ResourcesTexas Breach Tracker › City of Dallas
Municipal Ransomware Actor: Royal Remediated

City of Dallas
Breach Analysis

The City of Dallas was struck by Royal ransomware in May 2023, taking down police, fire dispatch, and court systems. Recovery took months and cost the city over $8.5M. Approximately 26,212 individuals had personal data exposed.

Incident Date
2023-05-03
Records Exposed
26,212
Attack Type
Ransomware
Threat Actor
Royal

How they got in

Royal ransomware group used phishing email to establish initial foothold. Dwell time estimated at several weeks before payload detonation. CJIS-connected police systems affected, triggering FBI involvement. Threat actor exfiltrated data before encrypting — double-extortion tactic.

Sentinel / Fortress / Command coverage

Sentinel 24/7 SOC monitoring: weeks-long dwell time with C2 callbacks would generate network anomaly alerts — mean time to detect drops from weeks to hours
Sentinel Email threat detection: Royal ransomware phishing TTPs have known signatures; sandbox detonation of attachment catches payload pre-execution
Fortress Vulnerability management: Royal ransomware exploits known CVEs in public-facing apps — patched within 72-hour SLA under Fortress tier
Command CJIS compliance mapping ensures police CAD systems have network isolation and documented IR plan — FBI notification workflow pre-built

Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →

Regulatory exposure

Regime Standard / Citation Gap Identified
CJIS CJIS SP v6.0 §5.3.1 Incident response plan — no documented IRP for CJIS-connected systems; police CAD unprotected
CJIS CJIS SP v6.0 §5.13.1 IT vendor security policy — managed services security requirements not enforced contractually
TDPA Tex. B&C Code §521.053 26,212 TX residents notified — notification required within 60 days of discovery

5-point hardening list

CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.

Is your organization hardened against this attack vector?

Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.