This is EmailMeNow’s August 2026 monthly cyber briefing for Texas chambers of commerce — peer incidents, living audit benchmarks, and actions staff can reuse in newsletters or board packs.
Cadence: editions for calendar month August publish on the last Sunday of the previous month (2026-07-26, America/Chicago). Re-run any domain anytime at audit.emailmenow.com — 100% is the ideal overall score.
Snapshot
| Field | Detail |
|---|---|
| Edition | August 2026 |
| Go-live | 2026-07-26 (last Sunday before August) |
| Audit / probe as-of | June 5, 2026 (listicle) · Aug 1, 2026 (peer ransomware) · Aug 21–22, 2026 (Texas Attorney General week · University of Texas at San Antonio) |
| Pattern | Peer chamber ransomware claims + local malware warnings; Aug education outages; domain audits still below the 100% ideal |
| Headline peers | Dallas Regional Chamber (AiLock claim) · Tulsa Regional Chamber (DragonForce claim) · Cuero Chamber of Commerce (confirmed fake-CAPTCHA) |
| Texas August add-ons | University of Texas at San Antonio attempted unauthorized activity (no confirmed theft) · Texas Attorney General August MTD ~58 notices / ~2.03M Texans through Aug 21 |
| Audit range (peers) | Greater Houston Partnership / houston.org 70% best · claimed victims 50% · Oklahoma City Chamber 32% — 0 of 7 at 100% |
| Member MFA | 0 of 6 public portals advertise YubiKey or Google Authenticator |
| Local leave-behind | B/CS Chamber August bulletin |
| IT security tip | Practice one offline restore — Backups only count if someone has restored from an offline copy. |

This month’s signals
Peer chambers hit by hacking
Ransomware crews and malware operators treated U.S. chambers as soft mid-market targets. Full field tables, MFA portal grades, and lookalike notes:
Claims vs confirmed: Dallas Regional Chamber (AiLock) and Tulsa Regional Chamber (DragonForce) remain actor listings until each chamber confirms. Cuero Chamber of Commerce warned members after a fake Win+R / Ctrl+V CAPTCHA tied to a Shopify event path — the confirmed Texas talking point.
Also on the Texas radar (late August)
- University of Texas at San Antonio systems offline after attempted unauthorized activity at the network edge — classes delayed; officials reported no evidence of data theft (do not call it a confirmed breach from the outage alone).
- Texas Attorney General Aug 21 week — 13 new notices / 136,398 Texans that day; August MTD ~58 notices / ~2.03M Texans through Aug 21.
- Local context: College Station Independent School District reviewed a ~$178k cybersecurity services agreement with the Texas A&M University System (Aug 25 board agenda) — useful board talking point that mid-market public entities are buying continuous monitoring.
Why it matters for Texas chambers
Chambers hold member directories, event payments, and a trusted sender brand every local business already opens. IBM’s Cost of a Data Breach Report 2026 found ransomware among ~39% of breached organizations, with ~41% of those including brand / reputation threats — the same pressure pattern as leak-site chamber claims.
Living scoreboard (re-run to verify)
Full ranked tables live on the annual / seasonal listicle — scores change; treat the listicle date as a snapshot:
→ Top Texas chambers of commerce email-security listicle
Rule of thumb: if overall is below 100%, prioritize enforced DMARC, inbound MTA-STS, and MFA stronger than SMS before buying another “awareness” slide deck.
Priority actions
- Treat member data as high-value — offline/immutable backups; practice restore.
- Harden member portals — require MFA; Google Authenticator–class TOTP minimum; YubiKey / FIDO for staff.
- Close email gaps — enforce DMARC; fix inbound transport (MTA-STS); share audit.emailmenow.com with members.
- Review third-party event stacks — Shopify / ticketing CAPTCHA widgets need the same scrutiny as the homepage.
- Train the never-Run-and-Paste rule — any CAPTCHA asking for Win+R / Ctrl+V is malware.
IT Security Tip
Practice one offline restore
Member lists and event systems need offline or immutable copies. Once a quarter, restore one critical folder or mailbox to a clean machine and time it — that drill beats another awareness slide.
Reuse this tip in member newsletters, Insider blurbs, or orientation slides — one tip per month keeps the cadence light.
Free member / firm benefit
Any Texas organization can run a 60-second domain self-check with no signup:
Printable association / chamber / bar leave-behinds:
- Chambers: B/CS Chamber August bulletin
- Credit unions: Cornerstone · America’s CUs · CUCT
- Bar / law: Brazos County Bar bulletin
Related trackers
- Texas Attorney General breach reports — 2026 YTD
- IBM Cost of a Data Breach Report 2026
- Chambers of commerce email spoofing
- DMARC member-benefit playbook
- University of Texas at San Antonio cyberattack attempt (Aug 2026)
Sources: EmailMeNow independent domain audits (audit.emailmenow.com); Texas Office of the Attorney General Data Security Breach Reports; peer incident posts linked above. Ransomware claims are intelligence leads until the organization confirms. Scores are public DNS / transport / header posture — not proof of intrusion.