Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

Everything's bigger and better in Texas – even data breaches

A data breach at Texas Parks and Wildlife Department's vendor exposed personal information of more than 3 million hunters and anglers who purchased licenses online. The compromised data includes names, birth dates, driver's license numbers, partial Social Security numbers, and payment details, prompting the state to urge affected individuals to monitor for fraud.

Background

- The article reports a data breach at Texas Parks and Wildlife Department (TPWD), exposing personal data of roughly 3 million hunters and anglers who purchased licenses or entered contests. - The breach occurred through a third-party vendor (a "supply chain" attack), not TPWD's own systems — a common vector where attackers target a smaller vendor to reach a larger organization's data. - Exposed data likely includes names, addresses, dates of birth, and potentially Social Security numbers or driver's license numbers (for background checks on hunting licenses). - Texas is the largest state by population with a strong hunting/fishing culture, making this a sizable privacy incident. - Supply-chain breaches have become increasingly common (e.g., the 2020 SolarWinds hack, the 2023 MOVEit breach), as attackers realize vendors are often less secure than their high-profile clients.