The City of Dallas was struck by Royal ransomware in May 2023, taking down police, fire dispatch, and court systems. Recovery took months and cost the city over $8.5M. Approximately 26,212 individuals had personal data exposed.
Royal ransomware group used phishing email to establish initial foothold. Dwell time estimated at several weeks before payload detonation. CJIS-connected police systems affected, triggering FBI involvement. Threat actor exfiltrated data before encrypting — double-extortion tactic.
Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →
| Regime | Standard / Citation | Gap Identified |
|---|---|---|
| CJIS | CJIS SP v6.0 §5.3.1 | Incident response plan — no documented IRP for CJIS-connected systems; police CAD unprotected |
| CJIS | CJIS SP v6.0 §5.13.1 | IT vendor security policy — managed services security requirements not enforced contractually |
| TDPA | Tex. B&C Code §521.053 | 26,212 TX residents notified — notification required within 60 days of discovery |
CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.
Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.