What happened
The Texas Parks and Wildlife Department (TPWD) has notified more than three million hunting and fishing license customers that their personal information was exposed in a breach of the third-party vendor that runs the agency's license sales system. TPWD posted the notice on its own site, "Notification of Data Security Incident," after Texas Cyber Command identified unauthorized access to the vendor's systems (Texas Parks and Wildlife Department, 2026).
TPWD has not named the vendor publicly. The agency's notice describes the incident as involving the license system used to sell hunting and fishing permits, not TPWD's own internal network.
What data was exposed
According to the agency's notice, an unauthorized party may have obtained driver's license numbers, passport numbers, email addresses, phone numbers and residential addresses tied to customer license profiles. TPWD said Social Security numbers, dates of birth and financial information, including credit card numbers, were not part of the exposed data set (Texas Parks and Wildlife Department, 2026).
SecurityWeek, reporting independently on the notice, confirmed the same scope: more than three million individuals affected, with government ID numbers as the most sensitive category exposed and no financial account data involved (SecurityWeek, 2026). CBS News Texas reported the same headline figure after reviewing the agency's public statement (CBS Texas, 2026).
TPWD has not attributed the intrusion to a specific actor or group, and no attribution claim appears in any of the public reporting reviewed for this brief.
Who is affected
Anyone who purchased a Texas hunting or fishing license through the affected vendor system falls within the exposure. TPWD has not published a precise date range for the license purchases covered, only the total customer count of more than three million.
The department said it is working with the vendor to review which records were accessed and is notifying affected customers directly as that review completes.
What affected customers should know
TPWD is offering one year of free credit monitoring through Kroll to affected customers. Customers can confirm eligibility and enroll by calling the agency's dedicated call center at (844) 959-7123, Monday through Friday, 8 a.m. to 5:30 p.m. Central time. The enrollment deadline for the free monitoring is September 14, 2026 (Texas Parks and Wildlife Department, 2026).
Because driver's license and passport numbers were exposed, affected customers should watch for attempts to open accounts or file documents in their name, not just credit card fraud. Credit monitoring services flag new account activity but do not by themselves prevent misuse of a government-issued ID number.
What happens next
TPWD says it has tightened access controls on the vendor's customer profile system and plans additional security changes, without giving a public timeline. The agency has not said whether the vendor's contract will change or whether the license system will be rebuilt on different infrastructure.
No regulatory filing beyond the department's own consumer notice was located at the time of this brief. Texas does not currently require a single state breach-notification portal filing in the way some states do, so the agency's own site is the primary public record of the incident.
Sources: TPWD Notification of Data Security Incident · SecurityWeek · CBS News Texas
