Back to news
Cybersecurity Alert
October 10, 2026 by EmailMeNow IT Consulting

Texas Cyber Command’s “Texas First. Cyber Ready.” Month Meets Live Phishing Reports

TXCC’s October campaign offers free MFA webinars while Harris County and Lavaca County warn about phishing. Audits (ideal 100%): co.lavaca.tx.us 78%, dir.texas.gov 49%, txcc.texas.gov 48%, constablepct4.com 31%.

Source: Texas Cyber Command · KENS 5 · Click2Houston · Crossroads Today

NewsPhishingTexasMFAYubiKeyAuthenticator AppsCybersecurityLocal Government
Texas government training table with a Stay cyber ready flyer and a note to type the website yourself

October is Cybersecurity Awareness Month. The San Antonio–based Texas Cyber Command is running “Texas First. Cyber Ready.” — free public webinars on phishing, identity theft, and multi-factor authentication. The same week, two local law-enforcement offices told Texans that phishing mail is already in inboxes.

KENS 5 (Oct 7) recapped the statewide campaign. Click2Houston (Oct 4) carried Harris County Constable Mark Herman’s “pause before you click” reminder. Crossroads Today (Oct 8) reported that the Lavaca County Sheriff’s Office is seeing phishing that can look like trusted mail.

This is awareness plus local alerts, not a reported breach of TXCC, DIR, Harris County Precinct 4, or Lavaca County.

Official campaign: Texas First. Cyber Ready. — Cybersecurity Awareness Month 2026

Texas government training table with a Stay cyber ready flyer and a note to type the website yourself

Snapshot

FieldDetail
Statewide campaignTXCC Texas First. Cyber Ready. — October 2026
Local alertsHarris County Constable Pct. 4 (Oct 4) · Lavaca County Sheriff (Oct 8)
Platform breachNot reported
CourtListener0 matching TXCC / Lavaca / Herman phishing dockets (searched Oct 10, 2026)
Report phishingForward the message as an attachment to phishing@txcc.texas.gov

House Bill 150 (89R, 2025) created TXCC and moved DIR cybersecurity operations to the Command. Headquarters is San Antonio. The public site still says stand-up in progress.

What TXCC is offering this month

Webinars are free, open to the public, and start at 10:00 a.m. Central (60 minutes). Register on the campaign page — type that address; do not use a “TXCC webinar” link from unexpected mail.

WeekThemeSessions still ahead
2Defending Your IdentityOct 13 identity / phishing · Oct 15 credential hygiene and MFA
3Emerging TechnologiesOct 20 AI / deepfakes · Oct 22 quantum · Oct 23 OT / infrastructure
4Cyber ResilienceOct 27 webinar · Oct 29 Capitol Auditorium (in person)

Week 1 (Oct 8, public-private partnerships) has already run. Questions: TXCCSecurity@txcc.texas.gov.

Government organizations still have a clock: report a qualifying incident within 48 hours of discovery (24 hours encouraged). The incident hotline is 877-347-2476. Calling it satisfies the statutory report. TXCC does not investigate private-citizen account takeovers — use local police, ReportFraud.ftc.gov, or IC3.

Local phishing, same week

Harris County Constable Precinct 4

Constable Mark Herman’s office told residents to treat unexpected email, texts, links, and attachments as suspect. Urgency is a tell. Type a number you already have. Do not enter a password on a page you reached from a cold message.

The office site is constablepct4.com. Dispatch: 281-376-3472.

Lavaca County Sheriff’s Office

LCSO told Hallettsville-area residents a phishing wave is circulating. Mail may look like a trusted sender and ask you to click or open an attachment. LCSO also heard similar messages hit other state, federal, and private inboxes. They did not publish a From address. Do not hunt for one.

Sheriff: co.lavaca.tx.us · 361-798-2121.

If you already clicked: tell IT or the sheriff’s office, reset passwords on hosts you type, and scan the device.

Printed phishing email on a kitchen table with a handwritten Do not click note

MFA: YubiKey and Google Authenticator

TXCC’s Oct 15 session is credential hygiene and MFA adoption. A hardware key does not un-click a fake “sheriff document.” It does stop a lot of replay after someone phishes email OTP. Grades match our MFA directory. Email OTP remaining is Fail even when a security key exists.

GradeMeaning
FailSMS, voice, or email OTP remains a documented factor
PassSelf-serve Google Authenticator-style open TOTP
StrongFIDO2 / YubiKey-class security key for sign-in
LoginGradeYubiKeyGoogle Authenticator
Texas Digital Identity (TDIS)FailSecurity key / hard tokenAuthenticator app named; GA not named
Texas OAG public loginFailNoNo
TXCC public siteUnevaluatedNo public login MFANo public login MFA

DIR’s TIAM / TDIS page documents authenticator app and security key, plus FIPS hard tokens for eligible agencies. The TDIS enrollment guide still walks users through a work-email verification code. Email remaining keeps the grade at Fail. Google Authenticator is not named. Prefer a security key or authenticator on a managed phone when your agency offers it.

Directory: MFA support directory · Category → Business Apps.

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
Proton PassPasskeys + authenticator-style TOTPProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Hardware security key beside a phone showing a generic authenticator code

Independent cybersecurity audits

We audited the Command host, DIR, Constable Pct. 4, and Lavaca County on October 10, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not mean TXCC or either sheriff’s office was breached.

OrganizationDomainOverallvs 100%
Lavaca Countyco.lavaca.tx.us78%−22
Texas DIRdir.texas.gov49%−51
Texas Cyber Commandtxcc.texas.gov48%−52
Constable Pct. 4constablepct4.com31%−69
DomainIdentityTransportWebsite
co.lavaca.tx.us75%15%90%
dir.texas.gov50%15%40%
txcc.texas.gov35%15%45%
constablepct4.com0%15%37%

Audit links: co.lavaca.tx.us · dir.texas.gov · txcc.texas.gov · constablepct4.com

constablepct4.com Identity 0% is why a fake “Constable Herman cybersecurity month” message can sit next to a real one. Type constablepct4.com and txcc.texas.gov. All four hosts sit at Transport 15% — spoofed “official” mail is easier to deliver than the 100% ideal.

Printed domain-audit scores well below the 100 percent ideal

Website stack

Passive homepage + Certificate Transparency probes (October 10, 2026). Versions only.

DomainStack note
txcc.texas.govCMS undetected; Sectigo TLS expires 2027-04-17
dir.texas.govCMS undetected; Sectigo TLS expires 2027-04-03
constablepct4.comCMS undetected; jQuery 1.8.3; Google Trust Services TLS expires 2026-12-05 (~55 days)
co.lavaca.tx.usASP.NET (no public version); Let’s Encrypt TLS expires 2027-01-06

jQuery 1.8.3 on the constable site is a freshness note, not a how-to. A short Google leaf date is a certificate calendar note, not an outage.

Blacklist and lookalikes

Email blacklist checks (public DoH, October 10, 2026): txcc.texas.gov, dir.texas.gov, and co.lavaca.tx.us were clear. constablepct4.com showed UCEPROTECT Level 3 hits on shared GoDaddy / secureserver.net MX — provider-netblock noise. We do not treat that as the office being blacklisted.

Registered lookalikes (BEC profile — not proof this week’s lures used them):

Brand scannedTo reviewLikely ownedBEC staging
txcc.texas.gov1302
constablepct4.com000
co.lavaca.tx.us3302
LookalikeTechniqueSignal
texas.cloud / texas.usTLD swap of texas.govNS + MX (BEC staging)
ntx.us / tx.netParent of .tx.usNS + MX (BEC staging)

The TXCC pass expands the registrable parent texas.gov. The Lavaca pass expands .tx.us. Hosts such as texas.com or tx.com are ordinary commercial TLD swaps — not evidence they were used in the LCSO wave. Type txcc.texas.gov, dir.texas.gov, constablepct4.com, and co.lavaca.tx.us. Continuous monitoring: Cybersquat Domain Monitoring.

CourtListener RECAP searches for Texas Cyber Command, the Lavaca phishing wave, and Constable Herman’s alert did not return a matching docket.

What Texans should do

  1. Register for the Oct 13 and Oct 15 TXCC webinars from the typed campaign page.
  2. Forward suspected phishing as an attachment to phishing@txcc.texas.gov. Do not click to “check” it.
  3. Bookmark txcc.texas.gov, constablepct4.com, and co.lavaca.tx.us.
  4. If your agency is on TDIS, enroll a security key or authenticator — do not stay on email OTP.
  5. Government IT: know the 48-hour TXCC report clock and the 877-347-2476 hotline.

Sources: TXCC Cybersecurity Awareness Month · TXCC incident reporting · KENS 5, Oct 7, 2026 · Click2Houston, Oct 4 · Crossroads Today, Oct 8 · DIR TIAM / TDIS · TDIS enrollment guide. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches October 10, 2026. Domain scores: audit.emailmenow.com only. No lure URLs, exploit PoCs, or sample pages in this post.