Texas Municipalities
Cyber Threat Brief
2026
22 municipalities. 1 coordinated campaign. $2.5M refused. FBI CJIS v6.0 auditing is live — every Texas city is in scope. This brief documents what happened, who did it, and what you need to do before October 1, 2027.
- 22 TX municipalities hit in Q4 2025 coordinated ransomware campaign
- FBI Wave 1 & 2 municipal outreach lists partially leaked via Austin breach
- CJIS v6.0 auditing active — full compliance deadline October 1, 2027
- 5 threat actor profiles: Royal, LockBit 3.0, BlackCat, REvil, Volt Typhoon
- 21-item 30/60/90 hardening roadmap — mapped to CJIS policy areas
22 Texas municipalities. One coordinated campaign.
The Q4 2025 coordinated ransomware campaign remains the largest municipal attack event in Texas history. Individual incidents span from Dallas (2023) through Borger, Mission, and the 2025 wave. FBI CJIS audit implications for each are documented where known.
The complete PDF includes full incident writeups, CJIS audit evidence requirements, and 21-item hardening checklist. Enter your work email to access it instantly.
No spam. One email with the PDF. Unsubscribe anytime.
✓ Sent — check your inbox. The PDF is on its way.
| City / Entity | Severity | Date | Threat Actor | Impact | CJIS Impact |
|---|---|---|---|---|---|
| City of Dallas, TX | Critical | May 2023 | Royal | Police, courts, emergency comms disrupted for weeks. 311 and library systems forced offline. $8.5M+ recovery cost. | FBI notification required. Criminal justice data in scope. Audit implications ongoing. |
| City of Mission, TX | High | Oct 2025 | Undisclosed | Supply-chain phishing through SaaS scheduling platform. Utility billing and internal comms disrupted 3 weeks. | Wave 1 FBI outreach. CJIS audit scope active. |
| City of Borger, TX | High | 2025 | REvil affiliate | REvil affiliate attack disrupted public works and utility systems. City shut down public-facing web services 11 days. | Criminal justice records in scope. CJIS audit implications unresolved. |
| City of Austin, TX | High | Jan 2026 | LockBit 3.0 | City employee data and FBI municipal outreach lists leaked. Wave 1 & 2 target names exposed publicly. | Outreach list leak confirmed CJIS audit scope. FBI notification filed. |
| Travis County, TX | Medium | Q4 2025 | Unknown (wave) | Part of 22-municipality coordinated campaign. Partial systems impact — critical services maintained. | Wave 1 FBI outreach. County criminal justice systems audited post-incident. |
| Fort Bend County, TX | Medium | Q4 2025 | Unknown (wave) | Coordinated campaign wave. County systems partially affected — public-facing services curtailed. | Wave 1 FBI outreach. CJIS systems reviewed. |
| Comal County, TX | Medium | Q4 2025 | Unknown (wave) | County network partially impacted during coordinated campaign. Services restored within 2 weeks. | Wave 1 FBI outreach. CJIS compliance review post-incident. |
| 20 Additional TX Municipalities | High | Q4 2025 | Coordinated campaign | Collective $2.5M ransom demand. All targets refused payment. TX DIR and Texas Cybersecurity Framework activated. | Wave 2 FBI outreach to multiple entities. Audit scope active across all targets. |
Who's targeting Texas municipalities?
Five threat actors represent the primary risk to Texas municipalities. Nation-state actors are interested in OT/ICS pre-positioning; ransomware groups target city governments for insurance leverage and data exfiltration.
13 policy areas. All in active audit scope.
FBI CJIS v6.0 auditing is live. Every Texas municipality is in scope through October 1, 2027. CoreRecon maps all 13 CJIS security policy areas to SOC monitoring tiers — and generates audit-ready evidence packages automatically.
Why municipalities. Why now.
Local governments account for 38% of all Texas ransomware incidents in 2025. The math is simple: limited security staff, high-value CJIS data, and cyber insurance make municipalities the highest-ROI target in the state.
What your municipality needs to do.
Every action below maps to a specific CJIS v6.0 policy area and a CoreRecon SOC tier. Start with Day 1 — the audit clock is already running.
The audit clock is running.
Every day without SOC coverage is a day your municipality is more exposed than the last. CoreRecon delivers CJIS-mapped monitoring, 30-minute response SLA, and audit-ready evidence packages at $89–$129/endpoint — priced for municipal budgets.
Get Your Free $2,500 Assessment →No contracts. No minimums. SDVOSB preferred vendor.