Texas Department of Transportation reported a supply-chain incident in May 2025 affecting approximately 350,000 records. A third-party document management vendor used by TxDOT was compromised, exposing contractor and employee records.
Third-party document management vendor that stored TxDOT contractor and employment records suffered a breach. Attacker gained access to the vendor's customer data environment and exfiltrated TxDOT records along with other state agency data.
Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →
| Regime | Standard / Citation | Gap Identified |
|---|---|---|
| TDPA | Tex. B&C Code §521.053 | 350,000 TX records triggered mandatory AG notification |
| CMMC | CMMC Level 1 §SC.L1-3.13.1 | If CUI/defense contractor data present: CMMC supply chain requirement applies |
CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.
Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.