Back to news
Cybersecurity Alert
September 26, 2026 by EmailMeNow IT Consulting

Princeton TX Reviews Find No Confirmed Breach After Ransomware Group Claims City Data

Collin County city says two reviews found no unauthorized access after a ransomware group claimed municipal data. Audits (ideal 100%): sevnx.com 76%, princetontx.gov 44%, civicplus.com 43%, texasattorneygeneral.gov 37%. CivicPlus: Google Authenticator yes, YubiKey not documented.

Source: City of Princeton · NBC 5 DFW

NewsRansomwareLocal GovernmentPhishingMFAYubiKeyAuthenticator AppsCybersecurity
Municipal desk after hours with a darkened monitor and a printed Investigation Ongoing notice

The City of Princeton (Collin County) is investigating an alleged cybersecurity incident. A ransomware group is claiming it copied municipal files. The city’s September 22, 2026, 7:12 p.m. update says two independent reviews have not found evidence of unauthorized access, a confirmed data breach, or unauthorized exfiltration. A third forensic review is underway. NBC 5 DFW reported the claim-versus-review split on September 22.

This is not a confirmed resident-data breach. It is not a finished forensic finding. Online leak-site posts are claims. The city says it will rely on its investigation, not outside parties, to decide what happened.

Municipal desk after hours with a darkened monitor and a printed Investigation Ongoing notice

Snapshot

FieldDetail
CityPrinceton, Texas — princetontx.gov
First noticeSept 18, 2026 — “potential unauthorized access”
Agenda languageSept 21 emergency notice — “intrusion” into critical IT and communications (Princeton Herald)
Latest city updateSept 22, 7:12 p.m. — two reviews found no unauthorized access / confirmed breach / exfil; third review hired
Online claimsUnverified ransomware-group post, summarized by SEVN-X CEO Matt Barnett on NBC 5
CourtListener0 matching RECAP dockets for this incident (searched Sept 26, 2026)

What changed in public language

Princeton published two official characterizations in four days. TX3DNews asked the city to reconcile them. We label both. We do not pick a winner.

DateWhat officials said
Sept 18City NewsFlash: responding to a cybersecurity incident involving potential unauthorized access to certain systems and data. Scope still unknown.
Sept 21Emergency supplemental agenda: an active incident resulting in an intrusion into critical IT and communications. Council may authorize emergency contracts.
Sept 21 meetingClosed session ~22 minutes. Councilmember Terrance Johnson said the city had nothing to report afterward (Herald, Sept 23).
Sept 21 remarksMayor Eugene Escobar Jr.: “As of today, there has been no evidence that anything posted online is actually accurate.”
Sept 22, 7:12 p.m.Two independent reviews: no evidence of unauthorized access, a confirmed data breach, or unauthorized exfiltration. Third firm hired for a comprehensive forensic review. Essential services continue.

The Sept 18 notice already said the city was aware of information circulating online and would not treat those claims as the scope finding. If personal information is later found affected, the city says it will send required notices under applicable law.

What a group claimed — still unverified

NBC 5 quoted Barnett describing the group’s post, not a city confirmation. Treat every line below as an allegation:

Claim (unverified)Why it matters
“Complete backup” of an internal file server / 20 departmental foldersWould be a city-wide records problem if proven
About 2 GB, 13,000+ residential addresses, 2,500+ new accounts, delinquent accountsUtility / permitting phishing bait if residents believe it
Credentials, court records, device forensics including the mayor’s phoneFollow-on BEC and impersonation risk
10 days to make contact before “full publication”Classic leak-site countdown — not a legal deadline for residents

Barnett told NBC 5 the first job is proof of life — whether the actor can show they actually hold the files. He also said actors rarely advertise data they cannot later produce, and that he is not inside Princeton’s investigation. Those are an outsider’s cautions, not a forensic report.

We do not link leak sites, sample files, or countdown pages.

Unverified-claim printouts beside independent-review folders and a pending forensic-review folder

What residents should do now

  1. Type princetontx.gov yourself. Bookmark the NewsFlash update. Ignore “city breach / pay this invoice / restore your account” mail and texts.
  2. Do not send money, Bitcoin, or “verification” codes to anyone claiming to represent the city, a ransomware crew, or a recovery firm you did not hire.
  3. Utility, court, and permit logins: change passwords on the typed city or vendor URL if you use those portals. Turn on an authenticator app where it is offered (see MFA below).
  4. If you get a notice that names you and claims city records were stolen, wait for a letter or portal message that matches the official NewsFlash — or call City Hall at the number on a paper bill. Do not call a number inside the email.
  5. Phishing that uses this headline: report it to the FBI IC3 and the Texas Attorney General. A credit freeze is a personal choice if you see account openings — not something the Sept 22 review requires.

Princeton’s identity score is 10%. Spoofed “City of Princeton IT / Communications / Mayor” mail is easier to deliver than it should be. The official host is still the one to type.

MFA: YubiKey and Google Authenticator

A hardware key does not settle whether a file server was copied. It does cut a lot of the follow-on phishing that follows a municipal headline: CivicPlus website accounts, vendor portals, and staff webmail.

GradeMeaning
FailSMS, email OTP, or no public key / open TOTP
PassSelf-serve Google Authenticator-style open TOTP
StrongFIDO2 / YubiKey-class security key for sign-in
PlatformGradeYubiKeyAuthenticator
CivicPlus accountPassNoYes
Princeton Website Sign InPassNoYes
Texas Attorney GeneralFailNoNo

CivicPlus (updated July 1, 2026) names Google Authenticator and other TOTP apps for account.civicplus.com. Email one-time codes are the documented fallback. YubiKey / FIDO and account passkeys are not documented. An organization can require 2FA; it is not automatic on every CivicEngage “Website Sign In.” Princeton’s resident login is at princetontx.gov/MyAccount.

The Texas OAG public login is username and password. Consumer-complaint help describes a confirmation email, not a YubiKey or authenticator enroll. MFA does not make a fake “AG breach notice” safe.

Staff mail for princetontx.gov is Unevaluated — no public Microsoft 365 / Google Workspace MFA page we can grade. We do not invent a YubiKey path for Outlook.

Directory: MFA support directory · Category → Business Apps.

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
Proton PassPasskeys + authenticator-style TOTPProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Hardware security key beside an authenticator phone and a Website Sign In reminder

Independent cybersecurity audits

We audited the city host, its CivicPlus vendor, the quoted incident-response firm, and the Texas AG consumer-reporting host on September 26, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not prove or disprove a file-server copy.

OrganizationDomainOverallvs 100%
SEVN-Xsevnx.com76%−24
City of Princetonprincetontx.gov44%−56
CivicPluscivicplus.com43%−57
Texas Attorney Generaltexasattorneygeneral.gov37%−63
DomainIdentityTransportWebsite
sevnx.com90%15%65%
princetontx.gov10%15%65%
civicplus.com25%45%37%
texasattorneygeneral.gov10%15%40%

Audit links: princetontx.gov · civicplus.com · sevnx.com · texasattorneygeneral.gov

City and OAG Identity 10% plus Transport 15% is the same pattern that makes spoofed “forensic update” and “your water account” mail easier to land. Type the hosts. Do not use a link from a countdown post.

Printed domain-audit scores well below the 100 percent ideal

Website stack

Passive homepage + Certificate Transparency probes (September 26, 2026). Versions only — not a claim these sites were compromised.

DomainStack note
princetontx.govASP.NET (CivicPlus); SSL.com TLS expires 2026-12-22
civicplus.comCMS undetected; Let’s Encrypt TLS expires 2026-12-04
sevnx.comHubSpot (vendor-managed); Google Trust Services TLS expires 2026-12-02
texasattorneygeneral.govCMS undetected; Sectigo TLS expires 2026-12-09

A live CivicPlus homepage does not mean back-office file servers were, or were not, touched.

Blacklist and lookalikes

Email blacklist checks (public DoH, September 26, 2026): princetontx.gov, civicplus.com, sevnx.com, and texasattorneygeneral.gov were clear on mail/domain lists we can query. City, CivicPlus, and OAG web/CDN IPs showed informational SPFBL notes — not led as mail reputation.

Registered lookalikes (BEC profile — not proof this incident used them):

Brand scannedTo reviewLikely ownedBEC staging
princetontx.gov210
civicplus.com1010
sevnx.com340
texasattorneygeneral.gov110
LookalikeTechniqueSignal
princetontx.comTLD swapNS + A — not the official .gov
princetontx.orgTLD swapNS + A + MX; parking lander
princetontx.usTLD swapRedirects to princetontx.gov
civicplus.ai / .io / .orgTLD swapRegistered; civicplus.cloud redirects to the brand
servnx.comInsertionNS + A
texasattorneygeneral.orgTLD swapNS + A + MX; .com redirects to the official .gov

Type princetontx.gov, civicplus.com, sevnx.com, and texasattorneygeneral.gov. Continuous monitoring: Cybersquat Domain Monitoring.

CourtListener RECAP searches for Princeton, Texas + ransomware / cybersecurity / data breach (September 26, 2026) did not return a docket for this incident. Older water-utility civil cases involving the city are a different story.

Sources: City of Princeton NewsFlash, Sept 18 / updated Sept 22, 2026 · NBC 5 DFW · Princeton Herald Sept 20 · Herald emergency-agenda update · Herald Sept 23 · TX3DNews Sept 23 · Princeton Weekly · SEVN-X · CivicPlus 2FA docs · Texas OAG identity theft · IC3. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches September 26, 2026. Domain scores: audit.emailmenow.com only. No leak-site links or sample files in this post.