ResourcesTexas Breach Tracker › 22 Texas Municipalities (Coordinated Wave)
Municipal Ransomware Remediated

22 Texas Municipalities (Coordinated Wave)
Breach Analysis

A coordinated ransomware campaign struck 22 Texas municipalities in Q4 2025, demanding a collective $2.5M ransom. All targets refused payment. Affected entities included cities in Bexar, Travis, El Paso, Hays, Brazoria, and Comal counties.

Incident Date
2025-10-01
Records Exposed
Unknown
Attack Type
Ransomware
Threat Actor
Unconfirmed

How they got in

Supply-chain style attack leveraging a shared municipal IT managed services provider. Initial access via compromised MSP credentials; single pivot enabled simultaneous lateral movement across all 22 client networks. CJIS-connected systems affected, triggering FBI notification requirements.

Sentinel / Fortress / Command coverage

Sentinel Anomalous MSP credential usage across multiple client networks simultaneously would trigger cross-client correlation alert within minutes
Sentinel SIEM rules for CJIS-adjacent system access from unusual source IP — real-time alert before lateral movement completes
Fortress Privileged access management: MSP vendor access via just-in-time provisioning eliminates standing credential risk
Command vCISO supply-chain risk assessment would have flagged shared MSP as single point of failure — contractual IR obligations and segmentation requirements added before attack

Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →

Regulatory exposure

Regime Standard / Citation Gap Identified
CJIS CJIS SP v6.0 §5.13 Third-party vendor access controls — MSP lacked CJIS-compliant access provisioning
CJIS CJIS SP v6.0 §5.3 Incident response — no documented IR plan for municipal IT; FBI notification delayed
TDPA Tex. B&C Code §521.053 Breach notification obligations triggered for citizen PII across multiple municipalities

5-point hardening list

CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.

Is your organization hardened against this attack vector?

Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.