Texas school districts (ISDs) continue to be prime targets for ransomware and major cyber incidents, disrupting operations and exposing student and staff data. A CBS Texas I-Team investigation found dozens of Texas school districts have been hit by cyberattacks, and a single district ransomware attack reportedly impacted more than 26,000 people.
Texas ISD Cyber Incidents (2026)
| District | Incident | Source |
|---|---|---|
| Uvalde CISD | Ransomware forced a district-wide shutdown of phones, cameras, AC controls, and other core systems | The Record |
| Lancaster ISD | Ransomware attack; attackers leaked the personal data of ~500 teachers to the dark web | WFAA |
| Houston ISD, Katy ISD, Lamar Consolidated ISD | Student/staff data exposed via the Canvas learning-platform breach claimed by ShinyHunters (third-party vendor) | Click2Houston |
Also Reported to the Texas OAG (Breach Notices)
Beyond the incidents above, these Texas school districts filed data breach notices with the Texas Attorney General:
| District | Texans Affected | Date Published |
|---|---|---|
| Alvin ISD | 48,877 | 06/30/2025 |
| Lovejoy ISD | 16,553 | 06/10/2025 |
| Eanes ISD | 9,506 | 04/27/2026 |
| Spring ISD | 5,690 | 05/20/2026 |
| Kerrville ISD | 4,300 | 08/26/2025 |
| Clarksville ISD | 2,980 | 02/25/2026 |
| Wharton ISD | 1,279 | 12/12/2025 |
| Sonora ISD | 853 | 03/03/2026 |
| Cleburne ISD | 684 | 07/15/2025 |
What Texas Law Requires
Texas mandates cybersecurity controls for public entities: districts must designate a cybersecurity coordinator (SB 820) and employees must complete certified cybersecurity training (HB 3834), aligned with the Texas DIR framework.
Check any district’s email posture at audit.emailmenow.com/?industry=local-government.
Recommendations for Districts
- Enforce DMARC, strict SPF, and DKIM; add MTA-STS and security headers.
- Adopt and document cybersecurity policies aligned with Texas DIR.
- Deliver HB 3834 training and designate a coordinator.
Protect your district. Contact EmailMeNow IT Consulting for staff training, policy documentation, and email hardening.
Sources: Texas OAG — Data Security Breach Reports · The Record — Uvalde CISD · WFAA — Lancaster ISD · Click2Houston — Canvas breach · CBS Texas I-Team