ResourcesTexas Breach Tracker › Texas Department of Transportation
Municipal Supply chain Under Investigation

Texas Department of Transportation
Breach Analysis

Texas Department of Transportation reported a supply-chain incident in May 2025 affecting approximately 350,000 records. A third-party document management vendor used by TxDOT was compromised, exposing contractor and employee records.

Incident Date
2025-05-19
Records Exposed
350,000
Attack Type
Supply chain
Threat Actor
Unconfirmed

How they got in

Third-party document management vendor that stored TxDOT contractor and employment records suffered a breach. Attacker gained access to the vendor's customer data environment and exfiltrated TxDOT records along with other state agency data.

Sentinel / Fortress / Command coverage

Command Vendor risk assessment: document management vendor would require annual SOC 2 Type II report; breach discovered during vendor review cycle, not after exfiltration
Fortress Third-party data handling requirements in contract: vendor must notify within 24 hours of any suspected breach — contractual obligation accelerates disclosure
Sentinel Data flow monitoring: PII sent to vendor tracked; alert on vendor breach via subscription to third-party risk intelligence feeds

Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →

Regulatory exposure

Regime Standard / Citation Gap Identified
TDPA Tex. B&C Code §521.053 350,000 TX records triggered mandatory AG notification
CMMC CMMC Level 1 §SC.L1-3.13.1 If CUI/defense contractor data present: CMMC supply chain requirement applies

5-point hardening list

CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.

Is your organization hardened against this attack vector?

Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.