Were you recently affected by a data breach?

Heart of Texas Workforce Development Board Data Breach

Heart of Texas Workforce Development Board, a Waco, Texas-based nonprofit workforce agency, has notified the Texas Attorney General of a data breach exposing names, Social Security numbers, and dates of birth for hundreds of individuals.

Heart of Texas Workforce Development Board
Date of Breach: Specific breach date not publicly disclosed; reported to the Texas Attorney General on September 11, 2026
CAU logo

Who was affected:

Clients of Heart of Texas Workforce Development Board

Impacted Data:

Names, Social Security numbers, dates of birth

Heart of Texas Workforce Development Board, Inc., a nonprofit workforce development agency based in Waco, Texas, has reported a data security incident to the Texas Attorney General involving the personal information of hundreds of individuals. Organizations that administer workforce programs and handle sensitive personal information on behalf of job seekers and program participants have a responsibility to protect that data, and those affected deserve a clear account of what happened.

Heart of Texas Workforce Development Board’s Data Breach Investigation

According to a filing submitted to the Texas Attorney General’s Data Security Breach Reports portal, published on September 11, 2026, Heart of Texas Workforce Development Board disclosed a data security incident affecting 640 Texas residents. The filing lists the categories of information involved as names, Social Security numbers, and dates of birth. As of this notice’s publication, the organization has not released additional public information about the incident beyond what appears in the state filing, including the specific date the breach occurred, how unauthorized parties gained access, or the underlying cause of the incident.

Nonprofit workforce agencies and similar community organizations often serve as intermediaries between government job-training programs and the individuals who rely on them, which means they routinely collect and retain Social Security numbers, dates of birth, and other identifying information as part of processing applications for employment services, training programs, and public benefits. This makes them a meaningful target for cybercriminals despite typically operating with smaller security budgets than private-sector companies handling comparable volumes of sensitive data, a gap that has made nonprofit and public-sector organizations an increasingly common target across the broader landscape of reported data breaches.

Texas law generally requires businesses and organizations to notify affected residents and the Attorney General within a reasonable window once a breach is discovered and its scope understood, though the precise discovery and containment dates for this particular incident were not included in the public filing reviewed for this article. This gap between when an incident actually occurs and when it becomes public is a normal part of the investigation and notification process, not evidence that anything was handled improperly.

The combination of a Social Security number and date of birth, even without additional information such as a driver’s license number or financial account details, is often sufficient on its own to open new lines of credit, file a fraudulent tax return, or apply for government benefits in a victim’s name. This is part of why Social Security numbers are treated as especially sensitive under most state breach-notification laws, including Texas’s, regardless of what other data may or may not have been exposed alongside them.

Because the full extent of how this information may ultimately be used is not always apparent right away, cybersecurity and consumer protection experts generally recommend that anyone notified of a breach involving a Social Security number take proactive steps, such as placing a fraud alert or credit freeze, well before any specific instance of misuse is discovered.

When Did This Breach Occur?

Heart of Texas Workforce Development Board’s data breach notification was published to the Texas Attorney General’s Data Security Breach Reports portal on September 11, 2026. The filing did not specify the exact date the breach itself occurred or the date it was discovered.

What Information Was Breached?

Per the filing, the categories of information involved include names, Social Security numbers, and dates of birth for 640 Texas residents.

What You Can Do

If you received a notice from Heart of Texas Workforce Development Board or believe you may have been affected by this breach, consider taking the following steps:

  • Consider placing a fraud alert or security freeze on your credit files with the three major credit bureaus.
  • Monitor your bank and credit card statements closely for any unauthorized transactions.
  • File your taxes as early as possible to reduce the risk of tax-related identity fraud.
  • Be cautious of unsolicited calls, emails, or texts referencing this breach, as scammers sometimes exploit public breach notices to run phishing schemes.
  • Keep any notification letter you receive in case you need it for future reference.

File a Data Breach Lawsuit Against Heart of Texas Workforce Development Board

If your personal information was exposed in the Heart of Texas Workforce Development Board data breach, you may have legal options available to you. Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Suspicious activity detected December 30, 2025; notice filed with the New Hampshire Attorney General on September 1, 2026
Date of Breach: Reported to the Texas Attorney General on September 11, 2026
Date of Breach: Reported to be around May 25, 2026; formally reported to the Texas Attorney General on September 11, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.