The personal information of more than 3 million Texas hunting and fishing license holders was exposed in a massive data breach, potentially leaving millions vulnerable to scams, fraud and identity theft.

According to an announcement from the Texas Parks and Wildlife Department, the Texas Cyber Command detected a cybersecurity incident involving a third-party license system vendor that “handles the sale of hunting and fishing licenses.”

The investigation indicates that an “unauthorized actor” may have gained access to sensitive information belonging to more than 3 million licensed Texas hunters and anglers, including passport numbers, email addresses, phone numbers and residential addresses.

Department officials said Social Security numbers, dates of birth and financial information — including credit card numbers — were not compromised. They also said there is no evidence that the information of anyone younger than 18 was exposed or that any specific group was targeted in the breach.

“We recognize the seriousness of this issue and have identified and implemented additional security options to better protect customer information. Many of our staff are hunters and anglers and were affected by this incident,” TPWD representatives wrote. “We are committed to continuing to work with the license system vendor to implement increased safeguards to prevent future incidents.”

The department said it is working closely with its licensing system vendor to implement additional safeguards, enhanced monitoring services and other security improvements.

Officials said the breach has not disrupted operations, noting that license sales will continue as scheduled in August for the upcoming license year.

If you believe you may have been affected by this data breach, you may be eligible to receive a free year of credit monitoring through Kroll. To confirm your eligibility and enroll, call (844) 959-7123 by the Sept. 14, 2026 deadline. 

As an added precaution, the department recommends closely monitoring financial accounts for suspicious activity, freezing or monitoring credit reports, and avoiding unsolicited links or requests for personal information unless they can be verified as legitimate.