ResourcesTexas Breach Tracker › North Texas Municipal Water District
Municipal OT Actor: Daixin Remediated

North Texas Municipal Water District
Breach Analysis

North Texas Municipal Water District — serving 13 cities north of Dallas — disclosed a cyberattack by the Daixin ransomware group in November 2024. Business systems were impacted; water operational technology was reported unaffected.

Incident Date
2024-11-05
Records Exposed
TBD
Attack Type
OT
Threat Actor
Daixin

How they got in

Daixin ransomware group, known for targeting water and healthcare sectors, compromised NTMWD business systems. Double-extortion: data exfiltrated to Daixin's TOR leak site. Water OT boundary reportedly maintained.

Sentinel / Fortress / Command coverage

Sentinel Daixin TTPs mapped to SIEM rules via threat intelligence: C2 callback pattern detected pre-detonation
Fortress Exfiltration detection: large data transfer to TOR exit node triggers immediate DLP block and SOC alert
Command Water sector OT/IT boundary assessment: business and OT systems segmented and monitored; Daixin attack contained to business network

Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →

Regulatory exposure

Regime Standard / Citation Gap Identified
AWIA America's Water Infrastructure Act §2013 Water utility cybersecurity assessment and emergency response plan not updated for ransomware threats
TDPA Tex. B&C Code §521.053 Any exfiltrated employee or contractor PII triggers TX notification requirement

5-point hardening list

CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.

Is your organization hardened against this attack vector?

Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.