ResourcesTexas Breach Tracker › Bexar County Appraisal District
Municipal Exfil Under Investigation

Bexar County Appraisal District
Breach Analysis

Bexar County Appraisal District reported unauthorized access to property records and taxpayer data in March 2025. Approximately 890,000 property owner records with addresses, ownership history, and valuation data were exposed.

Incident Date
2025-03-07
Records Exposed
890,000
Attack Type
Exfil
Threat Actor
Unconfirmed

How they got in

Misconfigured public-facing database API exposed taxpayer property records without authentication. Automated scraping tools harvested records over several weeks before internal monitoring caught the volume anomaly.

Sentinel / Fortress / Command coverage

Sentinel API rate limiting and anomaly detection: sustained high-volume query pattern from single IP triggers alert and automatic throttle
Fortress Configuration management: public-facing API security baseline review catches unauthenticated database endpoint
Command TDPA compliance audit identifies public-facing APIs containing PII as requiring authentication and audit logging

Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →

Regulatory exposure

Regime Standard / Citation Gap Identified
TDPA Tex. B&C Code §521.053 890,000 Bexar County residents required breach notification
TDPA Tex. B&C Code §521.052 Reasonable procedures to protect sensitive PII — unauthenticated database API violates reasonable care standard

5-point hardening list

CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.

Is your organization hardened against this attack vector?

Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.