August 2026 Bar / law-firm bulletin — print / PDF · share with BCBA officers + firm admins

Texas OAG YTD State Bar phishing brief Free domain check

Brazos County Bar Association · Local member contribution

August 2026 Law Firm IT & Cyber Bulletin

Local Brazos Valley incidents, a named Texas law-firm breach list, State Bar phishing watch, board talking points, and practical tips firms can use this week — plus a free domain self-check (QR below). Prepared by a College Station IT consultant focused on email and domain security.

EmailMeNow IT Consulting College Station · B/CS Chamber member
Bulletin date: August 4, 2026
(979) 472-3693
emailmenow.com

What to tell the board

  1. Local: BTU payment ransomware, ESD ACH diversion (~$400k recovered), and CodeRED vendor incident hit Brazos Valley — same BEC / vendor patterns law firms and clients face.
  2. Named firms (§2): Texas practices on OAG notices from Houston to Amarillo (and Killeen) — Thompson & Horton, Sprouse, Herrman, Bailey & Galyen, and more; State Bar / TLIE phishing alerts continue.
  3. Practice risk: wire / settlement redirect and trust-account fraud remain top loss drivers for small and mid-size firms.
  4. This week: voice-callback on wire/ACH changes; back up every machine; prefer app/hardware MFA over SMS on email and banking.
  5. Firm value: free domain self-check at audit.emailmenow.com — no signup (QR at right).

Firm benefit

EmailMeNow QR code linking to free domain self-check at audit.emailmenow.com

Scan for a free email / domain check

audit.emailmenow.com

No signup · 60 seconds

Law firm email security and breach watch — Texas and Brazos Valley context

Named Texas law-firm breaches · Brazos Valley incidents · tips below

1. Brazos County & Brazos Valley — local incidents

These hit close to home. Vendor ransomware and payment fraud are not “big city only” problems — they disrupt utilities, emergency services, and the clients and firms your members advise.

Org / system When What happened
Bryan Texas Utilities (BTU) Feb 2026 Ransomware at third-party card processor BridgePay suspended online credit/debit payments for ~70,000 Brazos Valley customers for about a week. BTU reported no customer data leak; card payments later restored with a new backend processor. (KBTX / The Eagle / BTU)
Brazos County ESD No. 1 Attack Oct 2025 · recovery Mar 2026 Business email compromise / vendor-payment diversion (~$400,000 ACH). Hackers monitored email, spoofed a near-identical vendor address, and intercepted a construction payment. Sheriff’s Office recovered nearly all funds in 2026; district implemented new safeguards. (KBTX / KCEN)
CodeRED (county emergency alerts) Vendor incident late 2025 · county notice Dec 2025 Nationwide CodeRED / OnSolve ransomware and data incident affected Brazos County Emergency Management’s alert platform. County warned that signup data (name, address, email, phone, passwords) may have been at risk and moved toward a replacement system. (WTAW / KCEN)

Local takeaway: vendor ransomware and BEC / ACH diversion are the same patterns that hit law-firm operating accounts, settlements, and trust transfers. Voice-callback on payment changes and offline backups matter in Bryan–College Station as much as in Houston.

2. Named law firms in public breach reports (Texas focus)

Named practices from Texas Attorney General data-security breach notices (EmailMeNow law-firm tracker window Aug 2025–Jul 17, 2026), sorted by Texans affected. Counts are portal totals — not proof of how an attack started. Large Texas firms and solo offices both appear. Local Brazos County firm grades stay private.

Firm (Texas-based) Base Texans affected Published
Thompson & Horton LLP Houston 41,222 Oct 30, 2025
Sprouse Shrader Smith PLLC Amarillo 17,666 May 5, 2026
Herrman & Herrman PLLC Dallas 13,424 Dec 22, 2025
Phillip Galyen P.C. dba Bailey & Galyen Bedford 11,038 May 22, 2026
Williams Hart & Boundas, LLP Houston 7,844 Mar 18, 2026
Modjarrad & Associates, PC d/b/a MAS Law Richardson 6,220 Jun 1, 2026
Law Office of Michael R. De La Paz San Antonio 2,000 Apr 13, 2026
Martin & Cukjati, LLP San Antonio 897 May 5, 2026
The Reecer Law Firm PLLC Denton 897 Jan 27, 2026
Martin Showers Smith & McDonald LLP Hillsboro 457 Aug 29, 2025
The Carlson Law Firm (Central Texas) Killeen 250 Jun 18, 2026

Also reported to Texas OAG (out-of-state HQ, Texans notified): Pillsbury Winthrop Shaw Pitman LLP (39,573 · Nov 2025) · Fried, Frank, Harris, Shriver & Jacobson LLP (16,724 · Mar 2026) · Dykema Gossett PLLC (6,132 · May 2026). Source: Texas OAG Data Security Breach Reports via EmailMeNow law-firm tracker (as of Jul 17, 2026).

Ransomware / leak claim (Texas firm) What was reported Caveat
Deandra Grant Law (criminal defense / DWI) Incransom group claimed access and threatened client/case data release Intelligence lead until the firm confirms scope — still useful for staff phishing awareness

Living list: emailmenow.com/news/law-firm-breaches-2026 · Bailey & Galyen brief · Dykema / MAS brief · Deandra Grant Law ransomware. Tracker tally: ~28 law-firm / legal-service OAG entries · ~170,000+ Texans listed.

3. Major Texas hacks & breaches — 2026 YTD

Through July 31, 2026, the Texas OAG Data Security Breach Reports page listed roughly 370 published notices affecting about 29.7 million Texans (EmailMeNow OAG YTD tracker). Below are major non-law-firm incidents clients ask about — not a full OAG dump. Named law-firm notices stay in §2 above.

Incident Approx. when Scale / notes
Conduent Business Services (revised OAG filing) 2026 YTD ~12.8 million Texans — largest published OAG report this year (national vendor serving public programs)
DentaQuest, LLC 2026 YTD ~3.97 million Texans listed on OAG portal
Texas Parks & Wildlife — hunting/fishing license vendor Jun 2026 (OAG) ~3.09 million Texans; driver’s licenses / passports / contact data — major state-government hit
Cerner Corporation 2026 YTD (OAG) ~2.66 million Texans — multi-state health IT filing
Houston City College — ShinyHunters Jun–Jul 2026 ~832,000 student/alumni emails on Have I Been Pwned after pay-or-leak campaign
Carnival Corporation 2026 YTD ~800,000 Texans in published filing
Texas Tech University Health Sciences Center Apr 2026 (OAG) ~738,500 Texans; HHS OCR filings put nationwide exposure near 1.4 million
East Texas Family Medicine — Genesis ransomware claim Jul 2026 Regional clinic on leak monitors; treat as patient-data (PHI) and follow-on phishing risk until cleared
Universities (examples) — St. Thomas Houston; University of Dallas May 2026 (OAG week) Tens of thousands of Texans in filings with SSN / ID / financial / medical fields

OAG counts are published notices (details can change). Ransomware “claims” are intelligence leads unless the org confirms. Living dashboard: emailmenow.com/news/texas-oag-breach-reports-2026-ytd

4. Law firms & legal phishing watch (Texas)

Law firms remain high-value targets: client files, settlement wires, and trusted “from” brands. State Bar and insurer guidance keeps flagging email-based fraud against Texas lawyers.

Watch item What was reported Why it matters here
State Bar of Texas / TLIE phishing Ongoing lawyer-targeted phishing and social-engineering alerts (annual meeting / CLE lures and lookalike portals) Local counsel and bar leaders are in the same targeting pool as Houston / Dallas firms
Texas OAG — law firm filings Multiple notices naming Texas firms / legal practices (~28 entries · ~170k+ Texans in tracker) — named list in §2 Client notification duties and follow-on phishing after a firm or vendor leak
Wire / settlement redirect (BEC) Industry pattern: spoofed counsel or client email changes wiring instructions mid-deal Same class of fraud as the local ESD ACH diversion — voice-callback is the control
Trust-account / IOLTA risk Compromised email + weak MFA can turn into unauthorized transfers from client funds Small Brazos Valley firms often share bookkeeping and email admin — lock both

Full briefs: State Bar phishing watch · Law firm breach tracker · Top Texas law firms email security. Firm-by-firm grades for local members stay private unless leadership asks for a closed briefing.

5. IT tips for firm / bar operations

  • Treat lookalike domains as a brand issue — near-spellings with live mail (MX) can send spoofed “Counsel” or “Bar” messages that look local.
  • Lock trust & settlement workflows — written voice-callback for any change to wiring, ACH, or IOLTA instructions; never trust the number in the email.
  • Ransomware backups for every machine — laptops, desktops, and servers: tested backups offline or immutable. One missed PC can freeze litigation calendars and accounting.
  • Separate practice management from domain email trust — Clio / MyCase / Microsoft 365 can be solid while SPF, DKIM, and DMARC on the public domain still need work so outsiders can’t impersonate the firm. (Definitions below.)

6. Tips attorneys & staff can use this week

  • Never trust Windows + R / Ctrl + V from a website “CAPTCHA” — close the tab; call the sender on a number already on file.
  • Wire / settlement / ACH changes only by voice callback to a number already on file — not the number in the email.
  • Prefer authenticator-app or hardware MFA over SMS for email, banking, and trust-account portals (SIM-swap risk). See illustration below.
  • Back up every computer — include home-office machines that hold client files or QuickBooks.
  • Free 60-second self-check: audit.emailmenow.com — enter the firm domain; no signup required.
Stronger than SMS: authenticator app MFA on a phone next to a hardware security key on a laptop

App MFA (one-time codes) and hardware security keys beat SMS codes — harder for SIM-swap thieves to steal

7. Tip cards (newsletters, orientations)

Tip - Trust / settlement desk

BEC often starts with a spoofed counsel, client, or title-company “from” address. Enforced DMARC makes many forgeries fail in the inbox.

Tip - Wire / ACH callback

Same lesson as the local ESD diversion: change wiring or bank details only after a voice callback to a number already on file — never the number in the email.

Tip - Ransomware backups

Back up all machines — every laptop, desktop, and server. Test restores. Keep at least one copy offline or immutable so ransomware cannot wipe it.

Tip - MFA stronger than SMS

Use an authenticator app or hardware security key for email, banking, and trust portals — not text-message codes alone.

Tip - CLE / member note

Add one line to CLE packets or newsletters: “Run a free email/domain check at audit.emailmenow.com” — zero-cost member value.

Tip - Phishing CAPTCHA

Fake CAPTCHA pages that ask for keyboard shortcuts are malware. State Bar phishing alerts are a ready talking point for staff training.

8. Related reading (for staff)

9. How EmailMeNow can help (optional)

As a College Station IT consultant and B/CS Chamber member, we work with bar leadership or firm IT / MSPs to harden domain email trust — complementary to practice-management tools, not a replacement for them.

10. Glossary — tech terms used in this bulletin

Term Plain-language meaning
ACH Automated Clearing House — U.S. bank network used for electronic payments and direct deposits. Attackers often try to redirect ACH or wire payments with fake “new account” emails.
Ransomware Malicious software that encrypts (locks) files and demands payment. Recovery depends on good backups of every machine — not just the server — plus backups ransomware cannot reach (offline / immutable).
BEC Business email compromise — fraud that impersonates a trusted person or brand (counsel, client, title company, vendor, executive) to trick someone into paying money or sharing data.
CAPTCHA “Completely Automated Public Turing test to tell Computers and Humans Apart” — the “prove you’re not a robot” check. Fake CAPTCHA pages that ask you to press keyboard shortcuts are malware lures.
CMS Content management system — software that runs a website (for example WordPress). Outdated CMS versions are a common way attackers break into public sites.
DKIM DomainKeys Identified Mail — a digital signature on outgoing email that proves the message was authorized by the domain’s owner.
DMARC Domain-based Message Authentication, Reporting and Conformance — a domain policy that tells receiving mail systems what to do with messages that fail SPF/DKIM checks (monitor, quarantine, or reject). Enforced DMARC blocks many spoofed “from” addresses.
IOLTA Interest on Lawyers’ Trust Accounts — client funds held in a firm trust account. Compromised email can be used to authorize fraudulent transfers from these accounts.
IT Information technology — computers, networks, email, and related systems.
MFA Multi-factor authentication — a second check after the password (app code, security key, or SMS). App or hardware MFA is stronger than SMS because phone numbers can be stolen via SIM-swap.
MSP Managed service provider — an outside IT company that supports your systems day to day.
OAG Office of the Attorney General (here: Texas) — publishes data security breach reports when organizations notify the state about incidents affecting Texans.
TLIE Texas Lawyers Insurance Exchange — malpractice / risk insurer that publishes fraud and phishing guidance for Texas attorneys.
PHI Protected health information — medical and related personal data regulated under U.S. health privacy rules; clinics and hospitals must protect it carefully.
MX Mail exchanger (DNS record) — tells the internet where email for a domain should be delivered. A lookalike domain with live MX can send mail that looks like firm or bar email.
SIM-swap Attack where a crook takes over your mobile number at the carrier so SMS one-time codes go to them instead of you.
SMS Short Message Service — text messaging. Convenient for codes, but weaker than authenticator apps or hardware keys.
SPF Sender Policy Framework — a DNS list of servers allowed to send email for your domain. Helps receivers spot unauthorized senders.

Also named in this bulletin: TLIE is Texas Lawyers Insurance Exchange; IOLTA is Interest on Lawyers’ Trust Accounts (client funds); ShinyHunters / Genesis are threat actors referenced in broader Texas breach news; BridgePay / CodeRED (OnSolve) are third-party vendors that served local utility and emergency-alert systems.