Nacogdoches County phishing disrupts payroll access
Summary
Nacogdoches County, Texas, identified a phishing-related cybersecurity incident on May 28, 2026. Online pay-stub access was still unavailable and paper stubs were in use on July 1, while payroll payments and other county services continued. A Texas AG listing later reported 1,100 affected Texans.
Key facts
Timeline
-
Incident start:
?
Earliest known or assessed start of malicious activity or incident activity. -
First public signal:
?
Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity. -
First public cyber evidence:
?
Earliest credible public information connecting the incident or disruption to malicious cyber activity. -
Official cyber disclosure:
?
First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related. -
Last impact seen:
?
Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
Primary victim organization
Impacted locations
Organization types
Critical infrastructure sector
DysruptionHub coverage
Incident characteristics
Assessments
- Status:
- Presumed Active
- Incident confidence:
- High
- Ransomware:
- Unresolved
DD-CIT classification
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Attack mechanisms
-
Phishing
The use of deceptive messages or websites to trick people into revealing information, transferring funds or executing malicious content.
Data impacts
-
Unauthorized data access
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
-
Data unavailable
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
Operational impacts
-
Online portal unavailable
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
-
Application unavailable
A specific application or software platform became unavailable or unusable.
-
Records access disruption
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
-
Manual workaround required
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
-
Staff unable to work normally
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
Extortion indicators
-
No known extortion indicator
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
Incident narrative
Analyst assessment
DysruptionHub assesses with high confidence that Nacogdoches County, Texas, experienced a cyber incident identified on May 28, 2026. County Judge Chris Bentley attributed the event to phishing, while the county’s official notice said a limited number of county systems were affected and the incident had been contained and remediated.
DysruptionHub’s published report documented the phishing attribution and the operational effects described by county officials. The public record does not establish whether phishing led to credential compromise, mailbox access, malware execution or another specific follow-on mechanism, so the attack remains characterized as phishing without inferring a more precise technical path.
Operational significance
The incident disrupted online access to employee pay stubs. County officials said employees were receiving paper pay stubs because online access was unavailable, creating a manual administrative workaround. Payroll payments themselves continued, and officials said county finances, sheriff’s office operations, emergency services and general county services were not affected.
The county also accelerated a previously planned transition from its former website to a new .gov domain. Sheriff information was still being migrated, and residents seeking jail-roster information were directed to booking summaries and daily activity reports while new pages were built. The public record does not establish that every website limitation resulted directly from the incident.
Data impact and disclosure
The county initially said no residents were affected and described the affected population as a limited number of former sheriff’s office employees, including some current county employees whose exposure related to prior sheriff’s office service. It offered direct notice and free credit monitoring.
A later Texas Attorney General breach listing, published July 7, reported 1,100 affected Texans and listed names, addresses, Social Security numbers, driver’s-license numbers, medical information and another unspecified data type as affected. The listing confirms a substantially larger affected-person count than the initial public description suggests, but the available record does not reconcile that difference or establish that data was copied, removed or publicly disclosed.
In a July 9 KTRE interview, Bentley said the breach affected a select few county employees, involved a limited amount of data and prompted an ongoing investigation, infrastructure review and accelerated website replacement. That account reinforces the county’s limited-scope characterization but does not resolve the affected-count discrepancy in the AG filing.
Current status
The county said the cyber incident was contained and remediated, but that statement is not a documented restoration of the affected pay-stub service. The latest confirmed operational observation, reported July 1, was that online pay-stub access remained unavailable and paper pay stubs were still being used. No later source located by July 26 confirmed that access was restored or the workaround ended. With 25 days since that observation, the incident is presumed active under the operational-impact lifecycle; this status reflects the absence of a documented all-clear rather than evidence of a renewed or broadening outage.
Confidence and uncertainty
Confidence is high that phishing was involved, that online pay-stub access was disrupted and that the incident affected personal information. The public record does not establish financial loss, missed payroll, interruption to emergency services or a broad county-system outage. Ransomware and threat-actor attribution remain unresolved: no encryption, ransom demand, extortion activity, payment or actor claim was identified.
Analytic gaps
The reviewed sources do not identify the phishing lure, targeted account, credential or session compromise, affected systems, exact duration of pay-stub unavailability, or whether affected data was copied or removed. They also do not reconcile the county’s description of a limited number of affected former sheriff’s office employees with the Texas AG’s report of 1,100 affected Texans.
Organizations involved
Nacogdoches County, Texas

Organization type
Critical infrastructure
Impacted locations
Sources
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
County officials attributed the May 28 incident to phishing and said limited systems were affected. As reported July 1, online pay-stub access was unavailable and employees were receiving paper pay stubs, while payroll payments, emergency services, county finances and other county services continued.
- Type: Official Statement
- Stance: Confirm
- Platform: Website
- Medium: Document
- Confidence: High
Nacogdoches County said a late-May cybersecurity incident affected a limited number of systems, was contained and remediated, did not interrupt emergency services, and affected a limited number of former sheriff’s office employees who were offered credit monitoring.
- Type: Public Record
- Stance: Confirm
- Platform: Website
- Medium: Web Page
- Confidence: High
The Texas Attorney General listing for Nacogdoches County reported 1,100 affected Texans and identified names, addresses, Social Security numbers, driver’s-license numbers, medical information and another unspecified data type as affected. Consumer notice was provided through a website, and the entry was published July 7, 2026.
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
County Judge Chris Bentley said the investigation remained ongoing, described the breach as affecting a select few county employees and a limited amount of data, and said the county accelerated its new website and reviewed infrastructure upgrades. The report did not confirm restoration of online pay-stub access.