49 million Dell customer records exposed. AT&T call logs on the dark web. Okta cascading into TX SaaS. Four threat actors with active TX tech campaigns. Here's what you need to know — and what to do about it.
The Austin/Plano/Dallas tech corridor is one of the most concentrated tech ecosystems in the US. Dell (Round Rock), Samsung (Austin), AT&T (Dallas), and hundreds of SaaS companies serving Fortune 500 clients call this region home. That concentration makes it a primary target for threat actors who understand that breaching a single vendor or platform gives them access to thousands of downstream customers.
14 documented incidents. Scroll or use the filter to find relevant events by attack type or region.
| Date | Entity | Location | Records | Attack Vector | Threat Actor | TX Impact |
|---|---|---|---|---|---|---|
| Dec 2020 | SolarWinds | Austin HQ | ~18,000 TX customers affected, CUI, credentials | Supply chain injection (SUNBURST backdoor in Orion update) | APT / SVR (Russia) | ✓ Austin HQ |
| Jan 2022 | Okta (LAPSUS$ breach) | San Francisco (TX SaaS cascade) | Customer support tool access, 366 customers affected | Subcontractor laptop compromise via personal Google account | LAPSUS$ | ✓ TX SaaS cascade |
| Oct 2022 | Okta (duplicate) | — | Re-used same support tool access from Jan 2022 | Same subcontractor access vector persisted | LAPSUS$ | ✓ TX SaaS cascade |
| May 2023 | MOVEit Transfer (TX cascade) | Progress Software (MA, TX SaaS victims) | TX HRIS, payroll, benefits admin systems compromised | SQL injection (CVE-2023-34362) — zero-day exploit | Cl0p / LockBit affiliates | ✓ TX SaaS + HRIS cascade |
| May 2024 | Dell Technologies | Round Rock, TX | ~49 million customer records exposed | Partner portal API exposing customer PII without auth | Unknown (discovered by researcher) | ✓ TX HQ — Round Rock |
| Aug 2024 | Samsung Austin Semiconductor + US customers | Austin, TX | Employee data + US customer data exfiltrated | Unknown initial access, exfil via internal systems | INC Ransom | ✓ Austin HQ — direct victim |
| Sep 2024 | Dell (second incident) | Round Rock, TX | 10,863 employee records via internal system exposure | Internal system misconfiguration, credentials accessible | Unknown | ✓ TX HQ — direct victim |
| Mar 2024 | AT&T (dark web SSN/passcode breach) | Dallas, TX | 73M current + former customer records on dark web | Credential stuffing + data broker aggregation — AT&T attributed to 2021 breach | ShinyHunters (dark web actor) | ✓ Dallas HQ — direct victim |
| Jul 2024 | AT&T (Snowflake call records) | Dallas, TX | Nearly all AT&T cellular customers — call + text records | Snowflake platform breach (MFA not enforced on admin account) | UNC5536 (Snowflake campaign) | ✓ Dallas HQ — second incident |
| 2023 | 23andMe (TX user data) | South San Francisco (TX users affected) | TX user genetic data exposed via credential stuffing wave | Credential stuffing (password reuse across platforms) | Unknown | ✓ TX users — credential stuffing wave |
| 2024 | GitHub Actions (TX startups — UNC4902) | GitHub (TX startup CI/CD exposure) | Source code secrets, OAuth tokens, CI/CD pipeline access | GitHub OAuth app token theft via malicious GitHub Actions | UNC4902 (UNC Threat Group) | ✓ TX startup CI/CD exposure |
| 2023–2024 | PyPI / npm (TX Python/JS SaaS supply chain) | PyPI + npm registries (TX Python/JS SaaS exposure) | Malicious packages exfiltrating env vars, secrets, API keys from CI/CD | Typosquatting, dependency confusion, compromised maintainer accounts | Multiple threat actors | ✓ TX Python/JS SaaS supply chain |
| 2024–ongoing | IntelBroker (TX tech company data) | Online dark web forum (ongoing) | Ongoing sales of TX tech company data, internal credentials, source code | Initial access via vulnerability exploitation, insider access purchase | IntelBroker | ✓ IntelBroker selling TX tech data |
| 2024 | Snowflake-attributed TX portcos (multiple) | Snowflake platform (TX SaaS companies affected) | Customer data, authentication tokens, downstream access | Snowflake admin account compromise (no MFA), token reuse across platforms | UNC5536 / UNC4899 (attribution to Scattered Spider) | ✓ TX SaaS portcos — Snowflake cascade |
Your customers are requiring these frameworks. Your procurement team needs to be ready. One breach may trigger multiple frameworks simultaneously.
| Framework | Applies To | Key Requirement | What To Do |
|---|---|---|---|
| SOC 2 Type II | All SaaS companies with enterprise customers | Annual audit: security, availability, confidentiality, privacy. Continuous monitoring of controls. | Engage a CPA firm for Type II audit. CoreRecon covers the security controls that auditors check: access management, change management, monitoring, incident response. |
| ISO 27001 / 27017 / 27018 | Cloud providers, SaaS, enterprise customers requiring international coverage | 27001: ISMS. 27017: cloud-specific controls. 27018: PII in cloud. Third-party certified. | ISO certification is a procurement requirement for many EU and enterprise customers. CoreRecon maps controls to ISO 27001 and 27017. |
| FedRAMP Moderate | SaaS companies selling to federal agencies, including TX state/local agencies via TX-RAMP | Third-party assessment organization (3PAO) assessment, CSP package, agency authorization. | FedRAMP Moderate is a prerequisite for federal agency contracts. If you sell to any government entity, TX-RAMP is the Texas state equivalent (launched 2024). CoreRecon's Command tier covers FedRAMP/TX-RAMP readiness. |
| TX-RAMP | Companies selling SaaS to Texas state agencies and local governments | TX Risk and Authorization Management Program — similar to FedRAMP at state level. Required for TX public sector contracts. | Assess applicability against your customer base. CoreRecon maps TX-RAMP requirements and helps build the SSP and POA&M. |
| CMMC L2 | Companies handling CUI for DoD contractors (includes SaaS serving defense contractors) | 110 controls from NIST 800-171. Third-party assessment required by Nov 10, 2026 for many contractors. | If any customer is a defense contractor, your handling of their data may require CMMC L2. CoreRecon covers CMMC L2 controls in our DoD contractor packages. |
| HIPAA | SaaS companies with healthcare customers (BAA required if PHI processed) | Business Associate Agreement required. Breach notification within 60 days. Security, technical, and administrative safeguards. | If you have healthcare clients, you need a BAA. Breach of your platform becomes a HIPAA reportable event for your healthcare customers. CoreRecon covers HIPAA controls in our Healthcare tier. |
| PCI DSS v4.0.1 | SaaS companies processing payment card data (enterprise B2B platforms with payment flows) | 12 requirements, 64 base requirements, growing to 70+ in v4.0.1 mandatory updates. Requires formal risk assessment annually. | For SaaS companies that process payments on behalf of clients, PCI DSS may apply at a merchant level. CoreRecon can scope and assess PCI applicability. |
| GDPR / CPRA / TDPSA | SaaS companies with EU users (GDPR), California residents (CPRA), TX residents (TDPSA) | GDPR: EU residents — 72-hr breach notification, DPO required. CPRA: CA residents — right to delete, opt-out. TDPSA: TX residents — data broker obligations, breach notification. | TX TDPSA (effective July 2024) is the newest Texas data privacy law. Data broker registration, consumer rights requests, breach notification timelines. GDPR and CPRA are standard for any SaaS with broad consumer or enterprise use. CoreRecon's privacy compliance support covers all three. |
| SEC Item 1.05 | Publicly traded tech companies (pre-IPO companies with SEC filings) | Material cybersecurity incidents must be disclosed in 4 business days (Form 8-K). Annual disclosure of cyber risk management. | If you're public or near-IPO, SEC Item 1.05 means your breach notification clock is 4 business days — not the GDPR 72 hours. The IR plan has to be ready before a breach, not after. CoreRecon's Command tier includes SEC Item 1.05 IRP documentation. |
24 concrete checklist items. Prioritized by impact and urgency for tech companies in the Austin/Plano/Dallas/Houston corridor.
Get the complete PDF — 28 pages, 14 incidents, 4 full threat actor profiles, compliance crosswalk tables, 6-vector hardening checklists, and the full 30/60/90 roadmap with implementation guidance.