A phishing attack on Nacogdoches County, Texas, affected a limited number of county systems and disrupted online pay-stub access, county officials said.
A cybersecurity notice from the county said officials identified and responded to the incident in late May. It said the incident was contained and remediated, and that emergency services were not interrupted.
Chris Bentley, the Nacogdoches County judge, told The Daily Sentinel that the May 28 incident was caused by phishing. The notice did not describe the attack type, saying the investigation remains ongoing and the county could not discuss technical or investigative details.
The notice said no residents were involved and no current county employees were affected as current employees. It said the impacted group was limited to former sheriff’s office employees, including some current county employees who previously worked there.
The county said those employees would receive direct notice and free credit monitoring.
Nacogdoches County, in eastern Texas, provides local government, law enforcement, court and public records services for more than 66,000 residents.
Bentley told The Daily Sentinel that sheriff’s office operations, county finances and county services were not affected.
But the county’s description also shows disruption in normal administrative systems. Bentley told the newspaper that employees were receiving paper pay stubs because online pay-stub access was unavailable.
“Nothing has affected pay at all,” Bentley told the newspaper. “What’s happened with pay is we are doing paper pay stubs.”
In its cybersecurity incident notice, the county listed the website transition among steps taken after the incident, saying officials moved forward with a previously planned transition and launched nacogdochesco.gov. The Daily Sentinel reported that the incident accelerated the move from the county’s former website, www.co.nacogdoches.tx.us, to the new .gov site.
The move put the county on a .gov domain, which the federal registrar says is available only to verified U.S.-based government organizations.
The sheriff’s office previously used a separate website, nac-sheriff.com, but its information is now being moved to nacogdochesco.gov. In a June 10 post, the office said its page on the new county website was still being built and that residents checking the daily jail roster would have to rely on booking summaries and daily activity reports until the page was completed.
The new county site says the county is “moving to a new website” and links users to sheriff’s daily reports, election results and a public information request form. It now shows static sheriff’s office reports, including booking summaries, daily activity logs and an inmate list, posted as individual links.
The notice did not say whether data was accessed or taken. It also did not say whether the attack directly affected the payroll system, public website or sheriff’s office online systems.
DysruptionHub emailed Bentley seeking clarification on whether the phishing attack directly affected payroll, website or sheriff’s office systems and which systems were taken offline or rebuilt. Mark Harkness, a county commissioner and judge pro tem, responded that the county could not provide additional information beyond its press release.
Bentley told The Daily Sentinel the attack has elevated information technology upgrades as commissioners enter budget discussions this summer. He said officials may explore grants or remaining federal pandemic relief funds to pay for technology improvements.
The Nacogdoches County incident resembles other 2025 Texas county cyberattacks in which officials reported administrative disruptions but said public safety operations continued.
Matagorda County declared a disaster in January after a breach affected internal systems, disrupted some operations and forced residents to use drop boxes or mailed checks for tax payments.
Kaufman County officials said an October security incident disrupted courthouse computer systems and employee files, while the sheriff’s department and emergency services continued operating normally.
No hacking group has publicly claimed responsibility for the county attack in public ransomware leak-site postings reviewed by DysruptionHub. The county has not reported a ransom demand.