Back to news
Cybersecurity Alert
August 30, 2026 by EmailMeNow IT Consulting

Texas Chambers of Commerce - September 2026 Cyber Monthly

September 2026 Texas chambers cyber briefing: peer incidents, domain-audit takeaways (ideal 100%), MFA notes, one IT security tip, and free member self-check links. Published on the last Sunday of the prior month.

Chambers of CommerceSmall BusinessBECEmail SecurityTexasMonthly
Digital audit dashboard with a Texas map highlighting chamber of commerce cybersecurity posture

This is EmailMeNow’s September 2026 monthly cyber briefing for Texas chambers of commerce — peer incidents, living audit benchmarks, and actions staff can reuse in newsletters or board packs.

Cadence: editions for calendar month September publish on the last Sunday of the previous month (2026-08-30, America/Chicago). Re-run any domain anytime at audit.emailmenow.com100% is the ideal overall score.

Snapshot

FieldDetail
EditionSeptember 2026
Go-live2026-08-30 (last Sunday before September)
Audit / probe as-ofJune 5, 2026 (listicle) · Aug 1, 2026 (peer ransomware) · Aug 21–22, 2026 (Texas Attorney General week · University of Texas at San Antonio)
PatternPeer chamber ransomware claims + local malware warnings; Aug education outages; domain audits still below the 100% ideal
Headline peersDallas Regional Chamber (AiLock claim) · Tulsa Regional Chamber (DragonForce claim) · Cuero Chamber of Commerce (confirmed fake-CAPTCHA)
Texas August add-onsUniversity of Texas at San Antonio attempted unauthorized activity (no confirmed theft) · Texas Attorney General August MTD ~58 notices / ~2.03M Texans through Aug 21
Audit range (peers)Greater Houston Partnership / houston.org 70% best · claimed victims 50% · Oklahoma City Chamber 32%0 of 7 at 100%
Member MFA0 of 6 public portals advertise YubiKey or Google Authenticator
Local leave-behindB/CS Chamber September bulletin
IT security tipNever Run-and-Paste a CAPTCHA — Win+R / Ctrl+V “verification” is malware, not a login check.

Digital audit dashboard with a Texas map highlighting chamber of commerce cybersecurity posture

This month’s signals

Peer chambers hit by hacking

Ransomware crews and malware operators treated U.S. chambers as soft mid-market targets. Full field tables, MFA portal grades, and lookalike notes:

Chambers hit by hacking — Dallas Regional Chamber, Tulsa Regional Chamber, Cuero Chamber of Commerce (Aug 2026)

Claims vs confirmed: Dallas Regional Chamber (AiLock) and Tulsa Regional Chamber (DragonForce) remain actor listings until each chamber confirms. Cuero Chamber of Commerce warned members after a fake Win+R / Ctrl+V CAPTCHA tied to a Shopify event path — the confirmed Texas talking point.

Also on the Texas radar (late August)

  • University of Texas at San Antonio systems offline after attempted unauthorized activity at the network edge — classes delayed; officials reported no evidence of data theft (do not call it a confirmed breach from the outage alone).
  • Texas Attorney General Aug 21 week — 13 new notices / 136,398 Texans that day; August MTD ~58 notices / ~2.03M Texans through Aug 21.
  • Local context: College Station Independent School District reviewed a ~$178k cybersecurity services agreement with the Texas A&M University System (Aug 25 board agenda) — useful board talking point that mid-market public entities are buying continuous monitoring.

Why it matters for Texas chambers

Chambers hold member directories, event payments, and a trusted sender brand every local business already opens. IBM’s Cost of a Data Breach Report 2026 found ransomware among ~39% of breached organizations, with ~41% of those including brand / reputation threats — the same pressure pattern as leak-site chamber claims.

Living scoreboard (re-run to verify)

Full ranked tables live on the annual / seasonal listicle — scores change; treat the listicle date as a snapshot:

Top Texas chambers of commerce email-security listicle

Rule of thumb: if overall is below 100%, prioritize enforced DMARC, inbound MTA-STS, and MFA stronger than SMS before buying another “awareness” slide deck.

Priority actions

  1. Treat member data as high-value — offline/immutable backups; practice restore.
  2. Harden member portals — require MFA; Google Authenticator–class TOTP minimum; YubiKey / FIDO for staff.
  3. Close email gaps — enforce DMARC; fix inbound transport (MTA-STS); share audit.emailmenow.com with members.
  4. Review third-party event stacks — Shopify / ticketing CAPTCHA widgets need the same scrutiny as the homepage.
  5. Train the never-Run-and-Paste rule — any CAPTCHA asking for Win+R / Ctrl+V is malware.

IT Security Tip

Never Run-and-Paste a CAPTCHA

Legitimate sites never ask you to open Run (Win+R), paste a command, and hit Enter to “prove you are human.” That pattern installs malware. Close the page, report it to IT, and tell members: if a CAPTCHA asks you to Run and Paste, it is fake.

Reuse this tip in member newsletters, Insider blurbs, or orientation slides — one tip per month keeps the cadence light.

Free member / firm benefit

Any Texas organization can run a 60-second domain self-check with no signup:

audit.emailmenow.com

Printable association / chamber / bar leave-behinds:


Sources: EmailMeNow independent domain audits (audit.emailmenow.com); Texas Office of the Attorney General Data Security Breach Reports; peer incident posts linked above. Ransomware claims are intelligence leads until the organization confirms. Scores are public DNS / transport / header posture — not proof of intrusion.