Back to news
Cybersecurity Alert
July 25, 2026 by EmailMeNow IT Consulting

TPIS Industrial Services Data Breach Impacts 2,123 Texans — SSNs and Health Data Exposed

Pasadena, TX contractor TPIS Industrial Services notified 2,123 Texans after a ransomware incident; PLAY claimed the firm March 26. Texas AG filing July 17. Audits (100% ideal): tpis.com 47% with 0% identity and 15% transport.

Source: Texas OAG · Claim Depot

NewsData BreachRansomwareTexasIndustrialCybersecurity
Industrial contractor office with ransomware lock overlay on a computer

TPIS Industrial Services, Inc. — a family-owned industrial contractor headquartered in Pasadena, Texas — disclosed a data breach tied to a ransomware attack that exposed personal and health information. The company reported to the Texas Attorney General on July 17, 2026, identifying 2,123 Texas residents.

This is not a duplicate of our July 17 OAG week table, where TPIS is a single row. This post is a dedicated deep dive on the PLAY claim, data types, and domain audit.

Industrial contractor office with ransomware lock overlay on a computer

Snapshot

FieldDetail
CompanyTPIS Industrial Services, Inc. (tpis.com)
HQPasadena, Texas
Texas AG publishedJuly 17, 2026
Texans affected2,123 (~2,359 total per industry digests)
Threat claimPLAY ransomware — dark-web claim ~March 26, 2026
NoticeU.S. Mail beginning ~July 17, 2026

What may have been exposed

CategoryExamples reported
IdentityNames, addresses
Government IDsSocial Security numbers, driver’s licenses
Health (PHI)Medical information, health insurance
Business / payrollClient documents, budgets, payroll, tax/financial records (per PLAY claim summaries)

Why Gulf Coast employers should care

Industrial contractors often hold employee SSN + benefits/health files alongside project docs. A PLAY-style claim months before AG notice is a familiar Texas pattern: extortion first, regulatory clock later. Pair offline backups and MFA on remote access with vendor questionnaires that ask about ransomware tabletop results.

Independent cybersecurity audits

Audited July 25, 2026. 100% is the idealtpis.com does not reach it.

OrganizationDomainOverallIdentityTransportWebsitevs 100% ideal
TPIS Industrial Servicestpis.com47%0%15%87%−53

How to read this table: Identity 0% and transport 15% leave a wide gap for spoofed “TPIS breach help” or payroll email after notice letters go out — even when website headers score higher (87%).

Audit link: tpis.com

Website stack note

Passive website-tech probe on July 25, 2026 for tpis.com: no notable public CMS / PHP / short-horizon TLS flags. That does not identify the ransomware path. Point-in-time only.

What affected people should do

  1. Read the TPIS letter for exact data types and monitoring offers.
  2. Consider a credit freeze; watch tax / medical identity fraud.
  3. Verify any follow-up only through contacts in the letter — not cold email or text.

Run a free audit at audit.emailmenow.com or contact EmailMeNow for ransomware readiness aimed at the 100% ideal.


Sources: Claim Depot — TPIS · BeyondMachines — TPIS PLAY claim · Texas OAG breach portal