AUSTIN, Texas — More than 3 million Texas hunting and fishing license customers may have had personal information exposed in a cybersecurity incident involving a Texas Parks and Wildlife Department license system vendor.

According to Texas Parks and Wildlife, Texas Cyber Command recently detected the incident involving the vendor that handles hunting and fishing license sales.

The agency said an unauthorized actor may have obtained driver’s license information, passport numbers, email addresses, phone numbers, and residential addresses belonging to customers. Officials said Social Security numbers, dates of birth, and financial information, including credit card details, were not obtained.

For frequent fisherman Austin Anderson, the news was unsettling.

“It just gets me outdoors. I love being outside,” Anderson said.

He spends time fishing several times a week and said he was surprised to learn a license purchase could be connected to a cybersecurity incident.

“A little bit of outrage,” Anderson said.

Texas Parks and Wildlife said there is no evidence that customers under the age of 18 were involved or that any specific group was targeted. The agency said it has implemented additional security measures and is working with the vendor to strengthen safeguards and monitoring services.

The breach has also raised questions about the amount of personal information collected during the licensing process.

When asked whether all of that information is necessary when renewing a license, Anderson said:

“I don’t think they need quite as much as they take. I mean, they already take a driver’s license number, and that should be enough for me. I don’t think they need a social.”

ALSO | Education advocates split as state board nears vote on new social studies standards

Michael Lebowitz, a former senior attorney with Army Cyber Command, said incidents involving state entities are not uncommon.

“Unfortunately, state agencies are always a frequent target of these organized crime groups,” Lebowitz said.

He recommends that affected Texans review their credit reports and remain alert for suspicious communications, such as spam emails or phone calls, that could follow a breach.

“These are very sophisticated spam calls now, you know, they use AI to mimic things that make them sound legitimate,” Lebowitz said.

CBS Austin asked Texas Parks and Wildlife several questions, including when the breach occurred, whether customer information was confirmed to have been obtained, and what specific security measures have been added since the incident.

In response, the agency reiterated that more than 3 million customers may have been affected and that additional safeguards have been implemented. The department did not directly answer those questions.

Despite his concerns, Anderson said he still supports the agency.

“I just hate to see this happen to them because I really have a lot of trust in that agency,” he said.

When asked what he believes Texas Parks and Wildlife should do moving forward, Anderson suggested the agency should do more for affected customers.

“Maybe repay a little bit of our fishing license. We have to keep them up, and they’re not doing their part in keeping our data safe,” Anderson said.

Texas Parks and Wildlife said affected customers are eligible to receive one year of free credit monitoring through Kroll. Customers can confirm their eligibility by calling the dedicated assistance line at (844) 959-7123.

The enrollment deadline for free credit monitoring is Sept. 14, 2026.

The agency also encourages customers to monitor their credit reports and financial statements, consider freezing their credit with the major credit bureaus, and remain cautious of emails, phone calls, or messages that request personal information.

Texas Parks and Wildlife said license sales will continue on schedule for August and the next license year and that it believes current and future customer data are not at risk.