Texas Tech Sector
Under Siege.
2026 Briefing
49 million Dell customer records exposed. AT&T call logs on the dark web. Okta cascading into TX SaaS. Four threat actors with active TX tech campaigns. Here's what you need to know — and what to do about it.
- Scattered Spider: help desk impersonation bypasses MFA, targets cloud storage and GitHub repos
- IntelBroker: actively selling TX tech company data on dark web forums — confirmed ongoing sales
- Volt Typhoon / APT41: pre-positioned inside TX tech supply chains since mid-2022 — sabotage posture, not theft
- LAPSUS$: social engineering + insider recruitment — confirmed targeting of major tech company source code
exposed (May 2024)
incidents (2023–2026)
profiles (Scattered, LAPSUS$, IntelBroker, Volt)
to detection (TX tech)
Austin–Plano–Houston corridor:
high-value, high-volume target
The Austin/Plano/Dallas tech corridor is one of the most concentrated tech ecosystems in the US. Dell (Round Rock), Samsung (Austin), AT&T (Dallas), and hundreds of SaaS companies serving Fortune 500 clients call this region home. That concentration makes it a primary target for threat actors who understand that breaching a single vendor or platform gives them access to thousands of downstream customers.
- Supply chain leverage: One breach cascades to hundreds of customers — Okta 2022/2023, MOVEit, Snowflake prove the cascade model
- Customer data concentration: Tech companies hold millions of consumer records and B2B contact data in SaaS platforms
- Federated identity blast radius: OAuth/token compromise at one SaaS grants access across interconnected apps
- SaaS-to-SaaS attack chains: npm/PyPI supply chain attacks inject malicious code that flows to enterprise customers
- Dell Round Rock: 49M customer records (May 2024), 10,863 employee records (Sep 2024) — both via partner API exposure
- AT&T Dallas: Dark web SSN/passcode sale (Mar 2024), Snowflake call records (Jul 2024) — two distinct incidents, one org
- Samsung Austin Semiconductor: Employee data + US customer data exfiltrated byINC Ransom (Aug 2024)
- TX SaaS portcos: Snowflake-attributed compromises hit multiple TX companies in 2024 campaign
TX Tech Incident Database —
2023–2026
14 documented incidents. Scroll or use the filter to find relevant events by attack type or region.
| Date | Entity | Location | Records | Attack Vector | Threat Actor | TX Impact |
|---|---|---|---|---|---|---|
| Dec 2020 | SolarWinds | Austin HQ | ~18,000 TX customers affected, CUI, credentials | Supply chain injection (SUNBURST backdoor in Orion update) | APT / SVR (Russia) | ✓ Austin HQ |
| Jan 2022 | Okta (LAPSUS$ breach) | San Francisco (TX SaaS cascade) | Customer support tool access, 366 customers affected | Subcontractor laptop compromise via personal Google account | LAPSUS$ | ✓ TX SaaS cascade |
| Oct 2022 | Okta (duplicate) | — | Re-used same support tool access from Jan 2022 | Same subcontractor access vector persisted | LAPSUS$ | ✓ TX SaaS cascade |
| May 2023 | MOVEit Transfer (TX cascade) | Progress Software (MA, TX SaaS victims) | TX HRIS, payroll, benefits admin systems compromised | SQL injection (CVE-2023-34362) — zero-day exploit | Cl0p / LockBit affiliates | ✓ TX SaaS + HRIS cascade |
| May 2024 | Dell Technologies | Round Rock, TX | ~49 million customer records exposed | Partner portal API exposing customer PII without auth | Unknown (discovered by researcher) | ✓ TX HQ — Round Rock |
| Aug 2024 | Samsung Austin Semiconductor + US customers | Austin, TX | Employee data + US customer data exfiltrated | Unknown initial access, exfil via internal systems | INC Ransom | ✓ Austin HQ — direct victim |
| Sep 2024 | Dell (second incident) | Round Rock, TX | 10,863 employee records via internal system exposure | Internal system misconfiguration, credentials accessible | Unknown | ✓ TX HQ — direct victim |
| Mar 2024 | AT&T (dark web SSN/passcode breach) | Dallas, TX | 73M current + former customer records on dark web | Credential stuffing + data broker aggregation — AT&T attributed to 2021 breach | ShinyHunters (dark web actor) | ✓ Dallas HQ — direct victim |
| Jul 2024 | AT&T (Snowflake call records) | Dallas, TX | Nearly all AT&T cellular customers — call + text records | Snowflake platform breach (MFA not enforced on admin account) | UNC5536 (Snowflake campaign) | ✓ Dallas HQ — second incident |
| 2023 | 23andMe (TX user data) | South San Francisco (TX users affected) | TX user genetic data exposed via credential stuffing wave | Credential stuffing (password reuse across platforms) | Unknown | ✓ TX users — credential stuffing wave |
| 2024 | GitHub Actions (TX startups — UNC4902) | GitHub (TX startup CI/CD exposure) | Source code secrets, OAuth tokens, CI/CD pipeline access | GitHub OAuth app token theft via malicious GitHub Actions | UNC4902 (UNC Threat Group) | ✓ TX startup CI/CD exposure |
| 2023–2024 | PyPI / npm (TX Python/JS SaaS supply chain) | PyPI + npm registries (TX Python/JS SaaS exposure) | Malicious packages exfiltrating env vars, secrets, API keys from CI/CD | Typosquatting, dependency confusion, compromised maintainer accounts | Multiple threat actors | ✓ TX Python/JS SaaS supply chain |
| 2024–ongoing | IntelBroker (TX tech company data) | Online dark web forum (ongoing) | Ongoing sales of TX tech company data, internal credentials, source code | Initial access via vulnerability exploitation, insider access purchase | IntelBroker | ✓ IntelBroker selling TX tech data |
| 2024 | Snowflake-attributed TX portcos (multiple) | Snowflake platform (TX SaaS companies affected) | Customer data, authentication tokens, downstream access | Snowflake admin account compromise (no MFA), token reuse across platforms | UNC5536 / UNC4899 (attribution to Scattered Spider) | ✓ TX SaaS portcos — Snowflake cascade |
Four groups with active
TX tech campaigns
The cascading obligation story:
8 frameworks, all active
Your customers are requiring these frameworks. Your procurement team needs to be ready. One breach may trigger multiple frameworks simultaneously.
| Framework | Applies To | Key Requirement | What To Do |
|---|---|---|---|
| SOC 2 Type II | All SaaS companies with enterprise customers | Annual audit: security, availability, confidentiality, privacy. Continuous monitoring of controls. | Engage a CPA firm for Type II audit. CoreRecon covers the security controls that auditors check: access management, change management, monitoring, incident response. |
| ISO 27001 / 27017 / 27018 | Cloud providers, SaaS, enterprise customers requiring international coverage | 27001: ISMS. 27017: cloud-specific controls. 27018: PII in cloud. Third-party certified. | ISO certification is a procurement requirement for many EU and enterprise customers. CoreRecon maps controls to ISO 27001 and 27017. |
| FedRAMP Moderate | SaaS companies selling to federal agencies, including TX state/local agencies via TX-RAMP | Third-party assessment organization (3PAO) assessment, CSP package, agency authorization. | FedRAMP Moderate is a prerequisite for federal agency contracts. If you sell to any government entity, TX-RAMP is the Texas state equivalent (launched 2024). CoreRecon's Command tier covers FedRAMP/TX-RAMP readiness. |
| TX-RAMP | Companies selling SaaS to Texas state agencies and local governments | TX Risk and Authorization Management Program — similar to FedRAMP at state level. Required for TX public sector contracts. | Assess applicability against your customer base. CoreRecon maps TX-RAMP requirements and helps build the SSP and POA&M. |
| CMMC L2 | Companies handling CUI for DoD contractors (includes SaaS serving defense contractors) | 110 controls from NIST 800-171. Third-party assessment required by Nov 10, 2026 for many contractors. | If any customer is a defense contractor, your handling of their data may require CMMC L2. CoreRecon covers CMMC L2 controls in our DoD contractor packages. |
| HIPAA | SaaS companies with healthcare customers (BAA required if PHI processed) | Business Associate Agreement required. Breach notification within 60 days. Security, technical, and administrative safeguards. | If you have healthcare clients, you need a BAA. Breach of your platform becomes a HIPAA reportable event for your healthcare customers. CoreRecon covers HIPAA controls in our Healthcare tier. |
| PCI DSS v4.0.1 | SaaS companies processing payment card data (enterprise B2B platforms with payment flows) | 12 requirements, 64 base requirements, growing to 70+ in v4.0.1 mandatory updates. Requires formal risk assessment annually. | For SaaS companies that process payments on behalf of clients, PCI DSS may apply at a merchant level. CoreRecon can scope and assess PCI applicability. |
| GDPR / CPRA / TDPSA | SaaS companies with EU users (GDPR), California residents (CPRA), TX residents (TDPSA) | GDPR: EU residents — 72-hr breach notification, DPO required. CPRA: CA residents — right to delete, opt-out. TDPSA: TX residents — data broker obligations, breach notification. | TX TDPSA (effective July 2024) is the newest Texas data privacy law. Data broker registration, consumer rights requests, breach notification timelines. GDPR and CPRA are standard for any SaaS with broad consumer or enterprise use. CoreRecon's privacy compliance support covers all three. |
| SEC Item 1.05 | Publicly traded tech companies (pre-IPO companies with SEC filings) | Material cybersecurity incidents must be disclosed in 4 business days (Form 8-K). Annual disclosure of cyber risk management. | If you're public or near-IPO, SEC Item 1.05 means your breach notification clock is 4 business days — not the GDPR 72 hours. The IR plan has to be ready before a breach, not after. CoreRecon's Command tier includes SEC Item 1.05 IRP documentation. |
6 vectors unique to the
tech sector attack surface
- ✓ Run GitGuardian, TruffleHog, or Gitleaks across all repos — audit what secrets are exposed in current code
- ✓ Move all secrets to AWS Secrets Manager, GCP Secret Manager, or HashiCorp Vault
- ✓ Rotate every credential found in any repo — assume it's compromised
- ✓ Enforce branch protection + require secret scanning in pre-commit hooks and CI pipelines
- ✓ Audit CI/CD service accounts (GitHub Actions, CircleCI, Jenkins) — principle of least privilege
- ✓ Enforce MFA on all IdP admin accounts (Okta, Azure AD, Google Workspace)
- ✓ Audit all OAuth apps with "highly privileged" permissions — remove unused integrations
- ✓ Implement OAuth token lifetime limits — 1-hour access tokens for high-sensitivity apps
- ✓ Enable token binding — correlate OAuth tokens with device/hardware security keys
- ✓ Monitor for anomalous OAuth app installs — especially in GitHub org and cloud console
- ✓ Use lock files (package-lock.json, pip.lock) — never install from unpinned versions
- ✓ Run Sonatype Nexus, JFrog Xray, or Snyk to scan every dependency for known malware
- ✓ Enable GitHub Dependabot or Renovate Bot for automated dependency updates
- ✓ Monitor for new maintainers on your critical packages — ownership changes are a known compromise signal
- ✓ Pin to known-good SHA hashes for dependencies in package.json
- ✓ Map every SaaS-to-SaaS integration and document OAuth scopes granted
- ✓ Apply principle of least OAuth scope — if a Salesforce integration only needs read access, don't grant write
- ✓ Review OAuth token lifetimes per connected app — revoke tokens for deprecated integrations
- ✓ Monitor connected app activity for unusual data access patterns in SIEM
- ✓ Disable integrations for departed employees — access persistence is a known attack vector
- ✓ Audit tenant isolation — confirm row-level security, data partitioning, and access controls per tenant
- ✓ Ensure database credentials are unique per customer or customer cohort
- ✓ Monitor cross-tenant data access patterns in your data warehouse or analytics platform
- ✓ Build customer notification workflow — TDPSA requires notification within 60 days; GDPR requires 72 hours
- ✓ Conduct architecture review with your security team or CoreRecon for tenant isolation gaps
- ✓ Implement input sanitization and output validation on all LLM integrations — treat user input as untrusted
- ✓ Restrict LLM access to system commands and data stores — use least privilege at the tool/function level
- ✓ Monitor for prompt injection attempts in application logs — anomalous user inputs with system-level instructions
- ✓ Audit RAG vector database access controls — ensure customer data is not inadvertently retrievable by other tenants
- ✓ Conduct LLM red team testing before production deployment — OWASP LLM Top 10 is the baseline
30/60/90-day roadmap —
50–500 employee TX tech companies
24 concrete checklist items. Prioritized by impact and urgency for tech companies in the Austin/Plano/Dallas/Houston corridor.
-
Enforce phishing-resistant MFA on all cloud and code platform accounts
Okta 2022, Snowflake, AT&T — MFA would have stopped all three. Deploy FIDO2 passkeys or hardware security keys for all engineers and admin accounts. -
Rotate all service account credentials and API keys
GitHub Actions tokens, AWS IAM access keys, CI/CD service accounts. Assume any credential that touched a public repo is compromised. Rotate immediately and audit rotation policy. -
Enable darknet monitoring for company domains and executive email addresses
IntelBroker sells company data. Darknet monitoring gives you advance warning when your data appears in breach forums before it becomes a customer notification crisis. -
Audit secrets in CI/CD pipelines — find and remediate exposed credentials
Run TruffleHog or GitGuardian across all repos. Every hardcoded credential found is a compromised credential. Move to Vault or cloud-native secrets management. -
Enable vendor and device certificate pinning for internal tools
Reduces risk of man-in-the-middle attacks on internal APIs. For SaaS platforms with internal tooling, ensure TLS everywhere and certificate validation is enforced. -
Audit all OAuth apps and integrations — remove unused or over-privileged grants
OAuth is the attack chain multiplier. Review every connected app in Okta/Azure/Google Workspace. Remove anything that doesn't have a current business justification. -
Enforce branch protection and require security scanning in CI/CD
GitHub/GitLab: require PR reviews, enable Dependabot, add secrets scanning in pre-merge pipelines. Every commit should be scanned before it lands in main. -
Create and test an incident response plan — document the first 4 hours
SEC Item 1.05 requires 4 business day disclosure. If you don't have a documented IR plan, the clock starts badly. Document containment, forensics, legal, and customer notification steps now.
-
Implement least-privilege OAuth token scopes per application
Map every SaaS integration and audit the scopes granted. If a Salesforce integration only needs read access to contacts, don't grant admin or write access. Scopes are the blast radius. -
Lock down third-party app integrations — enumerate and review every OAuth grant
Use OAuth scope audit tools or your IdP's connected apps dashboard. Create a quarterly review cadence for all OAuth grants. -
Enable SaaS endpoint detection and response (EDR) on all developer workstations and production servers
Tech companies have large attack surfaces on developer machines (access to prod, CI/CD, secrets). EDR on every endpoint is non-negotiable — Sentinel tier covers this. -
Deploy Secrets Manager (AWS Secrets Manager, GCP Secret Manager, or HashiCorp Vault) for all credentials
Move every API key, database password, and service account token out of code and config files. This is the most critical CI/CD security improvement for tech companies. -
Implement SSH key rotation policy — no static SSH keys for production access
Replace static SSH keys with ephemeral certificates via HashiCorp Vault or cloud-native certificate authority. Static SSH keys persist for years — they're a common lateral movement vector. -
Enable cloud provider security health alerts (AWS Security Hub, GCP Security Command Center, Azure Defender)
Configure alerts for: root account usage, public S3 buckets, security group changes, IAM policy modifications, and unusual API calls. 24/7 SOC should receive these alerts immediately. -
Conduct SaaS-to-SaaS integration audit — map the OAuth trust chain
Document every integration: which SaaS connects to which, what scopes are granted, what data is accessible. This becomes your tenant isolation and supply chain risk map. -
Implement package lock files + dependency scanning in all CI/CD pipelines
Pin every npm and PyPI dependency to a known-good version via lock files. Integrate Sonatype Nexus, Snyk, or GitHub Dependabot to flag known-vulnerable packages at build time.
-
Conduct a full penetration test — specifically test OAuth abuse and supply chain attack paths
Standard pen tests often miss OAuth token abuse and supply chain attack scenarios. Request a specific OAuth abuse scenario and a simulated npm/PyPI compromise in scope. -
Implement SBOM (Software Bill of Materials) generation for all build pipelines
SBOMs are becoming a procurement requirement (SEC, FedRAMP, enterprise contracts). Generate SBOMs for every release and store them with the artifact. SPDX or CycloneDX format. -
Establish formal incident response plan with tabletop exercise — test the first 4-hour playbook
Run a tabletop exercise with the engineering team, legal, and executive stakeholders. Test containment procedures, legal notification timelines (SEC 1.05 = 4 days; GDPR = 72 hours), and customer notification workflow. -
Enroll in threat intelligence feeds — FS-ISAC, CISA AIS, or comparable sector feeds
Sector-specific threat intel (FS-ISAC for fintech-adjacent tech, CISA AIS for all) gives your SOC early warning on campaigns targeting your vertical. IntelBroker, Scattered Spider, and Volt Typhoon TTPs are in these feeds. -
Assess FedRAMP Moderate / TX-RAMP applicability — determine if either is required for your customer base
If you sell to federal agencies or Texas state/local government customers, FedRAMP/TX-RAMP is a contract requirement, not an optional enhancement. CoreRecon's Command tier includes FedRAMP readiness assessments. -
Implement customer-tenant isolation audit — confirm multi-tenant data separation is enforced
Snowflake demonstrated that insufficient tenant isolation turns one breach into many. Audit your architecture: database credentials per customer, row-level security enforcement, cross-tenant query monitoring. -
Conduct LLM red team testing and AI security review if you have AI-native product features
OWASP LLM Top 10 is the baseline. Test: prompt injection, data exfiltration via model outputs, RAG vector database access controls, and model exfiltration scenarios. -
Document and test SEC Item 1.05 disclosure workflow with legal counsel
If you're public or near-IPO: material cyber incident disclosure in 4 business days. This requires pre-built disclosure templates, legal review workflow, and board communication procedures — not something you build during a breach.
Start with your
next move
Download the Full Brief
Get the complete PDF — 28 pages, 14 incidents, 4 full threat actor profiles, compliance crosswalk tables, 6-vector hardening checklists, and the full 30/60/90 roadmap with implementation guidance.
Sources: CISA KEV Catalog, FBI IC3, MS-ISAC, FS-ISAC, MITRE ATT&CK, IBM X-Force Threat Intelligence Index 2026, CrowdStrike 2026 Global Threat Report, Mandiant M-Trends 2026, Dell breach disclosure (May 2024), AT&T breach notifications (Mar 2024, Jul 2024), Samsung Austin Semiconductor INC Ransom disclosure (Aug 2024), Okta security notices (Jan 2022, Oct 2022), CISA AA24-038B (Volt Typhoon advisory, Jan 2024), SEC Item 1.05 Final Rule (Dec 2023). Research Report ID: 1301074.
Last updated: June 16, 2026. Threat intelligence current as of publication date.