Back to news
Cybersecurity Alert
July 31, 2026 by EmailMeNow IT Consulting

6 New Texas Breach Reports Published July 31, 2026: 9,787 Texans Affected

Texas OAG published 6 new data security breach reports on July 31, 2026, affecting 9,787 Texans. Goodwin Procter LLP led the batch with 1,550 affected.

Source: Texas Office of the Attorney General Data Security Breach Reports

CybersecurityData BreachTexas
Texas data breach report roundup for July 31, 2026

The Texas Office of the Attorney General published 6 new data security breach reports on July 31, 2026, according to a fresh scrape of the Texas OAG Data Security Breach Reports portal. Combined, these reports cover 9,787 Texans.

The largest filing — Goodwin Procter LLP — accounts for 1,550 affected Texans in this batch. See the live Texas OAG YTD dashboard for monthly charts.

July month-to-date now totals 68 published reports affecting 7,622,824 Texans through July 31, 2026.

Sector breakdown

  • Financial: 2 reports, 3,280 Texans — led by Travis County Credit Union
  • Government / education: 1 report, 2,996 Texans — led by Travis County Credit Union
  • Other sectors: 4 reports, 6,507 Texans

Reports Published July 31, 2026

EntityTexans AffectedConsumer NoticeDate Published
SM Energy Company3,851Yes07/31/2026
Travis County Credit Union2,996Yes07/31/2026
Goodwin Procter LLP1,550Yes07/31/2026
TELUS International AI, Inc., d/b/a TELUS Digital625Yes07/31/2026
MPS Enterprises, Inc. (“MPS”)481Yes07/31/2026
Sunrise Company284Yes07/31/2026

The OAG notes that report details — including the number of affected Texans and whether consumer notice was provided — may change after a report is first listed.

Independent Cybersecurity Audits

EmailMeNow domain audits on July 31, 2026 scored 8 filer domains in this batch. 7 of 8 show 15% Transport Security or below — a recurring gap that makes spoofed breach-notification email easier to deliver. Travis County Credit Union (traviscountytx.gov) leads at 62% overall; SM Energy Company (peoplesenergy.co.uk) scores 23%.

Pattern: Scores below the 100% ideal on identity or transport still leave room for spoofed incident-response email — even when website headers score higher.

OrganizationDomainOverallIdentityTransportWebsiteRisk
SM Energy Companypeoplesenergy.co.uk23%0%15%37%Weakest
SM Energy Companyoekovolt.com43%35%15%45%Below Average
SM Energy Companyofs.com46%45%15%40%Below Average
Travis County Credit Uniontraviscountytx.gov62%50%15%87%Above Average
Goodwin Procter LLPgoodwinprocter.com47%50%15%37%Below Average
TELUS International AI, Inc., d/b/a TELUS Digitaltelusinternational.com53%65%15%37%Average
MPS Enterprises, Inc. (“MPS”)mpsenterprises.co.uk41%35%15%37%Below Average
Sunrise Companysunrisecompany.nl38%25%45%37%Weak

Audit links: peoplesenergy.co.uk · oekovolt.com · ofs.com · traviscountytx.gov · goodwinprocter.com · telusinternational.com · mpsenterprises.co.uk · sunrisecompany.nl

Website stack note

  • MPS Enterprises, Inc. (“MPS”) (mpsenterprises.co.uk): PHP outdated/unsupported (5.3.29 — no vendor security patches)
  • SM Energy Company (ofs.com): Drupal behind current (running 11; latest 11.4.5)
  • Sunrise Company (sunrisecompany.nl): PHP outdated/unsupported (7.4.33 — no vendor security patches); WordPress behind current (running 6.7.7; latest 7.0.4)
  • Travis County Credit Union (traviscountytx.gov): Bootstrap: Bootstrap 3/4 are past primary vendor support; upgrade to Bootstrap 5 when practical (often theme-bundled).

Source: Texas OAG Data Security Breach Reports