Texas Department of Transportation Suffers Major Data Breach: 300,000 Crash Records Compromised
TxDOT Reports Data Breach Affecting Crash Record Database – 300,000 Texas Drivers Affected
A single compromised account pulled hundreds of thousands of crash reports out of TxDOT's system. Here is what was taken, who is exposed across Houston and Katy, and the steps to take this week.
The TxDOT data breach is not a story about a firewall failing. It is a story about one stolen login walking straight into a state database and copying around 300,000 crash reports before anyone noticed.
The Texas Department of Transportation found the breach on May 12, 2025, and disclosed it in early June. An attacker used a compromised account to reach the Crash Records Information System, called CRIS, and downloaded roughly 300,000 crash reports. In its own notice to the Texas Attorney General, TxDOT put the number of affected people at 423,391. CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, and we are writing this for the Houston driver, law firm, or CPA practice trying to figure out what a state agency's breach has to do with them.
What Happened in the TxDOT Data Breach
A compromised account, not a broken firewall, opened the door to the crash database.
The TxDOT data breach happened when an attacker logged in with a legitimate account's stolen credentials and downloaded around 300,000 crash reports from the Crash Records Information System. TxDOT flagged the unusual activity on May 12, 2025, disabled the account, and opened an investigation.
This is a credential-compromise breach, and that detail matters more than the headline number. The attacker did not smash through a wall. They walked in the front door with a working key. To a lot of monitoring tools, a valid login pulling records looks like an employee doing their job, which is why the bulk download ran before it tripped an alarm. TxDOT has said notification was not required by law here, yet it chose to mail letters to affected people and stood up an assistance line at 1-833-918-5951. That is the honest version of a bad situation.
- The entry point was an account, not a zero-day. Stolen or reused credentials remain the most common way large data sets get pulled out of government and business systems alike.
- The data spans years of wrecks. CRIS holds crash reports over multiple periods, so the exposed set is not limited to recent collisions.
- The two numbers are both real. Around 300,000 is the count of downloaded reports; 423,391 is the count of people TxDOT reported to the Texas Attorney General, since one report can name several people.
Who Is at Risk From the Stolen Crash Records
The exposed fields are the raw material for identity theft and insurance fraud.
Anyone named in a Texas crash report held by TxDOT could be exposed. The records may include full name, mailing or physical address, driver license number, license plate number, car insurance policy number, and crash or injury details - the exact set criminals use for identity theft and insurance fraud.
Driver license numbers and insurance policy numbers are worth more to a fraudster than a leaked email address, because they open doors an email cannot. With a license number and an address, someone can attempt to open accounts, file fraudulent claims, or pass a knowledge-based identity check. The nastier near-term risk is targeted phishing. A scammer who already knows your name, your address, and the fact that you filed a claim can call or email pretending to be your insurer or a settlement service, and it will not feel like a scam. In 35 years doing this, the breaches that hurt people most are rarely the ones with the biggest number - they are the ones where the stolen data lets the follow-up scam sound legitimate.
There is a business angle too. If an employee at a law firm, construction company, or CPA practice in Houston is in this data set, the personal details can be used to social-engineer that person at work - a convincing pretext to reset a password, approve a payment, or hand over access. We see that pattern often enough that personal breaches and business risk are never fully separate.
The Same Attack That Hit TxDOT Targets Small Businesses Daily
A stolen login is the number-one way data walks out of a network, and small firms get hit far more often than a state agency. CinchOps closes that gap with multi-factor authentication, privileged access controls, and monitoring that flags a valid account behaving strangely - the core of our cybersecurity and managed IT services.
Explore CinchOps cybersecurity →What Texas Drivers and Businesses Should Do Now
A short list of moves that actually reduce the fallout from this breach.
If you have been in a reported Texas wreck, act as though your data is in this set: freeze your credit, watch for insurer-themed phishing, and verify any payment or claim contact through a number you look up yourself, not one the caller gives you.
Most of the advice floating around after a breach is vague. Here is the version worth your time, for a Houston or Katy driver first, then for the business owner reading over their shoulder.
- Place a credit freeze at all three bureaus. It is free, it blocks new accounts in your name, and it is the single highest-value step. Thaw it temporarily when you actually need credit.
- Treat insurer and settlement calls as suspect. Hang up and call the number on your insurance card or policy. A real adjuster will not mind; a scammer will push back.
- Watch for claim-related phishing by email and text. The exposed data makes lures specific, so a message referencing your accident is not proof it is real.
- Use the TxDOT assistance line if you were notified. TxDOT set up 1-833-918-5951 and mailed letters to affected people; keep that letter.
- For business owners: turn on MFA and check who can pull bulk data. The lesson of this breach is that one account should never be able to quietly export a whole database.
For a company, the TxDOT breach is a free tabletop exercise. Ask one question: if an attacker logged in as your most trusted employee tomorrow, what could they copy before anyone noticed? If you cannot answer that quickly, that is the gap to close. Phishing-resistant training and payment-verification habits stop most of the follow-on fraud, and both are covered in our guide on preventing phishing attacks for Texas SMBs.
Everyone fixates on the 300,000 number. The scary part is the one before it: a single account. If one stolen login can copy a database, the problem was never the size of the breach - it was that no one was watching a trusted account act untrustworthy. That is fixable at any size, and it is exactly what a small Houston business should take from this.
How CinchOps Helps Houston Businesses Avoid the Next One
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, focused on the exact failure that caused the TxDOT breach: a trusted account doing untrusted things.
CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. A credential-compromise breach is not a fancy attack, which is the good news - the defenses that stop it are practical and within reach for a small firm:
- Multi-factor authentication and access limits. A stolen password alone should not be enough to log in, and no single account should be able to export everything.
- Monitoring that watches behavior, not just logins. A valid account suddenly pulling thousands of records is the alert that would have caught this early.
- Phishing-resistant training. Most stolen credentials start with a convincing lure, so we train people to spot the pretext this breach makes easy.
- Incident response you have rehearsed. Knowing who does what in the first hour is the difference between a contained event and a headline.
The TxDOT breach will fade from the news, but the method behind it is the one hitting Houston small businesses every week. If you run a business in Houston or Katy and are not sure whether one stolen login could empty your systems, talk to CinchOps and we will show you where you stand.
Frequently Asked Questions
What is the TxDOT data breach?
The TxDOT data breach is an incident the Texas Department of Transportation found on May 12, 2025, in which an attacker used a compromised account to download around 300,000 crash reports from its Crash Records Information System. In its notice to the Texas Attorney General, TxDOT reported 423,391 people were affected.
What information was exposed in the TxDOT breach?
The stolen crash records may include full name, mailing or physical address, driver license number, license plate number, car insurance policy number, and crash or injury details. That combination is valuable for identity theft, insurance fraud, and targeted phishing, which is why affected Texans should treat follow-up contact with caution.
How did the TxDOT data breach happen?
An attacker used a compromised account, meaning stolen or misused login credentials, to reach the Crash Records Information System and download reports. It was not a software zero-day. Because the login was valid, the activity looked legitimate to monitoring tools until the unusual bulk download was flagged on May 12, 2025.
Was I affected, and how will I know?
If you were named in a Texas crash report held by TxDOT, you may be in the exposed set. TxDOT is mailing letters to affected people even though notification was not legally required, and it set up an assistance line at 1-833-918-5951. Keep any letter you receive and call that line with questions.
How can a Houston business avoid a breach like this?
The TxDOT breach came from one stolen login, so the fixes are practical: require multi-factor authentication, limit which accounts can export bulk data, monitor for a valid account behaving strangely, and train staff against phishing. A managed IT provider can put all of that in place at small-business scale in Houston and Katy.
Discover More
Sources
- TxDOT Newsroom, Account compromise leads to crash records data breach
- SecurityWeek, Hackers Stole 300,000 Crash Reports From Texas Department of Transportation
- BleepingComputer, Texas Dept. of Transportation breached, 300k crash records stolen
- KVUE, Hundreds of thousands of TxDOT crash records breached after account compromise