Ransomware crews and malware operators spent 2026 treating U.S. chambers of commerce like soft mid-market targets. AiLock publicly claimed the Dallas Regional Chamber; DragonForce listed the Tulsa Regional Chamber; and the Cuero Chamber of Commerce warned members after a fake “Are you a robot?” CAPTCHA told visitors to press Windows + R and Ctrl + V — a clipboard-paste info-stealer pattern tied to a Shopify event-registration path (Victoria Advocate, Feb 2026).
Chambers hold what attackers want: member directories, event payments, and a sender brand every local business already trusts. Fresh audit.emailmenow.com scores on August 1, 2026 show none of the related domains at the 100% ideal — and none of the public member portals we reviewed advertise YubiKey or Google Authenticator.

Snapshot
| Field | Detail |
|---|---|
| Pattern | Metro chambers named on ransomware leak indexes + local chamber malware warning |
| Dallas | AiLock claim vs Dallas Regional Chamber (dallaschamber.org) — listed Mar 3, 2026; est. attack ~Jan 24 (DeXpose) |
| Tulsa | DragonForce claim vs Tulsa Regional Chamber (tulsachamber.com) — Apr 14, 2026 (Ransomware.live) |
| Cuero | Fake CAPTCHA social engineering; chamber tied lure to Shopify Purse Bingo registration; Cuero Development Corporation (cuerodc.com) had confirmed breach / data loss per chamber |
| Claimed leak size (Dallas) | Breachsense cites ~1.3 TB — indexer figure, not a chamber disclosure |
| Org confirmation | Cuero: local press + chamber notice. Dallas / Tulsa: public actor claims unless the chamber confirms |
| Domain audits (Aug 1) | Best peer 70% (houston.org); claimed victims 50%; OKC 32% — 0 of 7 at 100% |
| Member MFA | 0 of 6 portals advertise YubiKey or Google Authenticator TOTP |
Ransomware claims are intelligence leads, not verified breach notices. Cuero is the exception: reporters quote chamber leadership and a member-facing warning.
Chronology
| When | What |
|---|---|
| ~Jan 24, 2026 | Est. AiLock attack date indexed for Dallas Regional Chamber |
| Jan 26, 2026 | Cuero customer notices suspicious activity in chamber email / registration path |
| Feb 2026 | Cuero Chamber publicly warns about fake CAPTCHA malware |
| Mar 3, 2026 | AiLock claim against Dallas Regional Chamber surfaces on leak monitors |
| Apr 14, 2026 | DragonForce listing for tulsachamber.com indexed |
| Aug 1, 2026 | EmailMeNow re-audits domains, probes stacks, scans lookalikes, reviews portals |
Dallas Regional Chamber — AiLock claim
| Field | Detail |
|---|---|
| Organization | Dallas Regional Chamber |
| Domain | dallaschamber.org |
| Actor | AiLock (double-extortion RaaS) |
| Public listing | March 3, 2026 (DeXpose) |
| Est. attack | ~January 24, 2026 (ransomware indexes) |
| Actor demand (per DeXpose) | Threaten full leak unless a representative contacts negotiation channels |
| Claimed volume | ~1.3 TB per Breachsense — unverified by the chamber in public reporting we reviewed |
| Member hub | hub.dallaschamber.org — Salesforce Experience Cloud; email + password |
| Audit (Aug 1) | 50% overall · Identity 45% · Transport 15% · Website 37% |
Dallas is the region’s business-advocacy voice — economic development, education, public policy. A ransomware claim against that brand is a regional member-data risk even before any confirmed disclosure.

Tulsa Regional Chamber — DragonForce claim
| Field | Detail |
|---|---|
| Organization | Tulsa Regional Chamber |
| Domain | tulsachamber.com |
| Actor | DragonForce |
| Public listing | April 14, 2026 (Ransomware.live) |
| Member login | Accrisoft member login — username + password |
| Audit (Aug 1) | 50% overall · Identity 45% · Transport 15% · Website 37% |
DragonForce has been an active affiliate-driven ransomware brand since 2023, with heavy U.S. targeting in industry trackers. Same caveat as Dallas: a leak-site listing is not the same as a chamber press release.
Cuero — fake CAPTCHA, real keystrokes
| Field | Detail |
|---|---|
| Chamber | Cuero Chamber of Commerce — cuero.org |
| Related EDC | Cuero Development Corporation — cuerodc.com (chamber: only confirmed breach + significant data loss) |
| Lure | Fake CAPTCHA: “Are you a robot?” → Win+R → Ctrl+V |
| Entry path (per chamber) | Third-party Shopify registration for annual Purse Bingo |
| Source | Victoria Advocate (Feb 2026) |
| Chamber audits | cuero.org 46% · cuerodc.com 51% |
Legitimate CAPTCHAs never open the Windows Run dialog or ask you to paste a hidden command. That pattern is the “ClickFix” / clipboard-paste class used to drop info-stealers. If you hit it: close the tab, disconnect, scan the device — same guidance from FTC / ITRC materials on this scam family.

Why chambers are attractive targets
Chambers sit at the intersection of member PII, event payment flows, and trusted bulk email. IBM / Ponemon’s Cost of a Data Breach Report 2026 found ransomware among 39% of breached organizations, with 41% of those incidents including brand / reputation threats (public shaming and media leaks) — the same pressure pattern as leak-site chamber claims.
| Asset | Why attackers care |
|---|---|
| Member directories | Names, emails, phones, titles — ready phishing lists |
| Event / dues payments | Cards and ACH instructions in registration stacks |
| Trusted sender brand | Spoofed chamber alerts open because the brand already does |
| Lean IT | MSPs, shared hosts, membership CMS — thin security staff |
Same trust problem as our chamber email-spoofing primer — now with ransomware and malware against the org itself.
Independent cybersecurity audits
EmailMeNow domain audits on August 1, 2026. 100% is the ideal overall score — none of these reach it. Scores measure public identity / transport / website posture. They do not prove or disprove a ransomware intrusion path.
| Organization | Domain | Overall | Identity | Transport | Website | Risk |
|---|---|---|---|---|---|---|
| Greater Houston Partnership | houston.org | 70% | 95% | 15% | 37% | Good |
| Greater Austin Chamber | austinchamber.com | 65% | 80% | 15% | 40% | Above Average |
| Cuero Development Corporation | cuerodc.com | 51% | 50% | 15% | 37% | Average |
| Dallas Regional Chamber | dallaschamber.org | 50% | 45% | 15% | 37% | Average |
| Tulsa Regional Chamber | tulsachamber.com | 50% | 45% | 15% | 37% | Average |
| Cuero Chamber of Commerce | cuero.org | 46% | 35% | 15% | 37% | Below Average |
| Greater Oklahoma City Chamber | okcchamber.com | 32% | 0% | 15% | 37% | Weak |
Audit links: houston.org · austinchamber.com · cuerodc.com · dallaschamber.org · tulsachamber.com · cuero.org · okcchamber.com
Pattern: All 7 domains score 15% Transport Security — inbound mail transport (MTA-STS / related) is a sector-wide gap. Claimed ransomware victims Dallas and Tulsa sit at 50% overall (50 points under ideal). Peer Houston leads at 70% on strong identity (95%). Oklahoma City is the soft outlier at 32% with 0% identity.
How we graded MFA
Public member-login pages only — not a logged-in mystery shop of staff Microsoft 365 / Google Workspace. Methods change; re-check before you rely on this table. Same spirit as our national bank MFA scorecard.
| Grade | Meaning |
|---|---|
| Fail | Password-only (or email-first) login with no advertised second factor |
| Partial | App push / passkeys / proprietary soft token, but no standard TOTP and no YubiKey/FIDO |
| Pass (TOTP) | Self-serve Google Authenticator / Proton Pass-style OATH TOTP |
| Strong | FIDO2 / YubiKey-class security key for portal sign-in |
Member portal MFA — YubiKey and Google Authenticator
| Chamber | Portal | YubiKey / FIDO | Google Auth / TOTP | Login UX | Grade |
|---|---|---|---|---|---|
| Dallas Regional Chamber | hub.dallaschamber.org | No | No | Email + password | Fail |
| Tulsa Regional Chamber | Member login | No | No | Username + password | Fail |
| Greater Houston Partnership | member.houston.org/login | No | No | Company email first | Fail |
| Greater Austin Chamber | austinchamber.com/login | No | No | Email + password | Fail |
| Greater Oklahoma City Chamber | Member login | No | No | Username + password | Fail |
| Cuero Chamber | cuero.org/login (WordPress) | No | No | Email + password | Fail |
cuerodc.com is an economic-development site without a comparable public member hub in this review — graded on domain audit + stack only.

Takeaway: None of these six member surfaces advertise YubiKey or Google Authenticator. Password-only portals next to 50% victim-domain scores (and a 32% OKC outlier) is a poor combination when ransomware crews and info-stealers already name chambers. Staff Microsoft 365 MFA — if enabled — does not protect the chamber hub that holds member contacts.
Website stack note
Passive website-tech probes on August 1, 2026 covered 7 story domains (1 notable):
| Domain | Stack |
|---|---|
cuero.org | WordPress 6.9.5 — outdated vs latest 7.0.2; Paid Memberships Pro, Theme My Login |
cuerodc.com | WordPress 7.0.2 — current |
tulsachamber.com | PHP (version not exposed) |
okcchamber.com | PHP (version not exposed) |
houston.org | Next.js (version not exposed) |
dallaschamber.org | No notable CMS / PHP / short-horizon TLS flags |
austinchamber.com | No notable CMS / PHP / short-horizon TLS flags |
Cuero’s public chamber site still fingerprints behind current WordPress after a malware-related incident — patching the membership CMS matters even when the lure arrived via a third-party Shopify path.
Cybersquat / lookalike scan
DoH lookalike scans on August 1, 2026 (registered-only; BEC profile):
| Brand domain | Checked | To review | BEC staging | Highlights |
|---|---|---|---|---|
dallaschamber.org | 242 | 4 | 0 | dallaschamber.com / .biz / .info / .net — TLD swaps |
tulsachamber.com | 231 | 1 | 0 | tulsachambers.com — insertion (NS+A) |
cuero.org | 116 | 20 | 2 | cueto.org, uero.org — BEC staging (NS+MX) |
cuerodc.com | 150 | 4 | 0 | cuerocc.com, curodc.com — adjacent/omission with MX |
houston.org | 148 | 15 | 1 | houston.io — BEC staging (NS+MX) |
austinchamber.com | 246 | 1 | 0 | Brand holds redirect lookalikes (austin-chamber.com, austinchamber.org) |
okcchamber.com | 195 | 6 | 0 | kcchamber.com, okchamber.com — omissions with MX |
Short brands like cuero.org sit in a crowded lookalike space with live-MX staging domains — useful for the next “chamber invoice” lure even when the original incident was CAPTCHA malware. Track registrations with Cybersquat Domain Monitoring.
Priority actions for chambers
- Treat member data as high-value — offline/immutable backups; practice restore; segment membership CMS from finance workstations.
- Harden member portals — require MFA; Google Authenticator–class TOTP at minimum; YubiKey / FIDO for staff and privileged roles.
- Close email gaps — enforce DMARC; fix 15% transport (MTA-STS); share audit.emailmenow.com with members.
- Review third-party event stacks — Shopify / ticketing iframes and CAPTCHA widgets need the same scrutiny as the homepage.
- Train the never-Run-and-Paste rule — any CAPTCHA asking for
Win+R/Ctrl+Vis malware. - Monitor lookalikes — especially short city brands with live MX (cybersquat monitoring).
Related trackers
- IBM Cost of a Data Breach Report 2026
- Why chambers are prime email-spoofing targets
- Top Dallas chambers email security
- Top Oklahoma chambers email security
- National banks MFA — YubiKey vs Authenticator vs SMS
- WordPress WP2Shell RCE advisory
Sources: DeXpose — AiLock / Dallas Regional Chamber (Mar 3, 2026) · Ransomware.live — tulsachamber.com / DragonForce · Victoria Advocate — Cuero Chamber malware (Feb 2026) · Breachsense — Dallas ~1.3 TB indexer listing. Independent EmailMeNow domain audits, website-tech probes, cybersquat scans, and public portal MFA reviews August 1, 2026. Domain scores: audit.emailmenow.com only. Ransomware claims are actor-side unless the organization confirms.