This is EmailMeNow’s September 2026 monthly cyber briefing for Texas bar associations & law firms — peer incidents, living audit benchmarks, and actions staff can reuse in newsletters or board packs.
Cadence: editions for calendar month September publish on the last Sunday of the previous month (2026-08-30, America/Chicago). Re-run any domain anytime at audit.emailmenow.com — 100% is the ideal overall score.
Snapshot
| Field | Detail |
|---|---|
| Edition | September 2026 |
| Go-live | 2026-08-30 (last Sunday before September) |
| Audit / probe as-of | May 27, 2026 (listicle) · Texas Attorney General law-firm tracker through Aug 21, 2026 |
| Pattern | Law-firm Texas Attorney General notices + State Bar phishing watch; wire / IOLTA fraud risk |
| Texas firm signal | Named filings on the law-firm breaches tracker; Aug 21 Attorney General batch led by Wilmer Cutler Pickering Hale and Dorr LLP (~80k Texans affected — national firm filing, not a Texas HQ) |
| Audit range (top TX firms) | Norton Rose Fulbright 70% → Vinson & Elkins 39% — 0 of 15 at 100% |
| Association watch | State Bar of Texas phishing scams |
| Local leave-behind | Brazos County Bar August bulletin (Sep pack TBD) |
| IT security tip | Voice-callback on settlement and IOLTA changes — Number already on file — never the number in the email. |

This month’s signals
Law firms & State Bar watch
Texas lawyers remain high-value BEC targets (settlement wires, IOLTA, spoofed opposing counsel). Reuse:
- Texas State Bar phishing scams
- Law firm breaches 2026 tracker
- Top Texas law firms email security
- Texas Attorney General Aug 21 week — Wilmer Cutler Pickering Hale and Dorr LLP (~80,528 Texans) led that day’s legal filing (Texans-affected count; firm is not Texas-HQ)
Local pack for Brazos County Bar / Bryan–College Station firms: August bar bulletin (Sep leave-behind TBD).
Audit takeaway
Independent audits of major Texas firms still show a wide gap (best 70%, lowest 39%) with none at the 100% ideal — DMARC enforcement, MTA-STS, and lookalike monitoring remain the practical controls for firm ops and MSPs.
Living scoreboard (re-run to verify)
Full ranked tables live on the annual / seasonal listicle — scores change; treat the listicle date as a snapshot:
→ Top Texas law firms email-security listicle
Rule of thumb: if overall is below 100%, prioritize enforced DMARC, inbound MTA-STS, and MFA stronger than SMS before buying another “awareness” slide deck.
Priority actions
- Voice-callback on wire / settlement / IOLTA changes — number already on file.
- Enforce DMARC so spoofed “from the firm” mail fails in the inbox.
- Prefer app or hardware MFA for email and practice-management portals.
- Back up every workstation — ransomware recovery needs tested offline/immutable copies.
- Share the free self-check — audit.emailmenow.com for firms and clients.
IT Security Tip
Voice-callback on settlement and IOLTA changes
Wire and trust-account redirects remain a top law-firm loss path. Before changing settlement, IOLTA, or vendor payment instructions, call a number already on file. Ignore phone numbers and “urgent” links inside the same email thread.
Reuse this tip in member newsletters, Insider blurbs, or orientation slides — one tip per month keeps the cadence light.
Free member / firm benefit
Any Texas organization can run a 60-second domain self-check with no signup:
Printable association / chamber / bar leave-behinds:
- Chambers: B/CS Chamber September bulletin
- Credit unions: Cornerstone · America’s CUs · CUCT (August packs — still current)
- Bar / law: Brazos County Bar bulletin (August pack — still current)
Related trackers
- Texas Attorney General breach reports — 2026 YTD
- IBM Cost of a Data Breach Report 2026
- Law firm breaches 2026
- Texas State Bar phishing scams
Sources: EmailMeNow independent domain audits (audit.emailmenow.com); Texas Office of the Attorney General Data Security Breach Reports; peer incident posts linked above. Ransomware claims are intelligence leads until the organization confirms. Scores are public DNS / transport / header posture — not proof of intrusion.