represents the most frequent Volt Typhoon collection target — cyber exfiltration treated as a 22 CFR §127 unauthorized-export predicate. DFARS 252.204-7012 72-hr DIBNet clock from discovery (not detection) runs in parallel with a DDTC voluntary disclosure. DFARS 252.204-7021 makes CMMC certification a condition of award. DFARS 252.204-7019/7020 SPRS scoring ≤110 with 3-year refresh; DFARS 252.204-7020 sub-tier flow-down attaches prime CMMC + 22 CFR §127 exposure to Tier 2/3 ITAR incidents. NIST SP 800-171 Rev 2 — 110 controls across 14 families. False Claims Act qui tam exposure under 31 USC §§3729–3733 on unencrypted CUI per recent DoD cyber-fraud enforcement actions ($1.2M–$70M+ settlement range, 15–30% relator share). SDVOSB co-prime advantage counts toward DFARS 252.219-7003 SDVOSB utilization goals. CoreRecon $89–$129/endpoint, $2,500+/mo Command tier, 30-min IR SLA, SDVOSB-certified, TX-resident SOC, ITAR §120–130 DLP tagging on CAD/CAM file servers + DFARS 7012 72-hr disclosure workflow + DDTC voluntary disclosure workflow + sub-tier DFARS 7020 flow-down audit. CTA at /v/defense-contractors-tx landing page.
CMMC L2 Nov 2026
CMMC 2.0 32 CFR Part 170 Phase 2 enforcement begins — DoD will not award contracts if SPRS shows a gap
Senior Living August 2026
Texas Senior Living & Assisted Living Cybersecurity 2026: Avamere 380K, Prospect Medical 1.3M & CMS CoP Compliance — Why Resident PHI Is the Payday
V55 Senior-Living-TX anchor brief: Avamere Group 380,000+ records (ALPHV/BlackCat, 2023–2024, multi-state senior-living & SNF operator). Prospect Medical Holdings 1.3M records (Rhysida, 2023 — Texas-affiliated senior-care operations). Deer Oaks TX verified $225K ransom (2024, family-portal BEC pattern). Texas HHSC Medicaid breach (TX state-agency exposure path, 2024). Acuity Health 2.5M senior-care EHR supply-chain exposure (2024). Lifepoint Health TX senior-care multi-state breach (2024). Texas assisted-living facilities (ALFs), memory-care operators, and skilled-nursing facility (SNF) groups face five-layer compliance: HIPAA Security Rule + TX HSC §242 + TX HSC §247 (HHSC) + CMS Conditions of Participation (42 CFR §483) + TDPSA §541. Attack surface: MatrixCare / PointClickCare / American HealthTech credential paths, multi-facility shared-EHR-tenant segmentation gaps, family-portal BEC, MDS 3.0 eHR submission chain (CMS QIES ASAP), RUG score manipulation Medicare PDPM integrity, memory-care medication-management IoT devices. Sentinel $89/ep, Fortress $129/ep, Command $2,500+/mo — SDVOSB-certified, TX-resident SOC, 30-min IR SLA. Includes V55 launch framing and the V36 Senior-Living gated-PDF CTA at /resources/threat-briefs/senior-living.
380K records
Avamere Group — 380K records ALPHV/BlackCat (2023–2024, largest senior-living breach in U.S. history)
Dental Practices August 2026
Texas Dental Practice Cybersecurity 2026: HIPAA + TDPSA + TSBDE + TX HB 300 — Why Your Patients’ Data Is the Payday
V54 Dental-TX anchor brief: MCNA Dental 8.9M records (TX Medicaid/CHIP dental administrator, 2023). Henry Schein BlackCat/ALPHV supply-chain (2023) — 1M+ records across Dentrix customer network, including TX practices. Change Healthcare 192M (Feb 2024). West Texas Oral Facial Surgery INC Ransom (Jun 2025). Pecan Tree Dental Grand Prairie TX — Sinobi variant confirmed Jan 2026. Professional Dental Alliance 170K+ via vendor phishing. Texas dental practices & DSOs face HIPAA Security Rule + TDPSA §541 + TX HB 300 (HSC Ch. 181) + TSBDE 22 TAC §108.7 record-retention four-layer compliance. DMS-attack surface: Dentrix / Eaglesoft / Open Dental / Curve Dental PMS credential paths, DSO multi-location shared-AD exposure, Weave / Demandforce patient-comms SaaS hijacking, DEXIS Imaging / Patterson file-server ACL gaps. Sentinel $89/ep, Fortress $129/ep, Command $2,500+/mo — SDVOSB-certified, TX-resident SOC, 30-min IR SLA. Includes V54 launch framing and the V54 Dental-TX gated-PDF CTA at /resources/threat-briefs/dental-practices.
8.9M records
MCNA Dental 2023 — TX Medicaid/CHIP dental administrator
Utilities August 2026
Texas Utilities Cybersecurity 2026: NERC CIP, AWIA §2013 RRA/ERP, TX PUC §25.367 96-hr Clock & the Multi-Utility IT/OT Surface
Texas multi-utility operators (gas + electric + water combined MUDs, special utility districts, gas LDCs, multi-utility OES firms) face NERC CIP-002 through CIP-014 (CIP-008 IR plan tri-clock + CIP-014 physical security + CIP-013 supply-chain), AWIA §2013 Risk & Resilience Assessment + Emergency Response Plan on 5-yr cycle, TSA SD-Pipeline-2021-01D (top 100+ gas LDCs + LNG), 49 CFR Part 192/195 (gas distribution + transmission), EPA RRAN-aligned RRA/ERP, AWWA G430/J100/DWFR, RRC 16 TAC §3.70 pipeline damage prevention, TX PUC Substantive Rule §25.367 (96-hr electric cyber-incident clock to PUCT — concurrent with CIRCIA 72-hr for NERC-registered entities), TDPSA §541 (utility customer billing + usage data enumeration), Volt Typhoon IT/OT pre-positioning in U.S. energy + water since 2021 (CISA/NSA AA24-038A), Muleshoe TX water-tank overflow (Jan 2024, CyberArmyofRussia/Unitronics PLC), Halliburton TX $35M RansomHub (Aug 2024), Brazos Electric $2.1B Ch.11 (2021 aftermath), City of Dumas TX SCADA ransomware (Nov 2024). Shared-MSP / vendor-IT / AMI headend / SCADA recloser / GIS / customer-portal BEC attack surface. CoreRecon tri-clock parallel-narrative SOC deliverable at $89–$129/endpoint + $2,500+/mo Command tier with AWIA RRA/ERP authorship + CIP-014 audit support + CIP-013 supply-chain plan + TDPSA enumeration coverage. SDVOSB-certified, 30-min CIP-008 SLA, TX-resident analysts, federal-grant procurement eligible (DWSRF/BRIC/RUS/DOE OE-000).
96-hr + 72-hr
TX PUC §25.367 + CIRCIA concurrent clocks — TX electric utility tri-narrative reports in parallel after every CIP-008 IR event
Defense Contractors August 2026
Texas Defense Contractors & CMMC 2.0 Phase 2 Enforcement: The November 2026 Deadline That Kills Awards
Volt Typhoon (PRC state-sponsored) has pre-positioned inside the U.S. Defense Industrial Base since 2021 — Texas hosts the #2 US DIB and ~3,000 active TX defense suppliers per DoD OUSD(A&S) data. CMMC 2.0 32 CFR Part 170 Phase 2 enforcement begins November 2026; DFARS 252.204-7012 72-hr DIBNet clock from discovery (not detection); DFARS 252.204-7021 makes CMMC certification a condition of award; DFARS 252.204-7019/7020 SPRS scoring ≤110 with 3-year refresh; NIST SP 800-171 Rev 2 (110 controls across 14 families); ITAR §120–130 export-controlled technical data exposure on shop-floor CAD (Solidworks/AutoCAD/Siemens NX); False Claims Act qui tam exposure on unencrypted CUI per recent DoD settlements; DCAA audit cyber-cost-recovery issues; SDVOSB co-prime advantage counts toward DFARS 252.219-7003 SDVOSB utilization goals. CoreRecon SOC at $89–$129/endpoint, 30-min IR SLA, SDVOSB-certified, TX-resident.
CMMC L2 Nov 2026
CMMC 2.0 32 CFR Part 170 Phase 2 enforcement begins — DoD will not award contracts if SPRS shows a gap
Behavioral Health July 2026
Texas Behavioral Health & Mental Health Clinic Cybersecurity: The 42 CFR Part 2 + HIPAA Gap You're Inheriting in 2026
TX BH & mental health clinics hold psychiatric records, SUD histories, MAT EPCS prescribing logs, crisis-line recordings, and consent-management audit trails. 42 CFR Part 2 federal criminal liability stacks on HIPAA civil penalties. 6 named incidents (Behavioral Health Group TX SUD exposure, Deer Oaks $225K, Acuity Brands LockBit, Lifepoint, Ardent, CHS). TX HB 300, TX HSC Ch. 611, TDPSA §541.062, FTC HBNR 16 CFR §318, SAMHSA NIMDAT concurrent clocks. BH-EHR attack surface: Credible / Kipu / myEvolv / Netsmart / Epic Behavioral Health. $89–$129/endpoint, 30-min IR SLA, SDVOSB, TX-resident SOC.
$9.8M avg breach cost
BH sub-sector — IBM CODB 2025, highest of any healthcare sub-sector
Community Banks July 2026
Texas Community Banks Face a Cybersecurity Reckoning — Here’s How to Respond
With the FFIEC CAT retired, GLBA 2023 amendments in force, and TDPSA active, TX community banks face a compounding compliance burden with no SOC to manage it. Here’s what you need to do now.
86,067 Texans
affected by Texas Capital Bank breach (May 2026) — class action filed July 2026
Dental Practices June 2026
Texas Dental Practice Ransomware: Why Your Patients’ Data Is the Payday in 2026
TX dental practices face compounding ransomware risk in 2026. Named incidents (Henry Schein, Change Healthcare, Pecan Tree Dental Grand Prairie TX), PMS attack surface (Dentrix, Eaglesoft, Open Dental), HIPAA + TSBDE + TX HB 300 triple exposure, and what 30-min SOC response buys your practice.
8.9M records
MCNA Dental 2023 — TX Medicaid/CHIP dental administrator
Electric Co-ops June 2026
Texas Electric Cooperative Ransomware: Why Co-ops Are in the 2026 Crosshairs
TX electric co-ops face compounding threat from Volt Typhoon, Qilin, and Sandworm targeting OT/IT convergence gaps. Named incidents, NERC CIP triple-stack, and 5-step posture assessment.
Karnes EC + San Bernard EC
Qilin ransomware — member PII confirmed exfiltrated from both TX co-ops
Senior Living June 2026
Texas Senior Living Ransomware 2026: The 207-Day Gap That Costs Resident PHI
TX senior living & assisted living facilities face a 207-day average detection gap. Learn why ransomware gangs target LTC operators, the TX compliance stack, and how CoreRecon closes the gap.
207-day dwell
avg before a TX ALF detects a breach — 6+ months of resident PHI exposure
Mortgage Brokers June 2026
Texas Mortgage Brokers & Lenders Ransomware Threat 2026: loanDepot, Mr. Cooper, and the GLBA Safeguards Gap
Six named incidents — loanDepot $26M, Mr. Cooper $25M, Fairway $12-17M, Academy, FNF/LoanCare $5.9M, First American Title. ALPHV/BlackCat and LockBit 3.0 targeting TX mortgage brokers. GLBA Safeguards Rule §314.4 nine-element enforcement is live. NMLS bond exposure. 30-min wire fraud SLA math. 62 sources.
$71M+
documented losses across 6 verified mortgage sector incidents — loanDepot, Mr. Cooper, Fairway, Academy, FNF/LoanCare, First American
Water Utilities June 2026
TX Water Utilities Ransomware: Muleshoe Attack, SCADA Exposure & AWIA Compliance
Russian actors hit Muleshoe, TX in Jan 2024. Here is what Texas water districts need to know about AWIA compliance, SCADA exposure, and ransomware defense.
Jan 2024
CyberArmyofRussia_Reborn — Russian GRU-linked group caused Muleshoe TX water tank overflow, 30–45 min
Independent Pharmacies June 2026
TX Independent Pharmacies Under Ransomware Fire: The 2026 Threat Brief
Texas independent pharmacies face triple-jeopardy HIPAA + TSBP + DEA enforcement. 2026 threat brief covers named incidents (Change Healthcare 100M records, PharMerica 5.8M, AAP/Embargo 2,000+ pharmacies), regulatory stack, vendor consolidation risk, and 90-day remediation roadmap. CoreRecon SOC at $89–$129/endpoint.
100M records
Change Healthcare breach — 3-week pharmacy outage, TX pharmacies dispensing at personal risk
Dental Practices June 2026
Texas Dental Practice Ransomware & HIPAA Breaches: 2026 Threat Outlook
MCNA 8.9M records. Henry Schein BlackCat 1M+. Ransomware dwell time 207 days. HIPAA + TDPSA + TX HB 300 + TSBDE dual-enforcement. Dentrix/Eaglesoft/Open Dental/Curve attack surface. 8 controls, 30/60/90 roadmap. CoreRecon SOC at $89–$129/endpoint.
8.9M records
MCNA Dental 2023 — TX Medicaid/CHIP dental administrator
Water Utilities June 2026
Texas Water Utility Ransomware: The Incidents, Attack Surface, and Compliance Guide
CyberArmyofRussia compromised 4 TX Panhandle water utilities in Jan 2024 — Muleshoe tank overflowed via exposed VNC/Unitronics PLCs. AWIA Section 2013 mandates SCADA RRA. EPA RY2, TCEQ, CISA CPGs, NIST CSF 2.0 all in scope. 6 named threat actors, OT/IT attack surface, 8 water-utility-specific controls. CoreRecon OT-aware SOC at $89–$129/endpoint.
Jan 2024
CyberArmyofRussia HMI compromise at 4 TX Panhandle water utilities — Muleshoe tank overflowed
Water Utilities June 2026
Texas Water Utilities Cyber Threat Brief 2026
CyberArmyofRussia hit Muleshoe, Hale Center, Abernathy, and Lockney in January 2024 — HMI via VNC, tank overflow before operators noticed. AWIA Section 2013 mandates RRA including SCADA cybersecurity. EPA RY2, CISA CPGs, TCEQ, and NIST CSF 2.0 all in scope. 6 threat actors, OT/IT attack surface, 8 water-utility-specific controls. CoreRecon OT-aware SOC at $89–$129/endpoint.
Jan 2024
CyberArmyofRussia HMI compromise at 4 TX Panhandle water utilities — Muleshoe tank overflowed
Senior Living June 2026
Texas Senior Living & Assisted Living Communities Cyber Threat Brief 2026
1,200+ TX ALFs in 4-layer regulatory stack, no dedicated SOC, BYOD tablets without MDM, legacy EHRs — BlackCat/ALPHV actively targeting. Acuity Health 2.5M+ records. HIPAA + TX HSC Chapter 247 + Medicaid + TDPSA. 8 ALF-specific controls. 48 verified sources. CoreRecon SOC at $89–$129/endpoint.
2.5M+ records
Acuity Health 2024 — TX Medicaid ALF provider, resident health records exposed
Dental Practices June 2026
Texas Dental Practices & DSOs Cyber Threat Brief 2026
MCNA Dental: 8.9M records stolen (TX Medicaid/CHIP administrator). Professional Dental Alliance: 170K+ records. Dental records sell for $250–$1,000/file on dark web — 10x credit cards. HIPAA Security Rule + TDPSA dual-track. 3 named incidents, 5 attack vectors, 5 controls. CoreRecon SOC at $89–$129/endpoint.
8.9M records
MCNA Dental 2023 breach — TX Medicaid/CHIP dental administrator
Veterinary Hospitals June 2026
Texas Veterinary Hospitals Cyber Threat Brief 2026
NVA 2024 breach: 1.1M+ pet records exposed. BlackCat, LockBit, Rhysida targeting TX veterinary hospitals. AVImark/Hippo Manager credential compromise. HIPAA Security Rule + TX HB 300 dual-track exposure. 6 named incidents, 8 controls, 30/60/90 roadmap. CoreRecon SOC at $89–$129/endpoint.
1.1M+ pet records
NVA 2024 breach — largest veterinary sector breach in US history
Law Firms June 2026
Texas Law Firms Cyber Threat Brief 2026
Mossing & Navarre Toledo ransomware. Bryan Cave Leighton Paisner CCG breach. State Bar of TX hit by INC Ransom (January 2025). Orrick $8M settlement. TX Bar Rule 5.03, ABA Formal Opinion 498, TDPSA (Jul 2024), IRS Pub 4557. IOLTA wire fraud kill chain. 5 controls. 35+ verified sources.
45
ransomware attacks on law firms in 2024 — record high (Black Fog 2024)
Behavioral Health June 2026
Texas Behavioral Health Clinics Cyber Threat Brief 2026
6 verified TX behavioral health incidents. 42 CFR Part 2 + HIPAA double-jeopardy. BH organizations average $9.8M breach cost. BlackCat, Qilin, and Rhysida targeting psychiatric records and substance use data. TX HB 300 + NIMDAT + SAMHSA compliance. 8 controls, 30/60/90 roadmap. CoreRecon BH-focused SOC at $89–$129/endpoint.
$9.8M avg breach cost
BH organizations — IBM CODB 2025, highest of any healthcare sub-sector
Construction June 2026
Texas Construction & General Contractors Cyber Threat Brief 2026
Williams Brothers Construction hit by Akira (Feb 2026). Texas GC lost $2.5M in BEC wire fraud. Bouygues Construction €10M Maze ransom. CMMC 2.0 Phase 2 enforcement begins Nov 2026. BEC wire fraud kill chain. 8 controls for TX GCs. 32 verified sources.
$2.5M
TX GC BEC wire fraud loss — draw payment rerouted, $1.7M unrecovered
Accounting & CPA June 2026
Texas Accounting & CPA Firms Cyber Threat Brief 2026
Whitley Penn (Oct 2023), Lane Gorman Trubitt (Jan 2024), BST & Co. HIPAA action, Orrick $8M settlement. MOVEit exploitation targeting professional services. IRS WISP compliance walkthrough. FTC Safeguards Rule QI requirements. TDPSA + GLBA + SOC 2 overlap. 38 verified sources.
$8M
Orrick class action settlement — new professional services liability standard
Oil & Gas June 2026
Texas Oil & Gas Cyber Threat Brief 2026
935% ransomware surge YoY. Halliburton $35M loss (SEC 8-K). Colonial Pipeline DarkSide attack. Newpark Resources, ENGlobal. Volt Typhoon OT pre-positioning. TSA SD-02F, SEC Item 1.05, CMMC 2.0, TDPSA regulatory crosswalk. 59 verified sources.
$35M loss
Halliburton — RansomHub ransomware, Aug 2024 (SEC-confirmed)
Agriculture June 2026
Texas Agriculture Under Cyber Siege: 2026 Threat Brief
Three major food sector attacks. 118% ransomware spike. Schreiber $2.5M ransom, JBS $11M paid, Dole $10.5M direct costs. TDPSA + USDA + FDA FSMA 204 + APHIS regulatory stack. 8 OT/ICS controls for TX farmers, processors, and co-ops.
118% spike
Q4 2024 food/ag ransomware surge vs Q4 2023
Banking June 2026
Texas Community Banks Cyber Threat Brief 2026
Heartland Tri-State Bank collapsed ($47.1M CEO fraud). Evolve Bank lost $185M to LockBit. Core-provider supply chain risk. FFIEC CAT maturity walk-through. GLBA 16 CFR 314 Safeguards checklist. FDIC 36-hr notification guide. BEC wire-fraud benchmarks from FBI IC3 2024. 35+ verified sources.
$47.1M fraud
Heartland Tri-State Bank CEO — social engineering + wire authority = bank failure
Auto Dealers June 2026
Texas Auto Dealers Under Cyber Siege: 2026 Threat Brief
CDK Global paid $25M ransom. 15,000 dealers offline 3 weeks. 700Credit 5.6M consumers exposed. Motility/Reynolds 766K records. FTC Safeguards Rule 8-requirement checklist. 8 DMS dealer controls. 40+ verified sources.
$25M ransom
CDK paid — Austin-based DMS vendor (Jun 2024)
Law Firms June 2026
Why Texas Law Firms Are Under Siege: The 2026 Cybersecurity Reality
Houston attorney loses $2.4M in a single wire. FBI IC3 $2.77B BEC losses. Orrick $8M, HPMB $200K NY AG fine, Gunster $8.5M settlements. ABA Rule 1.6(c) + TX DR 1.05 + TX SB 2610 safe harbor. 12-step action checklist.
$2.4M wire loss
Houston firm — BEC kill zone at closing
Higher Education June 2026
Texas Higher Education Cyber Threat Brief 2026
1,000+ U.S. higher education institutions hit in 2024. TTUHSC 1.4M records. 207-day dwell analysis. 8-framework compliance crosswalk: FERPA, GLBA Safeguards, HIPAA, CMMC L2, TX SB 820, TX HB 300, PCI DSS, TX DIR. 35 verified sources. 12-item action plan.
1,000+ institutions
hit by ransomware or breach in 2024
Manufacturing June 2026
Texas Manufacturing Cyber Threat Brief 2026
Manufacturing is the most-attacked TX sector in 2026. IBM X-Force confirms supply-chain dominance. Brunswick Corp. $85M precedent. OT/IT convergence gaps and NIST CSF 2.0 implementation roadmap.
#1 attacked
sector in Texas per IBM X-Force 2026
Municipalities June 2026
Texas Municipalities Cyber Threat Brief 2026
22 Texas municipalities hit by coordinated ransomware in Q4 2025. FBI CJIS v6.0 auditing is live. 13 CJIS policy area gaps, threat actor profiles, and 30/60/90 hardening roadmap.
22 municipalities
hit by coordinated Q4 2025 ransomware wave
SaaS & Tech June 2026
Texas Tech Sector Cyber Threat Brief 2026
SaaS platform supply-chain attacks, API credential theft, and cloud misconfiguration targeting Texas tech companies. SOC 2 Type II gaps, startup IP exfiltration, and DevSecOps hardening roadmap.
SOC 2 Type II
compliance gap most common in TX tech incidents
Defense Contractors June 2026
Texas Defense Contractor Cyber Threat Brief 2026
Volt Typhoon supply-chain pre-positioning in Texas DIB. CMMC Level 2 enforcement Nov 2026. 4 confirmed incidents, CUI exfiltration vectors, and ITAR exposure analysis.
CMMC Nov 2026
Level 2 enforcement deadline for TX DIB
Law Firms June 2026
Texas Law Firms Cyber Threat Brief 2026
1.2M+ client records exposed. Business email compromise at closing, attorney credential theft, and client trust account fraud. Texas State Bar Ethics Opinion 712 compliance roadmap.
1.2M+ records
client records exposed in TX legal sector incidents
Credit Unions June 2026
Texas Credit Union Cyber Threat Brief 2026
FIN7, Scattered Spider, and LockBit 3.0 targeting Texas credit unions. NCUA CAT compliance gaps. Core banking system attacks and ACH fraud vectors. 280K+ member records at risk.
280K+ members
at risk across TX credit union incidents
Healthcare June 2026
Texas Healthcare Cyber Threat Brief 2026
12 verified TX healthcare incidents. 207-day average dwell time. $9.8M average breach cost. BlackCat, Qilin, Rhysida, INC Ransom profiles. HIPAA + TX HB 300 double-jeopardy regulatory exposure.
207-day dwell time
avg attacker persistence before detection
Interactive Tools — Free
Healthcare · HIPAA
HIPAA Readiness Quiz
18 questions. All 18 Security Rule standards. Know your OCR gaps before enforcement — instant scored results.
Take the Quiz →
All Verticals · IBM 2024
Breach Cost Calculator
Industry, endpoints, records. Get your IBM 2024 breach cost range + TX penalty exposure in 30 seconds.
Calculate My Risk →
All Verticals · BLS 2025
vCISO ROI Calculator
vCISO vs. in-house CISO. 3-year TCO with 1.3x benefits multiplier + CoreRecon tier selector.
Calculate vCISO ROI →
Defense · CMMC
CMMC Readiness Quiz
14 questions. All CMMC L2 domains. Know your SPRS gaps before DoD enforcement — Nov 2026 deadline.
Take the Quiz →
🛠 Try All 7 Tools — Free → All Guides & Resources →
Get the Weekly Texas Threat Brief

A concise read on the incidents, attacker tactics, and defensive moves shaping Texas security this week.