ResourcesTexas Breach Tracker › Lone Star Legal Aid (Houston)
Legal Ransomware Remediated

Lone Star Legal Aid (Houston)
Breach Analysis

Lone Star Legal Aid, a Houston-based nonprofit legal services organization, disclosed a ransomware attack affecting 22,000 client case files containing sensitive legal and financial information.

Incident Date
2024-05-15
Records Exposed
22,000
Attack Type
Ransomware
Threat Actor
Unconfirmed

How they got in

Phishing email with ransomware payload delivered to attorney. Compromised workstation used to move laterally across flat network to case management server.

Sentinel / Fortress / Command coverage

Sentinel Email sandbox: ransomware attachment detonated in isolation — malicious payload identified before attorney opens file
Fortress EDR on attorney workstations: ransomware behavior detected at execution stage — process tree killed before file encryption begins
Command Texas DR 1.05 and Ethics Opinion 712 compliance mapping: flat network topology identified as attorney-client privilege risk; remediation required

Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →

Regulatory exposure

Regime Standard / Citation Gap Identified
ABA Texas DR 1.05 Confidentiality of client information — 22,000 client legal files exposed
TDPA Tex. B&C Code §521.053 TX client notifications required within 60 days of discovery

5-point hardening list

CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.

Is your organization hardened against this attack vector?

Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.