State Bar of Texas confirmed data theft after an attack claimed by INC Ransom

Organization
State Bar of Texas
Exploit
Ransomware
Industry
Legal Services

The State Bar of Texas began notifying people in early April 2025 that a network intrusion earlier in the year had led to the theft of personal information. The organisation said an unauthorised actor had access to its network between 28 January and 9 February 2025, and that the intrusion was discovered on 12 February.

Notification letters and state filings identified the exposed data as names, Social Security numbers, driver's licence and other government issued identification numbers, financial account and payment card numbers, medical information and health insurance details. The Bar did not publish a total figure for those affected. Comparitech, reviewing state filings, counted about 2,700 notifications to Texas residents plus a small number elsewhere, including eight in Massachusetts and two in New Hampshire.

The INC Ransom group claimed the attack and posted samples of the stolen files, including legal case documents. Reports differ on when: Comparitech put the leak site listing at 27 February 2025, while teiss and other outlets dated it to 9 March. The Bar did not confirm the group's claims, describe how the intruder got in, or say whether a ransom was demanded or paid.

Recipients were offered complimentary credit and identity theft monitoring through Experian, with enrolment open until 31 July 2025. The State Bar of Texas licenses more than 100,000 attorneys and is the second largest bar association in the United States.

Sources