Back to news
Cybersecurity Alert
May 12, 2026 by EmailMeNow IT Consulting

Texas OAG Breach Reports Show 31,472,583 Texans Affected in 2026

Texas Attorney General breach-report data shows 426 published breach notices in 2026 year-to-date, affecting 31,472,583 Texans.

Source: Texas Office of the Attorney General Data Security Breach Reports

CybersecurityData BreachTexasLaw Firms
Cybersecurity dashboard tracking Texas OAG data breach reports in 2026

Texas Attorney General breach-report data shows that 426 data security breach notices have been published so far in 2026, affecting 31,472,583 Texans.

The data is current through Aug 28, 2026, based on published notices listed on the Texas OAG Data Security Breach Reports page. The OAG notes that report details, including the number of affected Texans and whether consumer notice was provided, may change after a report is listed.

Interactive Dashboard

Use the dashboard below to compare monthly report counts and Texans affected. The toggle switches between affected-person totals and the number of published breach notices.

Interactive Dashboard

Texas OAG Breach Reports: 2026 YTD

Published breach notices and affected Texans through Aug 28, 2026

Data current through Aug 28, 2026
2026 YTD reports 426
Texans affected 31.5M
Largest report 12.8M
Jan
267K
Feb
614.7K
Mar
1.2M
Apr
946.5K
May
14.4M
Jun
4.7M
Jul
7.3M
Aug MTD
2M
Show largest 2026 breach reports
Entity Published Texans affected Sector
Conduent Business Services, LLC (revised submission) May 20, 2026 12,784,367 Healthcare / Medical
DentaQuest, LLC Jul 17, 2026 3,973,000 Healthcare / Medical
Texas Parks and Wildlife Jun 26, 2026 3,087,721 Government / Education
Cerner Corporation Jul 7, 2026 2,658,388 Healthcare / Medical
Carnival Corporation May 28, 2026 800,060 Other

Source: Texas Office of the Attorney General Data Security Breach Reports. Totals reflect published notices and may change as reports are updated.

Sources

2026 Breach Activity by Month

May produced the largest affected-person count so far in 2026, driven heavily by a revised Conduent Business Services report. June month-to-date activity accelerated on June 18 when Texas Parks and Wildlife filed a report covering 3,087,721 Texans.

MonthReportsTexans Affected
Jan 202629267,010
Feb 202643614,701
Mar 2026561,158,740
Apr 202648946,524
May 20266014,398,629
Jun 2026644,706,160
Jul 2026607,343,239
Aug 2026 MTD662,037,580

2026 Compared with 2025

The 2026 year-to-date affected-person count has surpassed the full-year 2025 total in the committed OAG extract.

PeriodReportsTexans Affected
2026 YTD42631,472,583
2025 same period320,321
Full-year 202519017,865,265

Largest 2026 Breach Reports So Far

The largest published Texas OAG breach reports in 2026 by Texans affected are:

  1. Conduent Business Services, LLC (revised submission) - 12,784,367 Texans
  2. DentaQuest, LLC - 3,973,000 Texans
  3. Texas Parks and Wildlife - 3,087,721 Texans
  4. Cerner Corporation - 2,658,388 Texans
  5. Carnival Corporation - 800,060 Texans

The OAG dataset does not consistently identify the attack method, so these are the largest published breach reports by affected Texans, not necessarily the largest confirmed hacks by technique.

Most Common Data Exposures

Among 2026 reports, the most frequently listed exposed data types include:

  • Name of individual
  • Social Security number information
  • Medical information
  • Address
  • Driver’s license number
  • Financial information

Social Security numbers appeared in 357 of the 426 year-to-date reports, while medical information appeared in 244 reports.

Why This Matters for Texas Law Firms

Law firms hold sensitive client records, financial data, identification documents, medical information, employment records, and privileged communications. The breach trends reported to the Texas OAG show why firms should treat cybersecurity as both an operational and compliance priority.

For law firms, the practical lessons are clear:

  • Maintain documented access controls
  • Require multi-factor authentication
  • Review vendor access and contracts
  • Test backup restoration
  • Train staff on phishing, smishing, and social engineering
  • Keep incident response contacts and procedures current

Immediate Steps to Reduce Risk

Texas law firms should review whether they can document:

  • Who has access to sensitive systems
  • Which vendors can access client or firm data
  • Whether MFA is enabled on email, financial, and document systems
  • Whether backups are protected from ransomware
  • Whether staff know how to report suspicious messages

Run a free Instant Cybersecurity Audit at audit.emailmenow.com to evaluate your firm’s current risk level.

For help building a defensible cybersecurity program, contact EmailMeNow IT Consulting.