The City of Princeton (Collin County) is investigating an alleged cybersecurity incident. A ransomware group is claiming it copied municipal files. The city’s September 22, 2026, 7:12 p.m. update says two independent reviews have not found evidence of unauthorized access, a confirmed data breach, or unauthorized exfiltration. A third forensic review is underway. NBC 5 DFW reported the claim-versus-review split on September 22.
This is not a confirmed resident-data breach. It is not a finished forensic finding. Online leak-site posts are claims. The city says it will rely on its investigation, not outside parties, to decide what happened.

Snapshot
| Field | Detail |
|---|---|
| City | Princeton, Texas — princetontx.gov |
| First notice | Sept 18, 2026 — “potential unauthorized access” |
| Agenda language | Sept 21 emergency notice — “intrusion” into critical IT and communications (Princeton Herald) |
| Latest city update | Sept 22, 7:12 p.m. — two reviews found no unauthorized access / confirmed breach / exfil; third review hired |
| Online claims | Unverified ransomware-group post, summarized by SEVN-X CEO Matt Barnett on NBC 5 |
| CourtListener | 0 matching RECAP dockets for this incident (searched Sept 26, 2026) |
What changed in public language
Princeton published two official characterizations in four days. TX3DNews asked the city to reconcile them. We label both. We do not pick a winner.
| Date | What officials said |
|---|---|
| Sept 18 | City NewsFlash: responding to a cybersecurity incident involving potential unauthorized access to certain systems and data. Scope still unknown. |
| Sept 21 | Emergency supplemental agenda: an active incident resulting in an intrusion into critical IT and communications. Council may authorize emergency contracts. |
| Sept 21 meeting | Closed session ~22 minutes. Councilmember Terrance Johnson said the city had nothing to report afterward (Herald, Sept 23). |
| Sept 21 remarks | Mayor Eugene Escobar Jr.: “As of today, there has been no evidence that anything posted online is actually accurate.” |
| Sept 22, 7:12 p.m. | Two independent reviews: no evidence of unauthorized access, a confirmed data breach, or unauthorized exfiltration. Third firm hired for a comprehensive forensic review. Essential services continue. |
The Sept 18 notice already said the city was aware of information circulating online and would not treat those claims as the scope finding. If personal information is later found affected, the city says it will send required notices under applicable law.
What a group claimed — still unverified
NBC 5 quoted Barnett describing the group’s post, not a city confirmation. Treat every line below as an allegation:
| Claim (unverified) | Why it matters |
|---|---|
| “Complete backup” of an internal file server / 20 departmental folders | Would be a city-wide records problem if proven |
| About 2 GB, 13,000+ residential addresses, 2,500+ new accounts, delinquent accounts | Utility / permitting phishing bait if residents believe it |
| Credentials, court records, device forensics including the mayor’s phone | Follow-on BEC and impersonation risk |
| 10 days to make contact before “full publication” | Classic leak-site countdown — not a legal deadline for residents |
Barnett told NBC 5 the first job is proof of life — whether the actor can show they actually hold the files. He also said actors rarely advertise data they cannot later produce, and that he is not inside Princeton’s investigation. Those are an outsider’s cautions, not a forensic report.
We do not link leak sites, sample files, or countdown pages.

What residents should do now
- Type princetontx.gov yourself. Bookmark the NewsFlash update. Ignore “city breach / pay this invoice / restore your account” mail and texts.
- Do not send money, Bitcoin, or “verification” codes to anyone claiming to represent the city, a ransomware crew, or a recovery firm you did not hire.
- Utility, court, and permit logins: change passwords on the typed city or vendor URL if you use those portals. Turn on an authenticator app where it is offered (see MFA below).
- If you get a notice that names you and claims city records were stolen, wait for a letter or portal message that matches the official NewsFlash — or call City Hall at the number on a paper bill. Do not call a number inside the email.
- Phishing that uses this headline: report it to the FBI IC3 and the Texas Attorney General. A credit freeze is a personal choice if you see account openings — not something the Sept 22 review requires.
Princeton’s identity score is 10%. Spoofed “City of Princeton IT / Communications / Mayor” mail is easier to deliver than it should be. The official host is still the one to type.
MFA: YubiKey and Google Authenticator
A hardware key does not settle whether a file server was copied. It does cut a lot of the follow-on phishing that follows a municipal headline: CivicPlus website accounts, vendor portals, and staff webmail.
| Grade | Meaning |
|---|---|
| Fail | SMS, email OTP, or no public key / open TOTP |
| Pass | Self-serve Google Authenticator-style open TOTP |
| Strong | FIDO2 / YubiKey-class security key for sign-in |
| Platform | Grade | YubiKey | Authenticator |
|---|---|---|---|
| CivicPlus account | Pass | No | Yes |
| Princeton Website Sign In | Pass | No | Yes |
| Texas Attorney General | Fail | No | No |
CivicPlus (updated July 1, 2026) names Google Authenticator and other TOTP apps for account.civicplus.com. Email one-time codes are the documented fallback. YubiKey / FIDO and account passkeys are not documented. An organization can require 2FA; it is not automatic on every CivicEngage “Website Sign In.” Princeton’s resident login is at princetontx.gov/MyAccount.
The Texas OAG public login is username and password. Consumer-complaint help describes a confirmation email, not a YubiKey or authenticator enroll. MFA does not make a fake “AG breach notice” safe.
Staff mail for princetontx.gov is Unevaluated — no public Microsoft 365 / Google Workspace MFA page we can grade. We do not invent a YubiKey path for Outlook.
Directory: MFA support directory · Category → Business Apps.
Recommended MFA tools
| Product | Best for | Get it |
|---|---|---|
| YubiKey 5C NFC | USB-C laptops + NFC phones | Amazon |
| YubiKey 5 NFC | USB-A desktops + NFC phones | Amazon |
| Proton Pass | Passkeys + authenticator-style TOTP | Proton Pass |
We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Independent cybersecurity audits
We audited the city host, its CivicPlus vendor, the quoted incident-response firm, and the Texas AG consumer-reporting host on September 26, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not prove or disprove a file-server copy.
| Organization | Domain | Overall | vs 100% |
|---|---|---|---|
| SEVN-X | sevnx.com | 76% | −24 |
| City of Princeton | princetontx.gov | 44% | −56 |
| CivicPlus | civicplus.com | 43% | −57 |
| Texas Attorney General | texasattorneygeneral.gov | 37% | −63 |
| Domain | Identity | Transport | Website |
|---|---|---|---|
| sevnx.com | 90% | 15% | 65% |
| princetontx.gov | 10% | 15% | 65% |
| civicplus.com | 25% | 45% | 37% |
| texasattorneygeneral.gov | 10% | 15% | 40% |
Audit links: princetontx.gov · civicplus.com · sevnx.com · texasattorneygeneral.gov
City and OAG Identity 10% plus Transport 15% is the same pattern that makes spoofed “forensic update” and “your water account” mail easier to land. Type the hosts. Do not use a link from a countdown post.

Website stack
Passive homepage + Certificate Transparency probes (September 26, 2026). Versions only — not a claim these sites were compromised.
| Domain | Stack note |
|---|---|
| princetontx.gov | ASP.NET (CivicPlus); SSL.com TLS expires 2026-12-22 |
| civicplus.com | CMS undetected; Let’s Encrypt TLS expires 2026-12-04 |
| sevnx.com | HubSpot (vendor-managed); Google Trust Services TLS expires 2026-12-02 |
| texasattorneygeneral.gov | CMS undetected; Sectigo TLS expires 2026-12-09 |
A live CivicPlus homepage does not mean back-office file servers were, or were not, touched.
Blacklist and lookalikes
Email blacklist checks (public DoH, September 26, 2026): princetontx.gov, civicplus.com, sevnx.com, and texasattorneygeneral.gov were clear on mail/domain lists we can query. City, CivicPlus, and OAG web/CDN IPs showed informational SPFBL notes — not led as mail reputation.
Registered lookalikes (BEC profile — not proof this incident used them):
| Brand scanned | To review | Likely owned | BEC staging |
|---|---|---|---|
| princetontx.gov | 2 | 1 | 0 |
| civicplus.com | 10 | 1 | 0 |
| sevnx.com | 3 | 4 | 0 |
| texasattorneygeneral.gov | 1 | 1 | 0 |
| Lookalike | Technique | Signal |
|---|---|---|
| princetontx.com | TLD swap | NS + A — not the official .gov |
| princetontx.org | TLD swap | NS + A + MX; parking lander |
| princetontx.us | TLD swap | Redirects to princetontx.gov |
| civicplus.ai / .io / .org | TLD swap | Registered; civicplus.cloud redirects to the brand |
| servnx.com | Insertion | NS + A |
| texasattorneygeneral.org | TLD swap | NS + A + MX; .com redirects to the official .gov |
Type princetontx.gov, civicplus.com, sevnx.com, and texasattorneygeneral.gov. Continuous monitoring: Cybersquat Domain Monitoring.
CourtListener RECAP searches for Princeton, Texas + ransomware / cybersecurity / data breach (September 26, 2026) did not return a docket for this incident. Older water-utility civil cases involving the city are a different story.
Related coverage
- Norcross, GA confirmed ransomware
- ATF major incident / Qilin claim
- Houston brushing / QR-package alert
- Paxton CIPA demand-letter alert
- MFA support directory
Sources: City of Princeton NewsFlash, Sept 18 / updated Sept 22, 2026 · NBC 5 DFW · Princeton Herald Sept 20 · Herald emergency-agenda update · Herald Sept 23 · TX3DNews Sept 23 · Princeton Weekly · SEVN-X · CivicPlus 2FA docs · Texas OAG identity theft · IC3. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches September 26, 2026. Domain scores: audit.emailmenow.com only. No leak-site links or sample files in this post.