This is EmailMeNow’s August 2026 monthly cyber briefing for Texas credit unions — peer incidents, living audit benchmarks, and actions staff can reuse in newsletters or board packs.
Cadence: editions for calendar month August publish on the last Sunday of the previous month (2026-07-26, America/Chicago). Re-run any domain anytime at audit.emailmenow.com — 100% is the ideal overall score.
Snapshot
| Field | Detail |
|---|---|
| Edition | August 2026 |
| Go-live | 2026-07-26 (last Sunday before August) |
| Audit / probe as-of | June 2, 2026 (listicle) · Texas Attorney General credit-union notices through Jul 2026 · August Attorney General weeks |
| Pattern | Texas-based credit-union Texas Attorney General notices + domain email posture gaps; SMS MFA SIM-swap risk |
| Texas credit-union Attorney General peers | Energy Capital Credit Union (49,664) · MemberSource Credit Union (22,308) · Travis County Credit Union (2,996) |
| Audit range (15 major TX CUs) | Credit Human 74% → InTouch 33% — 0 of 15 at 100% ideal |
| Online-banking MFA | 15 Fail under SIM-swap grading (SMS/phone OTP primary) |
| Association leave-behinds | Cornerstone · America’s CUs · CUCT |
| IT security tip | Back up branch PCs, not just the core — Ransomware often starts on a laptop or teller workstation. |

This month’s signals
Texas credit-union breach notices
Three Texas-based credit unions on the Texas Attorney General Data Security Breach Reports portal (~75,000 Texans combined):
| Credit union | Base | Texans | Published |
|---|---|---|---|
| Energy Capital Credit Union | Houston | 49,664 | Jan 5, 2026 |
| MemberSource Credit Union | Houston | 22,308 | May 11, 2026 |
| Travis County Credit Union | Austin | 2,996 | Jul 31, 2026 |
Living trackers: Texas banks & credit unions Attorney General filings · MemberSource Credit Union brief · Jul 31 Attorney General week · Aug 21 Attorney General week.
Email / MFA posture
The Top Texas credit unions email-security listicle still shows none of 15 major TX CUs at the 100% ideal overall. Under EmailMeNow SIM-swap grading, consumer online-banking MFA for that set graded 15 Fail when SMS/phone OTP is primary — prefer authenticator-app TOTP or hardware keys for staff and high-risk members.
Living scoreboard (re-run to verify)
Full ranked tables live on the annual / seasonal listicle — scores change; treat the listicle date as a snapshot:
→ Top Texas credit unions email-security listicle
Rule of thumb: if overall is below 100%, prioritize enforced DMARC, inbound MTA-STS, and MFA stronger than SMS before buying another “awareness” slide deck.
Priority actions
- Voice-callback on wire / ACH changes — number already on file, never the number in the email.
- Prefer app or hardware MFA for staff email, VPN, and admin portals — not SMS alone.
- Enforce DMARC on the public CU domain — complementary to the core processor.
- Back up every machine — branch PCs and laptops, not just the core server; keep one copy offline/immutable.
- Member hygiene nudge — free domain self-check at audit.emailmenow.com.
IT Security Tip
Back up branch PCs, not just the core
Protect branch desktops and staff laptops with tested backups and at least one offline/immutable copy. Core recovery alone does not restore the workstation that opened the phishing lure.
Reuse this tip in member newsletters, Insider blurbs, or orientation slides — one tip per month keeps the cadence light.
Free member / firm benefit
Any Texas organization can run a 60-second domain self-check with no signup:
Printable association / chamber / bar leave-behinds:
- Chambers: B/CS Chamber August bulletin
- Credit unions: Cornerstone · America’s CUs · CUCT
- Bar / law: Brazos County Bar bulletin
Related trackers
- Texas Attorney General breach reports — 2026 YTD
- IBM Cost of a Data Breach Report 2026
- Major U.S. credit unions email security
- Texas banks MFA / SIM-swap / YubiKey
Sources: EmailMeNow independent domain audits (audit.emailmenow.com); Texas Office of the Attorney General Data Security Breach Reports; peer incident posts linked above. Ransomware claims are intelligence leads until the organization confirms. Scores are public DNS / transport / header posture — not proof of intrusion.