August 2026 Chamber bulletin — print / PDF · share with CEO + membership team

Texas OAG YTD Chamber news brief Free domain check

Bryan / College Station Chamber of Commerce · Member contribution

August 2026 IT & Cyber Bulletin

Local Brazos Valley incidents, major Texas breaches year-to-date, peer-chamber warnings, board talking points, and practical tips staff and members can use this week — plus a free domain self-check (QR below). Prepared by a local Chamber member focused on email and domain security.

EmailMeNow IT Consulting College Station · Chamber member
Bulletin date: August 24, 2026
(979) 472-3693
emailmenow.com

What to tell the board

  1. Local: BTU payment ransomware, ESD ACH diversion (~$400k recovered), and CodeRED vendor incident hit Brazos Valley — same patterns members face.
  2. Texas YTD: ~370 OAG notices / ~29.7M Texans through July 31 — TPWD, TTUHSC, Houston City College among the large hits.
  3. Peer chambers: Dallas AiLock · Tulsa DragonForce · Cuero fake CAPTCHA — audits Aug 1: Houston 70% best · victims 50% · OKC 32% · 0 of 7 at 100% · 0 of 6 portals advertise app/hardware MFA.
  4. This week: voice-callback on payment changes; back up every machine; prefer app/hardware MFA; never Win+R from a “CAPTCHA.”
  5. Member value: free domain self-check at audit.emailmenow.com — no signup (QR at right).

Member benefit

EmailMeNow QR code linking to free domain self-check at audit.emailmenow.com

Scan for a free email / domain check

audit.emailmenow.com

No signup · 60 seconds

Chambers hit by hacking: Dallas Regional Chamber, Tulsa Regional Chamber, Cuero Chamber of Commerce

Peer chamber graphic · Dallas · Tulsa · Cuero — full news brief linked in §3

1. Brazos County & Brazos Valley — local incidents

These hit close to home. Vendor ransomware and payment fraud are not “big city only” problems — they disrupt utilities, emergency services, and the businesses your members run.

Org / system When What happened
Bryan Texas Utilities (BTU) Feb 2026 Ransomware at third-party card processor BridgePay suspended online credit/debit payments for ~70,000 Brazos Valley customers for about a week. BTU reported no customer data leak; card payments later restored with a new backend processor. (KBTX / The Eagle / BTU)
Brazos County ESD No. 1 Attack Oct 2025 · recovery Mar 2026 Business email compromise / vendor-payment diversion (~$400,000 ACH). Hackers monitored email, spoofed a near-identical vendor address, and intercepted a construction payment. Sheriff’s Office recovered nearly all funds in 2026; district implemented new safeguards. (KBTX / KCEN)
CodeRED (county emergency alerts) Vendor incident late 2025 · county notice Dec 2025 Nationwide CodeRED / OnSolve ransomware and data incident affected Brazos County Emergency Management’s alert platform. County warned that signup data (name, address, email, phone, passwords) may have been at risk and moved toward a replacement system. (WTAW / KCEN)

Local takeaway: vendor ransomware (BTU payments) and BEC / ACH diversion (ESD) are the same patterns members face. Voice-callback on payment changes and offline backups matter in Bryan–College Station as much as in Dallas.

2. Major Texas hacks & breaches — 2026 YTD

Through July 31, 2026, the Texas OAG Data Security Breach Reports page listed roughly 370 published notices affecting about 29.7 million Texans (EmailMeNow OAG YTD tracker). Below are major Texas-based or Texas-impacting incidents members ask about — not a full OAG dump.

Incident Approx. when Scale / notes
Conduent Business Services (revised OAG filing) 2026 YTD ~12.8 million Texans — largest published OAG report this year (national vendor serving public programs)
DentaQuest, LLC 2026 YTD ~3.97 million Texans listed on OAG portal
Texas Parks & Wildlife — hunting/fishing license vendor Jun 2026 (OAG) ~3.09 million Texans; driver’s licenses / passports / contact data — major state-government hit
Cerner Corporation 2026 YTD (OAG) ~2.66 million Texans — multi-state health IT filing
Houston City College — ShinyHunters Jun–Jul 2026 ~832,000 student/alumni emails on Have I Been Pwned after pay-or-leak campaign
Carnival Corporation 2026 YTD (OAG) ~800,000 Texans in published filing
Texas Tech University Health Sciences Center Apr 2026 (OAG) ~738,500 Texans; HHS OCR filings put nationwide exposure near 1.4 million
East Texas Family Medicine — Genesis ransomware claim Jul 2026 Regional clinic on leak monitors; treat as patient-data (PHI) and follow-on phishing risk until cleared
Cuero Chamber of Commerce Feb 2026 Fake CAPTCHA malware; member warning; related EDC data-loss notice — Texas chamber peer
Dallas Regional Chamber — AiLock claim ~Jan–Mar 2026 Public ransomware claim vs metro chamber brand (actor claim until chamber confirms)
Universities (examples) — St. Thomas Houston; University of Dallas May 2026 (OAG week) Tens of thousands of Texans in filings with SSN / ID / financial / medical fields

OAG counts are published notices (details can change). Ransomware “claims” are intelligence leads unless the org confirms. Living dashboard: emailmenow.com/news/texas-oag-breach-reports-2026-ytd

3. Chambers hit by hacking (peer news)

From our Aug 2026 chambers brief: ransomware crews and malware operators treated U.S. chambers as soft mid-market targets. Chambers hold member directories, event payments, and a trusted sender brand every local business already opens.

Claims Dallas · Tulsa AiLock · DragonForce — actor listings until chamber confirms
Confirmed Cuero Chamber Fake CAPTCHA · Win+R / Ctrl+V · Shopify event path
Audits (Aug 1) 0 of 7 at 100% Houston 70% · Dallas/Tulsa 50% · OKC 32% · MFA portals Fail
Chamber Status What was reported Why it matters here
Dallas Regional Chamber Claim AiLock ransomware claim indexed ~Mar 2026 (est. attack ~Jan 24) · ~1.3 TB indexer figure unverified Metro peer — member-data and brand-risk pressure
Tulsa Regional Chamber Claim DragonForce listing indexed Apr 2026 Regional chambers appear on leak monitors when posture lags
Cuero Chamber of Commerce Confirmed Fake CAPTCHA → Windows + R / Ctrl + V (Feb 2026) · chamber tied lure to Shopify Purse Bingo registration · related EDC data loss Texas chamber; event-registration malware hits local orgs

Domain audits (Aug 1, 2026): ideal overall is 100%none of seven peer domains reached it (best peer houston.org 70%; claimed victims 50%; OKC 32%). All seven scored 15% transport. Member-portal MFA review: 0 of 6 advertise YubiKey or Google Authenticator — password-only grades Fail. Full tables + lookalike notes: chambers-commerce-hacking-ransomware-aug-2026 (DeXpose / Ransomware.live / Victoria Advocate). IBM Cost of a Data Breach 2026: ransomware in ~39% of breached orgs; ~41% of those included brand / reputation threats — benchmark brief.

4. IT tips for chamber operations

  • Treat lookalike domains as a brand issue — near-spellings with live mail (MX records) can send spoofed “Chamber” messages that look local.
  • Review third-party event stacks — Shopify / ticketing iframes and CAPTCHA widgets need the same scrutiny as the homepage (Cuero’s lure path).
  • Keep the public website current — outdated CMS / plugin stacks remain a common entry path on high-visibility chamber sites.
  • Ransomware backups for every machine — laptops, desktops, and servers: automated backups that are tested and kept offline or immutable (so ransomware cannot encrypt the only copy). One missed PC can halt operations.
  • Separate membership platform from domain email trust — Chamber Master / GrowthZone can be solid while SPF, DKIM, and DMARC on the public domain still need work so outsiders can’t impersonate you. (Definitions below.)

5. Tips members can use this week

  • Never trust Windows + R / Ctrl + V from a website “CAPTCHA” — stop, call the business on a number you already know.
  • Wire / ACH changes only by voice callback to a number already on file — not the number in the email.
  • Prefer authenticator-app or hardware MFA over SMS text codes for banking and email (SIM-swap risk). See illustration below.
  • Back up every computer — if ransomware locks files, a recent offline/cloud backup is often the only fast recovery. Include home-office PCs that hold business data.
  • Free 60-second self-check: audit.emailmenow.com — enter the business domain; no signup required.
Stronger than SMS: authenticator app MFA on a phone next to a hardware security key on a laptop

App MFA (one-time codes) and hardware security keys beat SMS codes — harder for SIM-swap thieves to steal

6. Tip cards (newsletters, orientations)

Tip - Finance / leadership desk

BEC (business email compromise) often starts with a spoofed chamber or vendor “from” address. Enforced DMARC makes many forgeries fail in the inbox.

Tip - Vendor / ACH callback

Same lesson as local ESD and utility vendor incidents: change payment or bank details only after a voice callback to a number already on file — never the number in the email.

Tip - Ransomware backups

Back up all machines — every laptop, desktop, and server. Test restores. Keep at least one copy offline or immutable so ransomware cannot wipe it.

Tip - MFA stronger than SMS

Use an authenticator app (Google Authenticator, Microsoft Authenticator, Proton Pass, etc.) or a hardware security key for email and banking — not text-message codes alone.

Tip - New-member welcome

Add one line to packets: “Run a free email/domain check at audit.emailmenow.com” — zero-cost member value.

Tip - Event registration

Warn members: fake CAPTCHA pages that ask for Win+R / Ctrl+V are malware. Cuero’s Shopify registration lure is a ready talking point for Insider / orientations.

7. Related reading (for staff)

8. How EmailMeNow can help (optional)

As a B/CS Chamber member, we work with you or your IT team / MSP to harden domain email trust — complementary to GrowthZone / Chamber Master, not a replacement for membership-platform ownership.

9. Glossary — tech terms used in this bulletin

Term Plain-language meaning
ACH Automated Clearing House — U.S. bank network used for electronic payments and direct deposits. Attackers often try to redirect ACH or wire payments with fake “new account” emails.
Ransomware Malicious software that encrypts (locks) files and demands payment. Recovery depends on good backups of every machine — not just the server — plus backups ransomware cannot reach (offline / immutable).
BEC Business email compromise — fraud that impersonates a trusted person or brand (chamber, vendor, executive) to trick someone into paying money or sharing data.
CAPTCHA “Completely Automated Public Turing test to tell Computers and Humans Apart” — the “prove you’re not a robot” check. Fake CAPTCHA pages that ask you to press keyboard shortcuts are malware lures.
CMS Content management system — software that runs a website (for example WordPress). Outdated CMS versions are a common way attackers break into public sites.
DKIM DomainKeys Identified Mail — a digital signature on outgoing email that proves the message was authorized by the domain’s owner.
DMARC Domain-based Message Authentication, Reporting and Conformance — a domain policy that tells receiving mail systems what to do with messages that fail SPF/DKIM checks (monitor, quarantine, or reject). Enforced DMARC blocks many spoofed “from” addresses.
IT Information technology — computers, networks, email, and related systems.
MFA Multi-factor authentication — a second check after the password (app code, security key, or SMS). App or hardware MFA is stronger than SMS because phone numbers can be stolen via SIM-swap.
MSP Managed service provider — an outside IT company that supports your systems day to day.
OAG Office of the Attorney General (here: Texas) — publishes data security breach reports when organizations notify the state about incidents affecting Texans.
PHI Protected health information — medical and related personal data regulated under U.S. health privacy rules; clinics and hospitals must protect it carefully.
MX Mail exchanger (DNS record) — tells the internet where email for a domain should be delivered. A lookalike domain with live MX can send mail that looks like “Chamber” email.
SIM-swap Attack where a crook takes over your mobile number at the carrier so SMS one-time codes go to them instead of you.
SMS Short Message Service — text messaging. Convenient for codes, but weaker than authenticator apps or hardware keys.
SPF Sender Policy Framework — a DNS list of servers allowed to send email for your domain. Helps receivers spot unauthorized senders.

Also named in this bulletin: AiLock, DragonForce, and Genesis are ransomware groups; ShinyHunters is a data-theft / extortion crew; GrowthZone / Chamber Master is the chamber membership platform software; BridgePay / CodeRED (OnSolve) are third-party vendors that served local utility and emergency-alert systems.