CoreRecon Threat Intelligence  •  Texas Oil & Gas Operators  •  August 2026 V57

TX Oil & Gas:
TSA SD-02F / SEC Item 1.05 / CIRCIA / RRC §3.71 / Volt Typhoon IT-OT

Halliburton TX $35M RansomHub direct loss (Aug 2024, SEC 8-K Item 1.05 confirmed). Colonial Pipeline (Houston-origin, May 2021, DarkSide via reused VPN credential) — first-ever U.S. East Coast fuel pipeline shutdown. Newpark Resources Woodlands TX ransomware (Oct 2024). ENGlobal Corp Houston TX — 6-week business outage (Nov 2024 – Jan 2025) third-party-SCADA-integrator cascade. Dragos VOLTZITE tracking cellular-RTU/SCADA-gateway credential compromise 2024–2025. Volt Typhoon IT/OT pre-positioning in U.S. energy since 2021 per CISA/NSA AA24-038A. Texas oil & gas operators face TSA SD-02F (effective May 3, 2025) + SEC Item 1.05 4-business-day + CIRCIA 72-hr + RRC of TX 16 TAC §3.71 + TDPSA §541 — five parallel regulatory clocks on the same set of facts.

Download the Full Threat Brief — Free
August 2026 CoreRecon Intelligence Report V57 TSA SD-02F + SEC Item 1.05 + CIRCIA + RRC §3.71 + TDPSA 60+ Verified Sources
$35M
Halliburton TX
RansomHub direct loss
SEC 8-K Item 1.05
935%
YoY ransomware surge
vs. oil & gas
Zscaler 2025
May 3'25
TSA SD-02F
Cybersecurity
Implementation Plan
4day
SEC Item 1.05
cyber-incident
disclosure clock
< 30min
CoreRecon IR SLA
beats TSA SD-02F
12-hr CISA clock
What This Brief Covers

TX Oil & Gas Operators
OT/ICS Threat Brief

Full intelligence report on the OT/ICS attack surface facing Texas oil & gas operators — from the Halliburton TX $35M RansomHub direct loss (Aug 2024, SEC 8-K Item 1.05 confirmed), Colonial Pipeline Houston-origin 6-day shutdown (May 2021, DarkSide via reused VPN credential with no MFA), Newpark Resources Woodlands TX ransomware (Oct 2024), and ENGlobal Corp Houston TX third-party-SCADA-integrator 6-week business outage (Nov 2024 – Jan 2025) to the Dragos VOLTZITE-documented cellular-RTU/SCADA-gateway credential compromise + Hanna UT Pump Station TX PLC ransomware proof-point, the Volt Typhoon IT/OT pre-positioning in U.S. energy since 2021 (CISA/NSA AA24-038A), the five parallel-narrative regulatory clocks (TSA SD-Pipeline-2021-01D + SD-02F effective May 3, 2025, SEC Item 1.05 4-business-day, CIRCIA 72-hr, RRC of TX 16 TAC §3.71, TDPSA §541 + CMMC 2.0 where defense-adjacent), and the SCADA air-gap myth + Modbus/DNP3/OPC-UA/EtherNet-IP + PI historian exfil + cellular-RTU gateway + VPN-credential reuse + Emerson DeltaV/Honeywell Experion/Rockwell ControlLogix vendor remote-access attack surface. Coverage built for Permian Basin upstream E&P operators, Houston-headquartered midstream pipeline + gas processing + downstream refining + Woodlands TX OFS-adjacent service companies, defense fuel supply chain operators, retail gas marketers, and small gas LDCs below TSA SD-02F threshold (covered by 49 CFR Part 192/195 + RRC §3.71).

60+ Verified Sources Including:

  • Halliburton TX — $35M RansomHub direct loss (Aug 2024), SEC 8-K Item 1.05 filed + Q4 2024 SEC 10-K disclosure; OT/IT convergence risk validated; SEC Item 1.05 precedent for every TX SEC-registered oil & gas issuer
  • Colonial Pipeline — Houston-origin, May 2021, 6-day shutdown via single reused VPN credential with no MFA; first-ever U.S. East Coast fuel pipeline closure; ~$4.4M DarkSide ransom
  • Newpark Resources Woodlands TX (Oct 2024) — NYSE-listed oilfield services ransomware confirmed
  • ENGlobal Corp Houston TX (Nov 2024 – Jan 2025) — third-party SCADA integrator to multiple TX midstream operators; 6-week business outage documented
  • Dragos VOLTZITE 2024–2025 + Hanna UT Pump Station TX — PRC state-sponsored targeting profile + Texas PLC ransomware case study
  • TSA SD-Pipeline-2021-01D series + TSA SD-02F (effective May 3, 2025) — Cybersecurity Implementation Plan required; 12-hr CISA cyber-incident window
  • SEC Item 1.05 (effective December 18, 2023) — 4-business-day cyber-incident disclosure from materiality determination
  • CIRCIA 72-hr CISA — covered energy + pipeline entities; final-rule pending; concurrent narrative
  • RRC of TX 16 TAC §3.71 + HB 1208 (2023) + SB 3 / SB 1928 (2025) — TX Railroad Commission cyber-induced-release reporting path explicitly authorized
  • TDPSA §541 — utility customer usage/billing PII + employee PI enumeration; §521.053 breach notification trigger
  • 8 oil & gas-specific controls + 30/60/90-day SD-02F / SEC Item 1.05 / RRC §3.71 + pre-authorized SCADA isolation playbook roadmap + Sentinel/Fortress/Command tier fit for 25–500 endpoints

Access the Full Brief

We email it as a PDF attachment. No newsletter. No spam. One delivery.

We use the contact details you provide to deliver this brief and respond to your request. Please do not include patient, client, account, case, or other sensitive information in this form.

Submission failed — please try again or email john@corerecon.com

Brief Sent.

Check your inbox — the PDF is on its way. If it lands in spam, drag it to your inbox so you find it later.

Want it immediately? Download below — we already emailed a copy.

Download PDF Now → Book Free Assessment →

Questions before then? Call (800) 955-2596 — live TX SOC, not a call center.

SDVOSB Certified • TX-Based SOC • No offshore data routing
Questions? (800) 955-2596
✅ 60+ verified sources
✅ TSA SD-Pipeline-2021-01D + SD-02F + SEC Item 1.05 + CIRCIA + RRC §3.71 + TDPSA covered
✅ 8-control oil & gas-mapped coverage
✅ 6 named TX oil & gas anchors: Halliburton, Colonial, Newpark, ENGlobal, VOLTZITE, Hanna UT
✅ 30/60/90-day SD-02F + SEC Item 1.05 + RRC §3.71 roadmap