This is EmailMeNow’s August 2026 monthly cyber briefing for Texas bar associations & law firms — peer incidents, living audit benchmarks, and actions staff can reuse in newsletters or board packs.
Cadence: editions for calendar month August publish on the last Sunday of the previous month (2026-07-26, America/Chicago). Re-run any domain anytime at audit.emailmenow.com — 100% is the ideal overall score.
Snapshot
| Field | Detail |
|---|---|
| Edition | August 2026 |
| Go-live | 2026-07-26 (last Sunday before August) |
| Audit / probe as-of | May 27, 2026 (listicle) · Texas Attorney General law-firm tracker through Aug 21, 2026 |
| Pattern | Law-firm Texas Attorney General notices + State Bar phishing watch; wire / IOLTA fraud risk |
| Texas firm signal | Named filings on the law-firm breaches tracker; Aug 21 Attorney General batch led by Wilmer Cutler Pickering Hale and Dorr LLP (~80k Texans affected — national firm filing, not a Texas HQ) |
| Audit range (top TX firms) | Norton Rose Fulbright 70% → Vinson & Elkins 39% — 0 of 15 at 100% |
| Association watch | State Bar of Texas phishing scams |
| Local leave-behind | Brazos County Bar August bulletin (Sep pack TBD) |
| IT security tip | Back up every workstation offline — Ransomware recovery needs a tested copy outside the live network. |

This month’s signals
Law firms & State Bar watch
Texas lawyers remain high-value BEC targets (settlement wires, IOLTA, spoofed opposing counsel). Reuse:
- Texas State Bar phishing scams
- Law firm breaches 2026 tracker
- Top Texas law firms email security
- Texas Attorney General Aug 21 week — Wilmer Cutler Pickering Hale and Dorr LLP (~80,528 Texans) led that day’s legal filing (Texans-affected count; firm is not Texas-HQ)
Local pack for Brazos County Bar / Bryan–College Station firms: August bar bulletin (Sep leave-behind TBD).
Audit takeaway
Independent audits of major Texas firms still show a wide gap (best 70%, lowest 39%) with none at the 100% ideal — DMARC enforcement, MTA-STS, and lookalike monitoring remain the practical controls for firm ops and MSPs.
Living scoreboard (re-run to verify)
Full ranked tables live on the annual / seasonal listicle — scores change; treat the listicle date as a snapshot:
→ Top Texas law firms email-security listicle
Rule of thumb: if overall is below 100%, prioritize enforced DMARC, inbound MTA-STS, and MFA stronger than SMS before buying another “awareness” slide deck.
Priority actions
- Voice-callback on wire / settlement / IOLTA changes — number already on file.
- Enforce DMARC so spoofed “from the firm” mail fails in the inbox.
- Prefer app or hardware MFA for email and practice-management portals.
- Back up every workstation — ransomware recovery needs tested offline/immutable copies.
- Share the free self-check — audit.emailmenow.com for firms and clients.
IT Security Tip
Back up every workstation offline
Attorney laptops hold matter files that never made it to the DMS. Keep offline or immutable backups and practice restoring one workstation image so a ransomware week is not a total outage.
Reuse this tip in member newsletters, Insider blurbs, or orientation slides — one tip per month keeps the cadence light.
Free member / firm benefit
Any Texas organization can run a 60-second domain self-check with no signup:
Printable association / chamber / bar leave-behinds:
- Chambers: B/CS Chamber August bulletin
- Credit unions: Cornerstone · America’s CUs · CUCT
- Bar / law: Brazos County Bar bulletin
Related trackers
- Texas Attorney General breach reports — 2026 YTD
- IBM Cost of a Data Breach Report 2026
- Law firm breaches 2026
- Texas State Bar phishing scams
Sources: EmailMeNow independent domain audits (audit.emailmenow.com); Texas Office of the Attorney General Data Security Breach Reports; peer incident posts linked above. Ransomware claims are intelligence leads until the organization confirms. Scores are public DNS / transport / header posture — not proof of intrusion.