Back to news
Cybersecurity Alert
August 1, 2026 by EmailMeNow IT Consulting

Chambers of Commerce Hit by Hacking — Ransomware and Fake CAPTCHA

AiLock claimed Dallas Regional Chamber; DragonForce listed Tulsa; Cuero warned of fake-CAPTCHA malware. Domain audits (ideal 100%): houston.org 70%; dallaschamber.org and tulsachamber.com 50%; okcchamber.com 32% — none at 100%. No portal advertises YubiKey or Google Authenticator.

Source: DeXpose / Ransomware.live / Victoria Advocate

NewsChambers of CommerceRansomwareMalwareMFAYubiKeyAuthenticator AppsBECCybersquatTexasOklahomaCybersecurity
Chamber of commerce office facade under abstract cyber breach alert signals

Ransomware crews and malware operators spent 2026 treating U.S. chambers of commerce like soft mid-market targets. AiLock publicly claimed the Dallas Regional Chamber; DragonForce listed the Tulsa Regional Chamber; and the Cuero Chamber of Commerce warned members after a fake “Are you a robot?” CAPTCHA told visitors to press Windows + R and Ctrl + V — a clipboard-paste info-stealer pattern tied to a Shopify event-registration path (Victoria Advocate, Feb 2026).

Chambers hold what attackers want: member directories, event payments, and a sender brand every local business already trusts. Fresh audit.emailmenow.com scores on August 1, 2026 show none of the related domains at the 100% ideal — and none of the public member portals we reviewed advertise YubiKey or Google Authenticator.

Chamber of commerce office facade under abstract cyber breach alert signals

Snapshot

FieldDetail
PatternMetro chambers named on ransomware leak indexes + local chamber malware warning
DallasAiLock claim vs Dallas Regional Chamber (dallaschamber.org) — listed Mar 3, 2026; est. attack ~Jan 24 (DeXpose)
TulsaDragonForce claim vs Tulsa Regional Chamber (tulsachamber.com) — Apr 14, 2026 (Ransomware.live)
CueroFake CAPTCHA social engineering; chamber tied lure to Shopify Purse Bingo registration; Cuero Development Corporation (cuerodc.com) had confirmed breach / data loss per chamber
Claimed leak size (Dallas)Breachsense cites ~1.3 TBindexer figure, not a chamber disclosure
Org confirmationCuero: local press + chamber notice. Dallas / Tulsa: public actor claims unless the chamber confirms
Domain audits (Aug 1)Best peer 70% (houston.org); claimed victims 50%; OKC 32%0 of 7 at 100%
Member MFA0 of 6 portals advertise YubiKey or Google Authenticator TOTP

Ransomware claims are intelligence leads, not verified breach notices. Cuero is the exception: reporters quote chamber leadership and a member-facing warning.

Chronology

WhenWhat
~Jan 24, 2026Est. AiLock attack date indexed for Dallas Regional Chamber
Jan 26, 2026Cuero customer notices suspicious activity in chamber email / registration path
Feb 2026Cuero Chamber publicly warns about fake CAPTCHA malware
Mar 3, 2026AiLock claim against Dallas Regional Chamber surfaces on leak monitors
Apr 14, 2026DragonForce listing for tulsachamber.com indexed
Aug 1, 2026EmailMeNow re-audits domains, probes stacks, scans lookalikes, reviews portals

Dallas Regional Chamber — AiLock claim

FieldDetail
OrganizationDallas Regional Chamber
Domaindallaschamber.org
ActorAiLock (double-extortion RaaS)
Public listingMarch 3, 2026 (DeXpose)
Est. attack~January 24, 2026 (ransomware indexes)
Actor demand (per DeXpose)Threaten full leak unless a representative contacts negotiation channels
Claimed volume~1.3 TB per Breachsenseunverified by the chamber in public reporting we reviewed
Member hubhub.dallaschamber.org — Salesforce Experience Cloud; email + password
Audit (Aug 1)50% overall · Identity 45% · Transport 15% · Website 37%

Dallas is the region’s business-advocacy voice — economic development, education, public policy. A ransomware claim against that brand is a regional member-data risk even before any confirmed disclosure.

Ransomware double-extortion motif with generic member-data folders

Tulsa Regional Chamber — DragonForce claim

FieldDetail
OrganizationTulsa Regional Chamber
Domaintulsachamber.com
ActorDragonForce
Public listingApril 14, 2026 (Ransomware.live)
Member loginAccrisoft member login — username + password
Audit (Aug 1)50% overall · Identity 45% · Transport 15% · Website 37%

DragonForce has been an active affiliate-driven ransomware brand since 2023, with heavy U.S. targeting in industry trackers. Same caveat as Dallas: a leak-site listing is not the same as a chamber press release.

Cuero — fake CAPTCHA, real keystrokes

FieldDetail
ChamberCuero Chamber of Commercecuero.org
Related EDCCuero Development Corporationcuerodc.com (chamber: only confirmed breach + significant data loss)
LureFake CAPTCHA: “Are you a robot?” → Win+RCtrl+V
Entry path (per chamber)Third-party Shopify registration for annual Purse Bingo
SourceVictoria Advocate (Feb 2026)
Chamber auditscuero.org 46% · cuerodc.com 51%

Legitimate CAPTCHAs never open the Windows Run dialog or ask you to paste a hidden command. That pattern is the “ClickFix” / clipboard-paste class used to drop info-stealers. If you hit it: close the tab, disconnect, scan the device — same guidance from FTC / ITRC materials on this scam family.

Fake CAPTCHA malware lure instructing Windows Run and paste commands

Why chambers are attractive targets

Chambers sit at the intersection of member PII, event payment flows, and trusted bulk email. IBM / Ponemon’s Cost of a Data Breach Report 2026 found ransomware among 39% of breached organizations, with 41% of those incidents including brand / reputation threats (public shaming and media leaks) — the same pressure pattern as leak-site chamber claims.

AssetWhy attackers care
Member directoriesNames, emails, phones, titles — ready phishing lists
Event / dues paymentsCards and ACH instructions in registration stacks
Trusted sender brandSpoofed chamber alerts open because the brand already does
Lean ITMSPs, shared hosts, membership CMS — thin security staff

Same trust problem as our chamber email-spoofing primer — now with ransomware and malware against the org itself.

Independent cybersecurity audits

EmailMeNow domain audits on August 1, 2026. 100% is the ideal overall score — none of these reach it. Scores measure public identity / transport / website posture. They do not prove or disprove a ransomware intrusion path.

OrganizationDomainOverallIdentityTransportWebsiteRisk
Greater Houston Partnershiphouston.org70%95%15%37%Good
Greater Austin Chamberaustinchamber.com65%80%15%40%Above Average
Cuero Development Corporationcuerodc.com51%50%15%37%Average
Dallas Regional Chamberdallaschamber.org50%45%15%37%Average
Tulsa Regional Chambertulsachamber.com50%45%15%37%Average
Cuero Chamber of Commercecuero.org46%35%15%37%Below Average
Greater Oklahoma City Chamberokcchamber.com32%0%15%37%Weak

Audit links: houston.org · austinchamber.com · cuerodc.com · dallaschamber.org · tulsachamber.com · cuero.org · okcchamber.com

Pattern: All 7 domains score 15% Transport Security — inbound mail transport (MTA-STS / related) is a sector-wide gap. Claimed ransomware victims Dallas and Tulsa sit at 50% overall (50 points under ideal). Peer Houston leads at 70% on strong identity (95%). Oklahoma City is the soft outlier at 32% with 0% identity.

How we graded MFA

Public member-login pages only — not a logged-in mystery shop of staff Microsoft 365 / Google Workspace. Methods change; re-check before you rely on this table. Same spirit as our national bank MFA scorecard.

GradeMeaning
FailPassword-only (or email-first) login with no advertised second factor
PartialApp push / passkeys / proprietary soft token, but no standard TOTP and no YubiKey/FIDO
Pass (TOTP)Self-serve Google Authenticator / Proton Pass-style OATH TOTP
StrongFIDO2 / YubiKey-class security key for portal sign-in

Member portal MFA — YubiKey and Google Authenticator

ChamberPortalYubiKey / FIDOGoogle Auth / TOTPLogin UXGrade
Dallas Regional Chamberhub.dallaschamber.orgNoNoEmail + passwordFail
Tulsa Regional ChamberMember loginNoNoUsername + passwordFail
Greater Houston Partnershipmember.houston.org/loginNoNoCompany email firstFail
Greater Austin Chamberaustinchamber.com/loginNoNoEmail + passwordFail
Greater Oklahoma City ChamberMember loginNoNoUsername + passwordFail
Cuero Chambercuero.org/login (WordPress)NoNoEmail + passwordFail

cuerodc.com is an economic-development site without a comparable public member hub in this review — graded on domain audit + stack only.

Password-only chamber login contrasted with hardware key and authenticator app

Takeaway: None of these six member surfaces advertise YubiKey or Google Authenticator. Password-only portals next to 50% victim-domain scores (and a 32% OKC outlier) is a poor combination when ransomware crews and info-stealers already name chambers. Staff Microsoft 365 MFA — if enabled — does not protect the chamber hub that holds member contacts.

Website stack note

Passive website-tech probes on August 1, 2026 covered 7 story domains (1 notable):

DomainStack
cuero.orgWordPress 6.9.5outdated vs latest 7.0.2; Paid Memberships Pro, Theme My Login
cuerodc.comWordPress 7.0.2 — current
tulsachamber.comPHP (version not exposed)
okcchamber.comPHP (version not exposed)
houston.orgNext.js (version not exposed)
dallaschamber.orgNo notable CMS / PHP / short-horizon TLS flags
austinchamber.comNo notable CMS / PHP / short-horizon TLS flags

Cuero’s public chamber site still fingerprints behind current WordPress after a malware-related incident — patching the membership CMS matters even when the lure arrived via a third-party Shopify path.

Cybersquat / lookalike scan

DoH lookalike scans on August 1, 2026 (registered-only; BEC profile):

Brand domainCheckedTo reviewBEC stagingHighlights
dallaschamber.org24240dallaschamber.com / .biz / .info / .net — TLD swaps
tulsachamber.com23110tulsachambers.com — insertion (NS+A)
cuero.org116202cueto.org, uero.org — BEC staging (NS+MX)
cuerodc.com15040cuerocc.com, curodc.com — adjacent/omission with MX
houston.org148151houston.io — BEC staging (NS+MX)
austinchamber.com24610Brand holds redirect lookalikes (austin-chamber.com, austinchamber.org)
okcchamber.com19560kcchamber.com, okchamber.com — omissions with MX

Short brands like cuero.org sit in a crowded lookalike space with live-MX staging domains — useful for the next “chamber invoice” lure even when the original incident was CAPTCHA malware. Track registrations with Cybersquat Domain Monitoring.

Priority actions for chambers

  1. Treat member data as high-value — offline/immutable backups; practice restore; segment membership CMS from finance workstations.
  2. Harden member portals — require MFA; Google Authenticator–class TOTP at minimum; YubiKey / FIDO for staff and privileged roles.
  3. Close email gaps — enforce DMARC; fix 15% transport (MTA-STS); share audit.emailmenow.com with members.
  4. Review third-party event stacks — Shopify / ticketing iframes and CAPTCHA widgets need the same scrutiny as the homepage.
  5. Train the never-Run-and-Paste rule — any CAPTCHA asking for Win+R / Ctrl+V is malware.
  6. Monitor lookalikes — especially short city brands with live MX (cybersquat monitoring).

Sources: DeXpose — AiLock / Dallas Regional Chamber (Mar 3, 2026) · Ransomware.live — tulsachamber.com / DragonForce · Victoria Advocate — Cuero Chamber malware (Feb 2026) · Breachsense — Dallas ~1.3 TB indexer listing. Independent EmailMeNow domain audits, website-tech probes, cybersquat scans, and public portal MFA reviews August 1, 2026. Domain scores: audit.emailmenow.com only. Ransomware claims are actor-side unless the organization confirms.