Bexar County Appraisal District reported unauthorized access to property records and taxpayer data in March 2025. Approximately 890,000 property owner records with addresses, ownership history, and valuation data were exposed.
Misconfigured public-facing database API exposed taxpayer property records without authentication. Automated scraping tools harvested records over several weeks before internal monitoring caught the volume anomaly.
Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →
| Regime | Standard / Citation | Gap Identified |
|---|---|---|
| TDPA | Tex. B&C Code §521.053 | 890,000 Bexar County residents required breach notification |
| TDPA | Tex. B&C Code §521.052 | Reasonable procedures to protect sensitive PII — unauthenticated database API violates reasonable care standard |
CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.
Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.