TPIS Industrial Services, Inc. — a family-owned industrial contractor headquartered in Pasadena, Texas — disclosed a data breach tied to a ransomware attack that exposed personal and health information. The company reported to the Texas Attorney General on July 17, 2026, identifying 2,123 Texas residents.
This is not a duplicate of our July 17 OAG week table, where TPIS is a single row. This post is a dedicated deep dive on the PLAY claim, data types, and domain audit.

Snapshot
| Field | Detail |
|---|---|
| Company | TPIS Industrial Services, Inc. (tpis.com) |
| HQ | Pasadena, Texas |
| Texas AG published | July 17, 2026 |
| Texans affected | 2,123 (~2,359 total per industry digests) |
| Threat claim | PLAY ransomware — dark-web claim ~March 26, 2026 |
| Notice | U.S. Mail beginning ~July 17, 2026 |
What may have been exposed
| Category | Examples reported |
|---|---|
| Identity | Names, addresses |
| Government IDs | Social Security numbers, driver’s licenses |
| Health (PHI) | Medical information, health insurance |
| Business / payroll | Client documents, budgets, payroll, tax/financial records (per PLAY claim summaries) |
Why Gulf Coast employers should care
Industrial contractors often hold employee SSN + benefits/health files alongside project docs. A PLAY-style claim months before AG notice is a familiar Texas pattern: extortion first, regulatory clock later. Pair offline backups and MFA on remote access with vendor questionnaires that ask about ransomware tabletop results.
Independent cybersecurity audits
Audited July 25, 2026. 100% is the ideal — tpis.com does not reach it.
| Organization | Domain | Overall | Identity | Transport | Website | vs 100% ideal |
|---|---|---|---|---|---|---|
| TPIS Industrial Services | tpis.com | 47% | 0% | 15% | 87% | −53 |
How to read this table: Identity 0% and transport 15% leave a wide gap for spoofed “TPIS breach help” or payroll email after notice letters go out — even when website headers score higher (87%).
Audit link: tpis.com
Website stack note
Passive website-tech probe on July 25, 2026 for tpis.com: no notable public CMS / PHP / short-horizon TLS flags. That does not identify the ransomware path. Point-in-time only.
What affected people should do
- Read the TPIS letter for exact data types and monitoring offers.
- Consider a credit freeze; watch tax / medical identity fraud.
- Verify any follow-up only through contacts in the letter — not cold email or text.
Related
Run a free audit at audit.emailmenow.com or contact EmailMeNow for ransomware readiness aimed at the 100% ideal.
Sources: Claim Depot — TPIS · BeyondMachines — TPIS PLAY claim · Texas OAG breach portal