Texas State Bar Hit by Major Data Breach: The Verdict Is In
Texas State Bar Overruled by Ransomware Gang – Counsel for Your Cybersecurity
INC Ransom breached the second-largest bar association in the country and walked out with case documents and financial records. If it can happen to them, it can happen to any Houston firm holding client data.
The Texas State Bar data breach is not a story about a giant target getting unlucky. It is a story about how a single intrusion at a professional legal body puts the personal data of attorneys, staff, and their clients on a dark web extortion page within weeks.
The State Bar of Texas is the second-largest bar association in the United States, with more than 100,000 licensed attorneys. Between January 28 and February 9, 2025, attackers were inside its network exfiltrating data. The Bar did not discover the intrusion until February 12. CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, and we read breaches like this one so a Houston firm can act on the lesson instead of becoming the next headline.
The Breach Ran for 12 Days Before Anyone Noticed
A short intrusion window, a long list of stolen data types.
The State Bar of Texas notified roughly 2,700 people that their data was taken in a breach that ran from January 28 to February 9, 2025, and was discovered on February 12. Notifications also went to a small number of out-of-state victims, including two in New Hampshire and eight in Massachusetts.
The stolen data set is the kind that fuels identity theft for years. According to reporting by Comparitech, the compromised information included names, Social Security numbers, financial account details such as account and card numbers, driver's licenses and other government-issued IDs, medical information, and health insurance information. INC Ransom also leaked samples of what appear to be legal case documents, which is the part that should worry any firm holding privileged material.
- The dwell time was the real problem. Attackers had roughly 12 days inside the network before detection, and detection came 3 days after they stopped. That window is where the damage happens.
- The Bar has not confirmed the ransom outcome. The State Bar has not verified INC Ransom's claim, and the exact entry point and whether any ransom was paid remain undisclosed.
- Victims got Experian monitoring. The Bar offered free credit and identity-theft monitoring through Experian, with an enrollment deadline of July 31, 2025, plus advice to consider credit freezes and fraud alerts.
INC Ransom Is a Ransomware Crew That Steals First and Encrypts Second
The group behind the attack, by the numbers.
INC Ransom is a ransomware gang that surfaced in July 2023 and hits healthcare, education, government, and legal targets. It runs double extortion: steal the data, threaten to publish it, then demand payment whether or not it also encrypts systems.
The group's usual way in is spear phishing and exploiting known, unpatched vulnerabilities in edge software. Security researchers have tied INC Ransom activity to internet-facing weaknesses in products like Citrix, Fortinet, and remote-management tools. It listed the State Bar of Texas on its dark web extortion page in early 2025 and posted sample files to pressure a payment. For a small firm, the takeaway is direct: the entry points INC Ransom favors are the same ones a Houston business leaves exposed when patching slips and multi-factor authentication is optional.
Law Firms Were the Standout Target in 2025, Not an Afterthought
The State Bar breach sits inside a broader run at the legal sector.
The legal sector drew unusual attacker attention in 2025. INC Ransom and the Silent Ransom Group both ran focused campaigns against law firms, and the FBI issued a warning to US-based firms about a group stealing legal data. Threat-intelligence firm Halcyon tracked more than 200 ransomware incidents against law firms from 2025 into early 2026.
Attackers target legal organizations for three plain reasons: the data is unusually sensitive, deadlines and privilege create pressure to resolve incidents fast, and there is a perception that firms will pay to protect attorney-client material. A Houston CPA practice or law firm does not need to be famous to fit that profile. It needs to hold client Social Security numbers, financial records, and case files, which nearly every firm does. In 35 years doing this, the firms that got hit were rarely the biggest names in town. They were the ones that assumed size was a shield.
- Privilege raises the stakes. Leaked case documents are not just a compliance problem. They can compromise active matters and client relationships in ways a stolen spreadsheet never would.
- Small firms feel the same blast radius. A downstream vendor or co-counsel to a larger enterprise becomes a target because it is the softer path to the same valuable data.
- Regulators are watching. Texas breach-notification duties and industry rules mean the cleanup cost lands on top of the breach itself, and small firms carry that weight without an enterprise legal team.
Everyone reads a breach like this and thinks it is about the big organization that got hit. It is not. It is about every 20-person firm downstream that holds the same Social Security numbers and case files with none of the defenses. Size did not save the State Bar, and it will not save a small firm either. Governance and monitoring do.
Close the Gap the State Bar Breach Exposed
CinchOps gives Houston-area law firms and professional practices the patching, monitoring, and phishing-resistant defenses that stop the exact entry points INC Ransom uses - at SMB scale. It is the core of our cybersecurity and managed IT services.
Explore CinchOps cybersecurity →How CinchOps Protects Houston Law Firms From the Next INC Ransom
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, focused on the patching, detection, and response capability the Texas State Bar breach shows most organizations still miss.
CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. The breach came down to a familiar chain: an exposed entry point, days of undetected access, and sensitive data walking out the door. That chain is exactly what a managed partner is built to break:
- Close the entry points INC Ransom favors. Fast patching of edge software and mandatory multi-factor authentication remove the spear-phishing and unpatched-vulnerability paths this group relies on.
- Cut the dwell time. Monitoring and detection shrink the window between intrusion and discovery, so a 12-day free run does not happen on your network.
- Train the human layer. Security awareness training aimed at the phishing lures that start most breaches, backed by tested reporting habits.
- Plan for the bad day. Encrypted, tested backups and an incident response plan mean a breach becomes a recovery, not a shutdown.
The Texas State Bar had far more resources than the typical Houston firm and still lost sensitive client data. If you run a law firm, a CPA practice, or any business in Houston or Katy that holds client Social Security numbers and case files, do not wait for a notification letter to find out where you stand. Talk to CinchOps and we will tell you straight.
Frequently Asked Questions
What was the Texas State Bar data breach?
The State Bar of Texas, the second-largest bar association in the United States, confirmed a data breach that ran from January 28 to February 9, 2025, and was discovered on February 12. Attackers exfiltrated sensitive personal data, and the INC Ransom gang later claimed responsibility and leaked sample files including legal case documents.
How many people were affected by the State Bar of Texas breach?
The State Bar of Texas notified roughly 2,700 people, per reporting by Comparitech, including a small number outside Texas such as two in New Hampshire and eight in Massachusetts. The exact total tied to INC Ransom's dark web listing was not confirmed by the Bar, which has more than 100,000 attorney members.
What data was stolen in the Texas State Bar breach?
The compromised data included names, Social Security numbers, financial account details such as account and card numbers, driver's licenses and other government-issued IDs, medical information, and health insurance information. INC Ransom also leaked samples of what appear to be legal case documents, raising privilege and confidentiality concerns for affected matters.
Who is the INC Ransom group?
INC Ransom is a ransomware gang that emerged in July 2023 and targets healthcare, education, government, and legal organizations. It typically gains access through spear phishing and unpatched, internet-facing vulnerabilities, then runs double extortion by stealing data and threatening to publish it unless a ransom is paid.
What should a Houston law firm do after a breach like this?
Focus on the chain that failed: patch internet-facing software fast, require multi-factor authentication, monitor for intrusions to cut dwell time, train staff on phishing, and keep tested backups with an incident response plan. A managed IT provider can deliver all of it at small-firm scale, which is how a Houston practice reaches enterprise-grade defense without the enterprise budget.
Discover More
Sources
- Comparitech, Texas State Bar data breach leaks SSNs and financial info; ransomware gang claims responsibility
- BleepingComputer, Texas State Bar warns of data breach after INC ransomware claims attack
- SecurityWeek, State Bar of Texas Says Personal Information Stolen in Ransomware Attack
- Halcyon, INC Ransom Group Mounts Rapid Campaign Against Law Firms