North Texas Municipal Water District — serving 13 cities north of Dallas — disclosed a cyberattack by the Daixin ransomware group in November 2024. Business systems were impacted; water operational technology was reported unaffected.
Daixin ransomware group, known for targeting water and healthcare sectors, compromised NTMWD business systems. Double-extortion: data exfiltrated to Daixin's TOR leak site. Water OT boundary reportedly maintained.
Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →
| Regime | Standard / Citation | Gap Identified |
|---|---|---|
| AWIA | America's Water Infrastructure Act §2013 | Water utility cybersecurity assessment and emergency response plan not updated for ransomware threats |
| TDPA | Tex. B&C Code §521.053 | Any exfiltrated employee or contractor PII triggers TX notification requirement |
CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.
Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.