惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

罗磊的独立博客
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
Visual Studio Blog
MyScale Blog
MyScale Blog
M
MIT News - Artificial intelligence
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
T
The Blog of Author Tim Ferriss
Martin Fowler
Martin Fowler
博客园 - 【当耐特】
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
宝玉的分享
宝玉的分享
Engineering at Meta
Engineering at Meta
WordPress大学
WordPress大学
Google DeepMind News
Google DeepMind News
C
Check Point Blog
Last Week in AI
Last Week in AI
F
Fortinet All Blogs
博客园 - 聂微东
Blog — PlanetScale
Blog — PlanetScale
H
Help Net Security
GbyAI
GbyAI
云风的 BLOG
云风的 BLOG

Malwarebytes

Kali365 phishing kit bypasses MFA and steals Microsoft logins Company bragged phone mics could listen to conversations. They couldn’t. Fake LinkedIn emails abuse Adobe to track victims Fake software on GitHub and SourceForge distribute Deno RAT 700+ education and tech websites hijacked in huge ClickFix malware campaign Scammers pretending to be Microsoft had help from US executives A week in security (May 18 – May 24) Update Chrome now: Critical bugs could let attackers run code Microsoft Defender vulnerabilities are being exploited in the wild TikTok, YouTube, and Roblox face scrutiny, but age gates won’t fix child safety Catch spyware in the act with Windows Webcam Monitoring Researchers left AI agents alone in a virtual town and watched it all unravel Fake malware-signing service Fox Tempest dismantled by Microsoft Firefox 151 packs big privacy upgrades into a small update Biometrics, diagnoses, and bank details exposed in major healthcare breach Facebook scam promises cheap Aldi meat boxes, steals payment info instead YouTube wants your face to fight deepfakes Microsoft is changing Edge’s plaintext password behavior A week in security (May 11 – May 17) AI is distorting the Holocaust (Lock and Code S07E10) Attackers replaced JDownloader installer downloads with malware Meta’s confusing new approach to chat privacy Why Malwarebytes blocks some Yahoo Mail redirects Deepfake sextortion forces schools to remove student photos from websites Texas sued Netflix over claims it secretly collected and sold users’ data May 2026 Patch Tuesday: no zero-days but plenty to fix Fake Claude search results lure Mac users into ClickFix attack 1 in 8 employees have sold company logins or know someone who has Stolen Canvas data was “returned” after hacker agreement, Instructure says Yarbo responds to robot flaws that could mow down their owners
Hackers steal passport and driver's license data of 3 mil...
Danny Bradbury · 2026-06-23 · via Malwarebytes

You can change a password and cancel a card. But replacing a passport or driver’s license number every time someone leaves yours unsecured in a vendor database isn’t so easy.

More than three million Texans are facing that problem after a data breach involving a vendor used by the Texas Parks and Wildlife Department (TPWD) to process hunting and fishing licenses.

In an announcement confirming the breach, TPWD says the hackers gained access through the third-party vendor’s systems and exposed personal information belonging to 3,087,721 people. The agency says the exposed data may include driver’s license information, passport numbers, email addresses, phone numbers, and residential addresses.

However, exactly what information was stolen remains unclear.

Conflicting accounts of what was exposed

In a breach notification filed with the Texas Attorney General’s office, TPWD said the incident affected:

  • Name of individual
  • Address
  • Social Security number information
  • Driver’s license number
  • Government-issued ID number (e.g. passport, state ID card)
  • Date of birth

When we asked them for clarification, TPWD referred us to the same public statement they put on the website, which lists this data as possibly stolen:

  • Driver license information
  • Passport numbers (if provided)
  • Email addresses
  • Phone numbers
  • Residential addresses

It explicitly said that Social Security numbers, dates of birth, and financial information, including credit card details, were not included in the incident.

“Social Security numbers, dates of birth and financial information, including credit card details were not obtained from this incident.” 

Those two lists don’t tally up, leaving Texans unclear as to exactly what information has been stolen.

TPWD has not identified the third-party vendor involved in the incident. It also declined to answer questions about when it first learned of the breach, how the attackers gained access to the data, or what specific security controls failed.

TPWD did say it is working with the license system vendor to implement increased safeguards. It didn’t say what those safeguards were, though, or exactly how the information was stolen in the first place.

Not the first major Texas data exposure

This isn’t the Texas government’s first data breach rodeo, which matters because criminals often combine data from multiple leaks. Information that seems limited on its own becomes much more useful when paired with other stolen data.

In 2020, software vendor Vertafore exposed records belonging to nearly 28 million Texas drivers by leaving the data in an unsecured external storage service, according to a StateScoop investigation.

In January last year, the Texas Department of Health and Human Services informed people that its employees had been stealing their data. At least 61,000 people were affected, it said at the time, before expanding that number in April to at least 94,000.

The latest breach, and the admission that government IDs were among the stolen data, may also complicate the Texas government’s repeated attempts to introduce digital identity programs. Senate Bill 215, which proposed a state digital ID for citizens, didn’t make it past committee.

If you bought a Texas hunting or fishing license

TPWD has offered affected individuals one year of free credit monitoring through Kroll. Enrollment closes September 14, 2026.

If you may have been affected:

  • Freeze your credit with Equifax, Experian, and TransUnion to make it harder for identity thieves to open accounts in your name.
  • Enroll in the Kroll credit monitoring before September 14, 2026.
  • Watch for phishing emails and texts referencing TPWD, fishing licenses, or the breach itself. Leaked emails and phone numbers are exactly what scammers use next.
  • Be suspicious of anyone who contacts you unexpectedly and asks you to verify driver’s license, passport, or other personal information.

Whether Texas ever reveals the vendor’s identity remains to be seen. What is certain is that the personal information of more than three million Texans is now in criminal hands.


Your name, address, and phone number are probably already for sale.  

Data brokers collect and sell your personal details to anyone willing to pay. Malwarebytes Personal Data Remover finds them and gets your information removed, then keeps watch so it stays that way. 

About the author

Danny Bradbury has been a journalist specialising in technology since 1989 and a freelance writer since 1994. He covers a broad variety of technology issues for audiences ranging from consumers through to software developers and CIOs. He also ghostwrites articles for many C-suite business executives in the technology sector. He hails from the UK but now lives in Western Canada.