TX Municipal Intelligence — June 2026

Texas Municipalities
Cyber Threat Brief
2026

22 municipalities. 1 coordinated campaign. $2.5M refused. FBI CJIS v6.0 auditing is live — every Texas city is in scope. This brief documents what happened, who did it, and what you need to do before October 1, 2027.

  • 22 TX municipalities hit in Q4 2025 coordinated ransomware campaign
  • FBI Wave 1 & 2 municipal outreach lists partially leaked via Austin breach
  • CJIS v6.0 auditing active — full compliance deadline October 1, 2027
  • 5 threat actor profiles: Royal, LockBit 3.0, BlackCat, REvil, Volt Typhoon
  • 21-item 30/60/90 hardening roadmap — mapped to CJIS policy areas
22
TX municipalities hit in Q4 2025 coordinated campaign
$2.5M
Collective ransom demand — refused by all targets
Oct 1, 2027
CJIS v6.0 full compliance deadline — all TX municipalities in scope
$8.5M+
City of Dallas recovery cost from May 2023 Royal ransomware attack
Incident Database

22 Texas municipalities. One coordinated campaign.

The Q4 2025 coordinated ransomware campaign remains the largest municipal attack event in Texas history. Individual incidents span from Dallas (2023) through Borger, Mission, and the 2025 wave. FBI CJIS audit implications for each are documented where known.

Download the Full Threat Brief

The complete PDF includes full incident writeups, CJIS audit evidence requirements, and 21-item hardening checklist. Enter your work email to access it instantly.

No spam. One email with the PDF. Unsubscribe anytime.

City / Entity Severity Date Threat Actor Impact CJIS Impact
City of Dallas, TX Critical May 2023 Royal Police, courts, emergency comms disrupted for weeks. 311 and library systems forced offline. $8.5M+ recovery cost. FBI notification required. Criminal justice data in scope. Audit implications ongoing.
City of Mission, TX High Oct 2025 Undisclosed Supply-chain phishing through SaaS scheduling platform. Utility billing and internal comms disrupted 3 weeks. Wave 1 FBI outreach. CJIS audit scope active.
City of Borger, TX High 2025 REvil affiliate REvil affiliate attack disrupted public works and utility systems. City shut down public-facing web services 11 days. Criminal justice records in scope. CJIS audit implications unresolved.
City of Austin, TX High Jan 2026 LockBit 3.0 City employee data and FBI municipal outreach lists leaked. Wave 1 & 2 target names exposed publicly. Outreach list leak confirmed CJIS audit scope. FBI notification filed.
Travis County, TX Medium Q4 2025 Unknown (wave) Part of 22-municipality coordinated campaign. Partial systems impact — critical services maintained. Wave 1 FBI outreach. County criminal justice systems audited post-incident.
Fort Bend County, TX Medium Q4 2025 Unknown (wave) Coordinated campaign wave. County systems partially affected — public-facing services curtailed. Wave 1 FBI outreach. CJIS systems reviewed.
Comal County, TX Medium Q4 2025 Unknown (wave) County network partially impacted during coordinated campaign. Services restored within 2 weeks. Wave 1 FBI outreach. CJIS compliance review post-incident.
20 Additional TX Municipalities High Q4 2025 Coordinated campaign Collective $2.5M ransom demand. All targets refused payment. TX DIR and Texas Cybersecurity Framework activated. Wave 2 FBI outreach to multiple entities. Audit scope active across all targets.
Threat Actor Profiles

Who's targeting Texas municipalities?

Five threat actors represent the primary risk to Texas municipalities. Nation-state actors are interested in OT/ICS pre-positioning; ransomware groups target city governments for insurance leverage and data exfiltration.

Ransomware
Royal
Ransomware-as-a-Service · Active since 2022
Responsible for the City of Dallas attack (May 2023). Double-extortion model — data exfiltration before encryption. Royal uses legitimate Windows tools (Rclone, Cobalt Strike, BitLocker) making detection difficult. Known for specifically targeting municipal government networks and negotiating directly with city managers. TX municipalities remain a primary target.
Ransomware
LockBit 3.0
Ransomware-as-a-Service · Dismantled Apr 2024, resurged
Responsible for City of Austin breach (Jan 2026). The dismantled group re-emerged under new operators. LockBit historically targets municipalities because they often have cyber insurance and limited IT security staff. Austin breach exposed FBI outreach lists — demonstrating the intelligence value of municipal network compromise beyond direct ransom.
Ransomware
BlackCat / ALPHV
Ransomware-as-a-Service · Healthcare/Government focus
Targeted Change Healthcare (Feb 2024, $22M ransom) and multiple TX municipalities. BlackCat's EX-ABUNDANCE model combines data theft with encryption. Exploits known vulnerabilities in municipal unpatched systems. The group disbanded in mid-2024 but affiliates continue operations under other names — ALPHV's code was open-sourced.
Ransomware
REvil / Sodinokibi
Ransomware-as-a-Service · State-linked affiliates
Responsible for City of Borger attack. REvil's affiliate model means the same toolkit hits different targets — Borger was likely a smaller affiliate using pre-configured tooling. REvil affiliates specifically look for municipalities with CJIS data because it creates negotiating leverage (law enforcement access as a hostage).
Nation-State
Volt Typhoon
China MSS · OT Pre-positioning · Living-off-the-land
CISA AA24-038A (Feb 2024): Volt Typhoon has had persistent access to U.S. critical infrastructure — including energy, water, and municipal utility OT — since mid-2022. The actor uses LOLBins to blend into normal network traffic, evading every signature-based EDR. Goal is sabotage capability for conflict activation, not financial theft. TX municipalities running water, wastewater, or traffic systems are explicitly in scope.
CJIS v6.0 Compliance Crosswalk

13 policy areas. All in active audit scope.

FBI CJIS v6.0 auditing is live. Every Texas municipality is in scope through October 1, 2027. CoreRecon maps all 13 CJIS security policy areas to SOC monitoring tiers — and generates audit-ready evidence packages automatically.

01
Information Exchange
Sentinel → Encrypted CJI handling
Common gap: Unencrypted email for criminal justice data, missing MOUs with third-party vendors
02
Security Awareness Training
Sentinel → Annual training, documentation
Common gap: Training completed but undocumented, incomplete annual refreshers, contractor gaps
03
Incident Response
Command → 24/7 SOC, 30-min SLA
Common gap: No formal IR plan, response times undocumented, no TX DPS reporting mechanism
04
Auditing & Accountability
Sentinel → Automated log retention, 90-day minimum
Common gap: Insufficient log retention, no user-level audit trails, logs not reviewed monthly
05
Access Control
Sentinel → RBAC, least-privilege, background checks
Common gap: Overly broad access, no formal role assignments, background checks not completed
06
Identification & Authentication
Sentinel → MFA, unique IDs, password standards
Common gap: Shared accounts, no MFA for remote CJIS access, weak password policies
07
Configuration Management
Fortress → CMDB, change approval workflow
Common gap: No formal baseline documentation, ad-hoc changes without approval, no CMDB
08
Media Protection
Sentinel → Encryption, chain-of-custody logging
Common gap: Unencrypted USB/storage, no destruction certificates, media not tracked
09
Physical Protection
Sentinel → Badge access, workstation standards
Common gap: No badge access, visitor logging incomplete, CJI data on open workstations
10
Systems & Communications Protection
Fortress → Firewall, IDS/IPS, VPN enforcement
Common gap: No IDS/IPS, firewall rules undocumented, remote access without VPN
11
Formal Audits
Command → Annual CJIS audits, corrective action plans
Common gap: No self-assessment, findings not tracked, no audit-ready documentation
12
Personnel Security
Sentinel → Reinvestigation tracking, access revocation
Common gap: No reinvestigation schedule, access not revoked on termination
13
Mobile Devices
Fortress → MDM, encryption, remote wipe
Common gap: No MDM, personal devices accessing CJI, no remote wipe capability
Attacker's Playbook

Why municipalities. Why now.

Local governments account for 38% of all Texas ransomware incidents in 2025. The math is simple: limited security staff, high-value CJIS data, and cyber insurance make municipalities the highest-ROI target in the state.

CJIS Leverage
Criminal Justice Data as Hostage
Highest-value municipal target
CJIS data — criminal records, warrant information, NCIC access — creates negotiating leverage that普通 corporate targets don't have. Attackers know that city managers face a binary choice: lose FBI database access (and therefore law enforcement capability) or pay the ransom. This is why criminal justice data is specifically targeted in municipal ransomware campaigns.
Supply Chain Pivot
SaaS Platforms as Delivery Vector
Used in Q4 2025 campaign
The Q4 2025 coordinated campaign used a legitimate SaaS scheduling platform as a phishing delivery mechanism. Municipal employees received legitimate-looking calendar invites that bypassed email filtering because the sender domain was trusted. CoreRecon's Sentinel tier includes supply-chain email monitoring that flags anomalous sender patterns across all integrated SaaS tools.
Insurance Leverage
Cyber Insurance as Trigger
Municipal ransomware economics
Municipal cyber insurance policies have created a perverse incentive structure. Attackers know that cities with cyber insurance are more likely to pay — and insurance payouts fund recovery without public procurement scrutiny. This is why ransomware groups specifically research a target's cyber insurance coverage before setting ransom demands. CoreRecon helps municipalities demonstrate security maturity to reduce insurance premiums.
OT Targeting
Water, Wastewater, Traffic OT
Volt Typhoon pre-positioning target
Volt Typhoon specifically targets OT/ICS networks in municipal utility systems — water treatment, wastewater, traffic control. Pre-positioning inside these networks creates sabotage capability that serves geopolitical goals, not financial ones. A Texas city running CoreRecon Fortress or Command tier has OT-specific monitoring that can detect the LOTL techniques Volt Typhoon uses to hide in municipal networks.
30 / 60 / 90 Day Roadmap

What your municipality needs to do.

Every action below maps to a specific CJIS v6.0 policy area and a CoreRecon SOC tier. Start with Day 1 — the audit clock is already running.

Days 1–30
CJIS Policy Areas 2, 5, 6, 9
Enable MFA on all remote access — Policy Area 6 (Identification & Auth). Prioritize IT admin accounts and VPN access.
Document CJIS access roles — Policy Area 5 (Access Control). Map every user with CJIS system access to a defined role.
Complete security awareness training records — Policy Area 2. Every CJIS-accessed employee needs documented annual training.
Audit physical security at PD and courts — Policy Area 9. CJI data on workstations in open areas is a common audit failure point.
Rotate service account passwords — Policy Area 6. Q4 2025 campaign exploited stale service credentials.
Enable audit log collection (90-day retention) — Policy Area 4. Implement automated log forwarding to a SIEM.
Run CJIS readiness self-assessment — Policy Area 11. Baseline your current state against the 13 policy areas.
Days 31–60
CJIS Policy Areas 1, 4, 7, 8, 10
Enforce CJI encryption in transit — Policy Area 1. All criminal justice data must be encrypted across email and file transfer.
Build a formal incident response plan — Policy Area 3. Include TX DPS reporting mechanism and 30-min SLA documentation.
Implement CMDB and change management — Policy Area 7. Document baseline configurations for all CJIS-connected systems.
Audit and encrypt all mobile devices — Policy Area 13. Implement MDM with remote wipe for all devices accessing CJI.
Encrypt all portable media — Policy Area 8. Implement BitLocker/TFALSE for USB and external drives containing CJI.
Deploy IDS/IPS at network perimeter — Policy Area 10. CoreRecon Fortress includes managed firewall and IDS/IPS for municipal networks.
Establish monthly audit log review process — Policy Area 4. Automate the review and generate compliance reports.
Days 61–90
CJIS Policy Areas 3, 11, 12 + OT Security
Enroll in 24/7 SOC monitoring — Policy Area 3 (Incident Response). 30-minute response SLA required for CJIS compliance.
Complete annual CJIS self-assessment — Policy Area 11. Generate audit-ready evidence package with automated documentation.
Implement automated access revocation — Policy Area 12. Termination checklists and 24-hour access revocation on employee departure.
Conduct OT/ICS security assessment — Water, wastewater, traffic control. Volt Typhoon pre-positioning requires OT-specific monitoring.
Document all third-party MOUs — Policy Area 1. Any vendor with CJIS data access needs a written MOU and security questionnaire.
Run tabletop incident response exercise — Policy Area 3. Test the IR plan with PD, courts, and city manager's office participation.
Generate CJIS audit evidence package — Policy Area 11. CoreRecon Command tier automates evidence generation for FBI CJIS audits.
Free Tool · CJIS SP v6.0 · 13 Policy Areas · Auditor-Ready PDF
CJIS v6.0 Audit Readiness Checklist
Map your gaps across all 13 CJIS policy areas. Assign remediation owners, target dates, and effort estimates. Export an auditor-ready PDF before TX DPS arrives — no sales call, no cost.
Build My Audit Checklist →
Your Next Step

The audit clock is running.

Every day without SOC coverage is a day your municipality is more exposed than the last. CoreRecon delivers CJIS-mapped monitoring, 30-minute response SLA, and audit-ready evidence packages at $89–$129/endpoint — priced for municipal budgets.

Get Your Free $2,500 Assessment →

No contracts. No minimums. SDVOSB preferred vendor.