Cybersecurity

Ransomware at Texas Appraisal Districts: What Happened and What a CAD Should Do

Ransomware at Texas Appraisal Districts: What Happened and What a CAD Should Do

Ransomware reaches appraisal districts through ordinary paths like email, and it can take core services offline for days or months. The districts that recovered fastest had working backups and a plan. Four large Texas appraisal districts have been hit since 2022: Bexar, Dallas, Travis and Tarrant.

The details from each one are useful if you run IT for a smaller district, because the same gaps exist at any size.

What happened at each district

Bexar County Appraisal District, March 2022. Email servers went down along with several other critical systems. The website and phones stayed up. Assistant Chief Appraiser Scott Griscom told KSAT it did not look like anyone had clicked a link, but the attack appeared to come in through email. The attackers left a ransom note with no dollar amount and no contact information. They could not reach the appraisal records database, and the district restored from its backups. Griscom's advice to other organizations was short: back up your data.

Dallas Central Appraisal District, November 2022. Barracuda's writeup says the Royal ransomware group hit the district, likely through phishing, and disrupted about 300 desktop computers, the email system and the website for an agency that manages nearly 850,000 parcels. More than two weeks in, the website was still down and staff could not process homestead exemptions. A district spokesperson put it this way: "We can collect information. We just can't do anything with them right now." Email and public web applications came back in December, and the district had almost fully recovered by early February 2023. The district later confirmed it paid $170,000 to the attackers.

Travis Central Appraisal District, December 2022. Phone lines, online chat and the internal network went offline. The district said response times slowed for staff answering questions and processing homestead exemption applications. The public website, the property search tool and tax bill payments were not affected. Chief Appraiser Marya Crigler said at the time: "At this time, we do not have an estimate on how long it will take to restore our network."

Tarrant Appraisal District, March 2024. Axios reported that the attackers demanded $700,000. Email, phones, the property search feature and a website the district had launched earlier that month were affected. Officials notified the FBI and the Texas Department of Information Resources (DIR). They said they did not want to pay, and they were not sure whether any data had actually been taken.

What these cases have in common

Email was the likely way in for at least two of them. In every case, the first thing the public noticed was a service they rely on going dark: phones, chat, property search or the website.

Timing mattered too. The Dallas spokesperson said the attack did not affect protests because it hit during a slower period, and protests typically peak in summer. That is a fair point, and it also means an attack in May or June would put a district in a much harder spot.

What a CAD should have in place before an attack

Backups you have tested and can restore from. Bexar's backups are why its outage was measured in days. Keep at least one copy that ransomware cannot reach, either offline or set so it cannot be changed or deleted. Then restore from it on a schedule, so you know how long it takes.

Email protection and multifactor authentication on every account. Filter attachments and links, and require a second factor for email, remote access and administrator logins.

Endpoint monitoring that someone actually watches. Ransomware often starts encrypting after hours. You want an alert to reach a person, not sit in a console.

An incident plan with names and phone numbers. Write down who calls the FBI, your insurer, your IT provider and your board chair. Texas law also expects action from local governments. Under Government Code 2054.603, a local government that holds sensitive personal information must notify DIR within 48 hours of discovering a qualifying security incident, and follow up within ten business days after the incident is resolved with a report that includes the cause. DIR takes initial reports by phone at (877) DIR-CISO.

A way to serve the public while systems are down. Phones and chat went out at Travis, and email went out at Bexar. Decide ahead of time which backup phone number, email address and paper process you will use.

A decision on ransom, made in advance. Whether to pay is a question for your attorney, your insurer and law enforcement. It is a bad one to answer for the first time during an outage.

Where to start

If you can only do one thing this month, restore a file from your backups and time it. If the answer is "we have never tried," you have your first project.

The bigger lesson

None of these districts were careless in some unusual way. Email, backups and a written plan are the same three gaps at every size. A managed IT provider closes them by testing restores, watching alerts after hours and keeping the incident plan current, so the first time you read it is not during an outage.

safemode IT is a managed IT and cybersecurity provider based in Kyle, Texas. We support appraisal districts and other local government offices across Central Texas. To talk through your backup and incident readiness, call 512-761-7652 or visit safemodeit.com.

Sources

Not sure your IT is as solid as it should be? Take 10 minutes and tell us about your setup. No pressure, no obligation.

Book a 10-Minute Discovery Call →

Frequently asked questions

How do ransomware attacks usually reach a Texas appraisal district?

Email is the most common path. Bexar CAD said its attack appeared to come in through email, and the Dallas attack was likely phishing. Filtering, multifactor authentication and staff training reduce that risk but do not remove it, so backups still matter most.

Does a Texas appraisal district have to report a ransomware attack to the state?

A local government that holds sensitive personal information must notify the Texas Department of Information Resources within 48 hours of discovering a qualifying security incident under Government Code 2054.603. It also has to file a follow-up report within ten business days after the incident is resolved.

Should an appraisal district pay the ransom?

That is a question for your attorney, your insurer and law enforcement. Dallas CAD paid $170,000, while Tarrant said it did not want to pay. Decide your approach before an attack, not during one.

What is the first thing a small CAD should do to prepare?

Restore a file from your backups and time it. If nobody has tried, that is your first project. Keep one backup copy that ransomware cannot change or delete.

Can safemode IT manage this so we do not have to deal with it?

Yes. We run backups, email protection and endpoint monitoring for local government offices across Central Texas. Learn more about our managed IT services or reach out for a free assessment.

Last updated: October 9, 2026

ransomwareappraisal districttexas cadbackupsincident responselocal government