Back to overview
Confidence MediumFeb 9, 2025texasbar.com

State Bar of Texas suffers data breach by INC ransomware gang

PatternExternal actor · Malware · Confidentiality impact

The State Bar of Texas experienced a data breach due to unauthorized access to its network between January 28 and February 9, 2025. The incident was discovered on February 12, 2025. The INC ransomware gang claimed responsibility for the attack, adding the organization to its dark web extortion page on March 9, 2025, and leaking samples of allegedly stolen data. The compromised information, affecting approximately 2,700 individuals, included full names, Social Security numbers, financial account information (including account and credit/debit card numbers), driver's licenses or other government-issued IDs, medical information, and health insurance information. The State Bar of Texas offered free credit and identity theft monitoring services to affected members.

Signal date
Feb 9, 2025
Updated
Jun 30, 2026
Confidence
Medium
Sources
2 sources
texasbar.com logo

Texasbar

Sector
Finance and Insurance
Signals
1 linked

Signal context

First seen: Feb 9, 2025

Last updated: Jun 30, 2026

Status: Public signal

Key points

  • Unauthorized access to the State Bar of Texas network occurred between January 28 and February 9, 2025.
  • Incident discovered on February 12, 2025.
  • INC ransomware gang claimed responsibility for the attack.

Signal analysis

Beta

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Affected organization
Texasbar logo
Texasbar

Sector: Finance and Insurance

Likely country: Location not provided

Estimated
Threat source
Malware, Hacking activity

Watch ransomware, endpoint compromise and business interruption exposure.

  • Source type: outside the affected organization
Business impact
Potential operational disruption

Impact area: Confidentiality, Availability

Likely asset: User or customer data

Trend context
91 signals with similar action pattern
  • 23 signals in the same sector
  • 100 signals with the same likely impact area
  • 1 signal linked to this organization/domain
Mentioned entities
TexasbarData DisclosureState Bar of TexasINCThe State Bar of TexasThe INCIDsUnauthorized

External sources

Related signals

Grouped by why the signal is relevant.

ahisd.net logoAhisdJun 26, 2026
Same sectorSame action patternSame impact area

Alamo Heights ISD Reports Data Breach Following Ransomware Attack

Alamo Heights Independent School District (ISD) reported a data breach impacting over 26,000 people, disclosed to the Texas Attorney General's office on June 25, 2026 (published June 26, 2026 UTC). The breach was linked to a ransomware attack by the Qilin group, which occurred on April 9, 2026. The compromised information included names, Social Security numbers, driver's license numbers, and bank and medical information.

ayabank.com logoAyabankJun 23, 2026
Same sectorSame action patternSame impact area

AYA BANK Hit by Lapsus$ Ransomware Attack

AYA BANK, a prominent financial institution in Myanmar, fell victim to a ransomware attack by the Lapsus$ group, discovered on June 23, 2026. Lapsus$ claimed to have stolen over 120 gigabytes of data, including a full dump and PII, and threatened to sell it if a ransom was not paid. AYA Bank acknowledged a breach of an older application portal exposing some customer information but stated its core financial networks remained secure.

legendsmn.com logoLegendsmnJun 19, 2026
Same sectorSame action patternSame impact area

Legendary Home Services Breached by NightSpire Ransomware

On June 19, 2026, US home services company Legendary Home Services (operating as legendsmn.com) was listed as a victim by the NightSpire ransomware group. The breach was publicly identified on ransomware-tracking platforms. Initial reports indicate a ransomware attack, but the exact number of affected individuals and specific categories of data compromised (such as names, addresses, phone numbers, email addresses, or payment information) remain unknown.

aflac.com logoAflacJun 30, 2026
Same sectorSame action patternSame impact area

Aflac Life Insurance Japan Suffers Cybersecurity Breach Exposing Policyholder Data

Aflac Life Insurance Japan disclosed unauthorized access to its systems between June 15 and June 25, 2026. The breach affected files containing policy details, personal information, and bank account information of approximately 4.38 million customers. The company has suspended affected systems and is investigating the incident with third-party cybersecurity experts.

naic.org logoNaicJun 29, 2026
Same sectorSame action patternSame impact area

National Association of Insurance Commissioners (NAIC) Confirms Data Breach via Oracle PeopleSoft Zero-Day

The National Association of Insurance Commissioners (NAIC), a US insurance regulatory standards body, confirmed a cyberattack after the ShinyHunters group claimed theft of 3.1TB of data. The breach was reportedly achieved through an Oracle PeopleSoft zero-day vulnerability. ShinyHunters claimed access to regulatory filings, production logs, cloud configuration files, and other internal records.

insee.fr logoInseeJun 26, 2026
Same sectorSame action patternSame impact area

France's National Statistics Department (Insee) Reports Cyberattack on Staff Data

France's national statistics department, Insee, reported a cyberattack that exposed identity and professional contact data for approximately 12,800 current and former staff and related civil service personnel. The breach, detected on June 19, 2026, involved an internal staff directory (trombi.insee.fr). Insee stated that no sensitive information such as passwords, personal contact details, bank details, social security numbers, or health information was accessed. News of the incident was widely reported on June 26, 2026.