Texas Parks and Wildlife Told Me My Data Was Stolen. The Response Was the Same One Everyone Gets. | v64otd.com

Texas Parks and Wildlife Told Me My Data Was Stolen. The Response Was the Same One Everyone Gets.

Add v64otd.com to your daily reading list — the ledger doesn't lie.

This isn't a new argument for me. It's one that's been sitting under my collar for a while, and this year it got personal.

I got a letter from Texas Parks and Wildlife telling me my personal information had been exposed in a breach of their license vendor's systems. It's a small state agency doing a mundane thing — selling hunting and fishing licenses — handing my data to a vendor it apparently didn't vet closely enough, and finding out the same way I did: after the fact. The letter offered the standard response. Some free monitoring, an apology, move along.

corporatocracy (noun) — a system where the same institutions trusted with your most sensitive information treat protecting it as a discretionary expense and monetizing it as a core competency, and where the penalty for getting either one wrong is smaller than the cost of doing it right.

curated control (noun) — a system in which you're shown a consent checkbox, a privacy policy, or an opt-out link and told that's where your control over your information begins and ends, while the actual decisions about where your data goes happen upstream — inside a vendor contract, an embedded software kit, or a data broker's resale agreement — in places you were never shown and never asked about at all.

It doesn't make it right. It never did. Here's why.

What Happened at TPWD

The Texas Parks and Wildlife Department disclosed on June 18, 2026, that a third-party vendor managing its hunting and fishing license system had been breached, exposing driver's license numbers, passport numbers, emails, phone numbers, and home addresses for more than 3.1 million license holders. TPWD still hasn't publicly named the vendor. Social Security numbers and financial data weren't part of this one, which is the only reason it's on the less severe end of what's out there. It's still a state agency that handed citizen data to a vendor it didn't adequately vet, and found out the same way everyone else did: after the criminals already had it.

It's Not Just Government

A health IT vendor, Unlimited Technology Systems, detected unauthorized activity in its data center on October 19, 2025. The investigation found that an unauthorized party had accessed files between October 5 and October 10, 2025 — meaning the company found out about it two weeks after the fact, which is the good part of this story. The bad part: notification letters didn't go out until roughly 274 days later, in late July 2026. That's over nine months between discovery and telling the people affected. More than 442,000 patients were affected, including at least 277,364 Texas residents. What was taken: names, Social Security numbers, dates of birth, driver's licenses, government IDs, health insurance information, diagnosis information, and medical record numbers. The company is offering two years of identity monitoring through Kroll. Two years against a stolen Social Security number and a diagnosis history that both last a lifetime.

Two More, So You Know This Isn't Rare

Stryker, the medical device manufacturer, had employee and consumer data stolen in a March 2026 attack attributed to an Iran-linked hacking group; a lawsuit now alleges the company failed to implement reasonable security despite having the resources to do so. Carnival Corporation notified 6 million people in May 2026 after hackers social-engineered their way into a single employee's account and walked out with names, addresses, birthdates, and identification numbers for customers who had nothing to do with that employee's inbox. Different industries, different attack methods, same result: somebody else's negligence became your problem, and you didn't find out until they got around to telling you.

The Other Failure: Stewardship as an Afterthought

Everything above is negligence — companies and agencies that didn't spend what it cost to keep data safe. Texas Attorney General Ken Paxton's lawsuit against Allstate and its data analytics subsidiary, Arity, is the other half of the picture, and it's arguably worse because nothing about it was an accident. The lawsuit alleges Allstate and Arity paid app developers to secretly embed tracking software into apps like Life360, GasBuddy, and Fuel Rewards, logging the location and movement of more than 45 million people's phones every 15 seconds, without notice or consent, to build what the companies themselves called the world's largest driving behavior database. They then used that covertly harvested data to help justify raising people's insurance rates, and sold it to other insurers on top of that. A federal judge allowed most of the related claims to proceed in March 2026, and the underlying conduct has been in litigation for over a year now.

This is not a company that lost track of data it was supposed to protect. This is a company that built its business model on taking data that nobody agreed to give, and only stopped when a state attorney general sued. That's the clearest possible illustration of corporatocracy in action: a corporation deciding, as a matter of strategy, that the value of your data to its underwriting model was worth more than your right to say no — and being right, for over a decade, because nothing stopped it until litigation did. It's curated control, too, in its purest form: the millions of people whose locations were logged every 15 seconds never saw an Arity consent screen at all. They agreed to a fuel rewards program or a family locator app, and the actual data-sharing decision was made entirely somewhere they never looked.

Why Does It Take So Long to Tell Anyone?

Texas law requires a business to notify affected individuals within 60 days of determining a breach occurred — not 60 days from the breach itself, 60 days from the point the company figures out it happened. Unlimited Technology Systems discovered its breach on October 19, 2025. Notifications didn't go out until roughly nine months later. Companies can get a delay if law enforcement is actively investigating, and that may well explain part of the gap here — I don't have confirmation either way. But at minimum, the standard everyone's supposedly operating under and what actually happens on the ground aren't the same thing, and the people waiting on that letter are the ones absorbing the distance between the two.

Why Is a Year (or Two) of Credit Monitoring Considered Compensation?

It isn't, according to the people who actually study this. Consumer Reports has called credit monitoring "ultimately just a Band-Aid for a much deeper problem." Security researchers point out that it can flag suspicious activity after the fact, but it doesn't erase fraudulent debt, doesn't repair damaged credit, doesn't compensate for the time spent fixing either one, and does nothing about the fact that a stolen Social Security number doesn't expire in a year or two. Offering a fixed monitoring window for permanent exposure isn't protection. It's a documented industry practice, chosen specifically because it's the cheapest thing a breached institution can offer that still looks like something.

The Technical Excuse Doesn't Hold Up

"We couldn't have known" is the line every one of these institutions leans on, and it isn't true. Real-time threat monitoring isn't experimental technology — it's a mature industry that multiple companies run as their entire business. CrowdStrike's Falcon platform provides continuous monitoring and automated threat detection at enterprise scale, built specifically to catch intrusions in real time rather than months later. Arctic Wolf offers 24/7 monitoring through a dedicated security team assigned to each customer, with the explicit purpose of catching what automated tools miss. Satcom Direct, based in Melbourne, Florida, sells the same category of protection — enterprise firewalls, embedded antivirus, and real-time intrusion detection — to its own aviation and maritime clients as a standard tier of service, not an add-on. Three different companies, three different industries, the same product: knowing you've been breached in hours, not in nine months. If a satellite communications company and a handful of dedicated security vendors can sell continuous monitoring as an off-the-shelf product, a state agency or a Fortune 500 company handling millions of records has no excuse for going months without noticing an intrusion in its own systems. The capability isn't the bottleneck. The willingness to pay for it is.

What Severe Penalties Actually Look Like

The United States doesn't have a real answer for any of this, and it isn't for lack of trying. The American Data Privacy and Protection Act advanced further in Congress than any federal privacy bill ever had, passing committee in 2022, but it still died at the end of that session. Its successor, the American Privacy Rights Act, has sat in draft since April 2024. As of this year, there is still no comprehensive federal privacy law in the United States — just a patchwork of 19 state laws, sector-specific rules like HIPAA, and whatever a state attorney general decides to pursue on their own, the way Paxton did with Allstate.

Who Killed It, and Why

Ask why Congress hasn't passed either bill, and the answer isn't a mystery. It's a paper trail. Meta, Amazon, Alphabet, and Apple have spent more than $100 million combined on federal lobbying since 2021. The data broker industry alone — companies whose entire business is buying and reselling exactly the kind of information Allstate got sued for taking — spent $143 million lobbying Congress between 2020 and 2022, with spending spiking to $16.6 million in the single quarter the ADPPA came up for committee consideration in June 2022. That's not a coincidence of timing. That's the industry showing up hardest exactly when the bill that would have restrained it was on the table. The bill died months later.

The two provisions that sank both the ADPPA and the American Privacy Rights Act were the two provisions industry fought hardest to kill: a federal law strong enough to preempt weaker state ones, and the right of an individual citizen to sue a company directly when it violates their privacy, instead of waiting on a regulator with limited time and limited staff. Those aren't technical sticking points buried in legislative language. Those are the two things standing between you and real accountability, and the people elected to write that law left both out rather than pass it without them. Sit with that: the corporations that would be punished by strong privacy legislation are the same corporations funding the campaigns of the people voting on whether it passes. That isn't an accusation. It's a matter of public record, and it's why the bill you'd actually want has been sitting dead or in draft for four years running.

It isn't only Washington, and it isn't only Congress. State legislatures haven't been drafting their own defenses either. Reporting has traced direct links between industry lobbying and the language that ended up in "privacy" bills considered in Connecticut, Florida, Oklahoma, and Washington — bills sold to the public as consumer protection, with provisions that trace back to Amazon, Microsoft, and other companies with a direct stake in the outcome. Read that again: in multiple states, the companies these laws were supposed to restrain were the ones holding the pen. That's not regulatory capture in the abstract. That's corporatocracy in its most literal form — not a system quietly influenced after the fact, but a system where the law's own language originates inside the industry it claims to regulate. The state legislators who introduced, amended, and voted for those bills aren't victims of clever lobbying they didn't see coming. They're participants in it, at the state level exactly as much as their counterparts are at the federal level, and both deserve to be named for it rather than let the word "Congress" or "the legislature" absorb the blame anonymously.

What Real Enforcement Looks Like

The European Union has had one since 2018, and it isn't symbolic. GDPR fines have topped €7.1 billion cumulatively, with €1.2 billion assessed in 2025 alone, across more than 2,800 enforcement actions. The structure is what makes it work: up to €20 million or 4% of a company's global annual revenue, whichever is greater, for the kind of violation Allstate is accused of — unlawful data collection and unauthorized use. Up to €10 million or 2% of global revenue for the kind of failure that hit TPWD, Unlimited Technology Systems, Stryker, and Carnival — inadequate security. Percentage-of-revenue penalties scale with the offender, which is exactly what a flat fine can't do. A $2 million fine is a rounding error for an insurance conglomerate and a death sentence for a small vendor; a percentage of global revenue is neither.

Compare that to what the U.S. actually has on the books. California's CCPA tops out at around $7,988 per intentional violation — real money in theory, but the typical American privacy enforcement action lands in the $300,000-to-$3 million range, nowhere close to GDPR's scale. There's no single regulator, no harmonized standard, and no central registry tracking any of it. Senator Elizabeth Warren's proposal to expose negligent executives to jail time is a step toward taking this seriously; it shouldn't be a novel idea. It should be the floor.

The United States doesn't need a new theory of data privacy. It needs to adopt the one that's already been tested at scale for eight years and is currently extracting billions of dollars from companies that decided your data was theirs to use. Real teeth means fines that scale with the size of the offender, not a settlement a company can absorb as a cost of doing business — and it means those teeth apply the same way whether the offender is a Fortune 500 insurer or a state agency that outsourced the job to a vendor and never checked the work.

In this piece, "corporatocracy" isn't a company that got hacked. It's the calculation made beforehand — that protecting your data costs more than losing it — proven right, year after year, because nothing has ever forced the math to change.

Curated control, in this piece, isn't a menu with the good options missing. It's a consent box standing between you and a system that was never going to ask your permission for the part that actually mattered.

Call to Action: What Needs to Happen Now

  • Contact your member of Congress and both Texas senators directly — not a form letter, a specific ask: support a federal privacy law with real penalties, a private right of action, and no industry-favorable preemption of stronger state protections.
  • If you're in Texas's 24th District, that's Rep. Beth Van Duyne. Statewide, that's Sen. Ted Cruz and Sen. John Cornyn — both hold a vote right now, regardless of what happens in November.
  • Ask the same of whoever you're voting for in the Senate race this November — Ken Paxton or James Talarico — before you vote, not after.
  • Slow down on urgency. Phishing emails and scam calls almost always lean on urgent, emotionally charged language — a locked account, a missed payment, a family member in trouble. That urgency is the tell, not the threat.
  • Never use the contact information in the message itself. If a bank, employer, or agency contacts you about something serious, don't click the link or call the number provided. Look up the organization's number independently and call that one.
  • Assume the caller ID can be faked. Scammers can spoof a legitimate company's phone number, so a call appearing to come from your bank or a government agency doesn't confirm it actually is one. Hang up and call the number on the back of your card or on the agency's official site instead.
  • Freeze your credit, don't just monitor it. A credit freeze is free, and unlike credit monitoring, it actually stops new accounts from being opened in your name rather than just alerting you after the fact.
  • Check a breach-tracking service like Have I Been Pwned periodically. Companies are often slow to notify you, as this piece has already shown. You don't have to wait on their timeline to find out.

Sources

Texas Parks and Wildlife Department. Notification of Data Security Incident.

Fox News, KXAN, GovTech, SecurityWeek, NBC DFW, Rescana. Coverage of the Texas Parks and Wildlife Department vendor data breach (June 2026).

ClassAction.org, Morningstar/PR Newswire, ClaimDepot, Becker's Hospital Review, Settlement Insight. Coverage of the Unlimited Technology Systems data breach, discovery and notification timeline, and affected-individual counts.

ClassAction.org. Coverage of the Stryker Corporation data breach lawsuit (March 2026 incident).

Class action and breach-tracking coverage of the Carnival Corporation data breach notification (May 2026).

Office of the Texas Attorney General. Attorney General Ken Paxton Sues Allstate and Arity for Unlawfully Collecting, Using, and Selling Over 45 Million Americans' Driving Data to Insurance Companies.

CarPro, Fox Business, FindLaw, CBS19/Insurify. Coverage of the Texas AG lawsuit against Allstate and Arity.

Privacy Daily, FindLaw, Keller Rohrback, CIPAWorld/National Law Review, MLex, Repairer Driven News. Coverage of the related federal consolidated class action against Allstate/Arity, including the March 3, 2026, ruling on the motion to dismiss.

Consumer Reports, via CBS News and NBC News. Commentary on the limitations of credit monitoring as breach compensation.

CrowdStrike, Arctic Wolf, Satcom Direct. Company-published descriptions of managed detection and response and continuous threat monitoring services.

Kiteworks, StationX, Termly, Sprinto. 2026 GDPR fine and enforcement statistics.

Brooklyn Law School, Termly, American Bar Association, HIPAA Journal. Legislative history of the American Data Privacy and Protection Act and the American Privacy Rights Act.

Issue One. Reporting on Big Tech lobbying spend, including opposition to the Kids Online Safety and Privacy Act.

The Markup. The Little-Known Data Broker Industry Is Spending Big Bucks Lobbying Congress.

State of Surveillance. Reporting on industry-drafted language in state privacy legislation in Connecticut, Florida, Oklahoma, and Washington.

CISA. Avoiding Social Engineering and Phishing Attacks and Recognize and Report Phishing.

LegalClarity, PrivacyLawMap, DataBreachCost, Recording Law. Summaries of the Texas data breach notification statute and its 60-day individual notification deadline.

Ballotpedia, Texas Tribune, Washington Post, NBC News, Houston Public Media, 19th News, TPR. Coverage of the 2026 Texas U.S. Senate primary results (Talarico defeats Crockett; Paxton defeats Cornyn).

Congress.gov, GovTrack, Office of Rep. Beth Van Duyne. District and biographical information for Texas's 24th Congressional District.

V64OTD // YOUR DATA WAS NEVER SAFE. IT WAS JUST CHEAP TO IGNORE.