Skip to content

Nacogdoches County phishing disrupts payroll access

Summary

Nacogdoches County, Texas logo

Nacogdoches County identified a phishing-related cybersecurity incident on May 28, 2026. Online pay-stub access was unavailable and paper stubs were in use July 1 while payroll and other county services continued; no newer operational-impact evidence was found by August 3, so the disruption is presumed resolved. A Texas AG listing reported 1,100 affected Texans.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Phishing

    The use of deceptive messages or websites to trick people into revealing information, transferring funds or executing malicious content.

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Application unavailable

    A specific application or software platform became unavailable or unusable.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Nacogdoches County, Texas, experienced a cyber incident identified on May 28, 2026. County Judge Chris Bentley attributed the event to phishing, while the county’s official notice said a limited number of county systems were affected and the incident had been contained and remediated.

DysruptionHub’s published report documented the phishing attribution and the operational effects described by county officials. The public record does not establish whether phishing led to credential compromise, mailbox access, malware execution or another follow-on mechanism.

Operational significance

The incident disrupted online access to employee pay stubs. County officials said employees were receiving paper pay stubs because online access was unavailable, creating a manual administrative workaround. Payroll payments continued, and officials said county finances, sheriff’s office operations, emergency services and general county services were not affected.

The county also accelerated a previously planned transition from its former website to a new .gov domain. Sheriff information was still being migrated, and residents seeking jail-roster information were directed to booking summaries and daily activity reports while new pages were built. The public record does not establish that every website limitation resulted directly from the cyber incident.

Disclosure posture

The county initially said no residents were affected and described the affected population as a limited number of former sheriff’s office employees, including some current county employees whose exposure related to prior sheriff’s office service. It offered direct notice and free credit monitoring.

A Texas Attorney General breach listing, published July 7, reported 1,100 affected Texans and listed names, addresses, Social Security numbers, driver’s-license numbers, medical information and another unspecified data type as affected. The listing establishes a substantially larger affected-person count than the county’s initial description suggests, but the available record does not reconcile that difference or establish that data was copied, removed or publicly disclosed.

In a July 9 KTRE interview, Bentley said the breach affected a select few county employees, involved a limited amount of data and prompted an ongoing investigation, infrastructure review and accelerated website replacement. That account reinforces the county’s limited-scope characterization but does not resolve the discrepancy with the Attorney General filing.

Current status

The latest confirmed operational observation was July 1, when online pay-stub access remained unavailable and paper stubs were still being used. Searches through August 3 found no later evidence that the disruption or workaround continued and no service-specific restoration notice. The operational impact is therefore presumed resolved after 33 days without a newer observation; this is a time-based lifecycle assessment, not an authoritative all-clear or a known restoration date.

Confidence and uncertainty

Confidence is high that phishing was involved, that online pay-stub access was disrupted and that the incident affected personal information. The public record does not establish financial loss, missed payroll, interruption to emergency services or a broad county-system outage. Ransomware and threat-actor attribution remain unresolved: no encryption, ransom demand, extortion activity, payment or actor claim was identified.

Analytic gaps

The reviewed sources do not identify the phishing lure, targeted account, credential or session compromise, affected systems, exact duration of pay-stub unavailability, restoration method, or whether affected data was copied or removed. They also do not reconcile the county’s description of a limited number of affected former sheriff’s office employees with the Texas Attorney General’s report of 1,100 affected Texans.

Organizations involved

Impacted locations

Sources

Nacogdoches County phishing attack disrupts payroll access

County officials attributed the May 28 incident to phishing and said limited systems were affected. As reported July 1, online pay-stub access was unavailable and employees were receiving paper pay stubs, while payroll payments, emergency services, county finances and other county services continued.

Notice of Cybersecurity Incident

Nacogdoches County said a late-May cybersecurity incident affected a limited number of systems, was contained and remediated, did not interrupt emergency services, and affected a limited number of former sheriff’s office employees who were offered credit monitoring.

Data Security Breach Reports

The Texas Attorney General listing for Nacogdoches County reported 1,100 affected Texans and identified names, addresses, Social Security numbers, driver’s-license numbers, medical information and another unspecified data type as affected. Consumer notice was provided through a website, and the entry was published July 7, 2026.

Nacogdoches County judge details response to cyber attack, push for upgraded systems

County Judge Chris Bentley said the investigation remained ongoing, described the breach as affecting a select few county employees and a limited amount of data, and said the county accelerated its new website and reviewed infrastructure upgrades. The report did not confirm restoration of online pay-stub access.

See something that needs correction?

Signed-in members can report an error, update, or missing source.