
TPIS Industrial Services Inc., a family-owned industrial contractor headquartered in Pasadena, Texas, disclosed a data breach connected to a ransomware attack that compromised sensitive personal and health information.
The breach was reported to the Texas Attorney General on July 17, 2026, with 2,123 Texas residents identified as affected.
On March 26, 2026, PLAY, a ransomware group, posted a claim on the dark web, stating it had successfully obtained data from TPIS Industrial Services and intended to publish the stolen information within three days.
PLAY claimed to have accessed a wide range of data from the company's systems including private and personal confidential data, client documents, budget records, payroll information, IDs, tax records and financial information.
The types of personally identifiable information (PII) exposed in the breach included names, addresses, Social Security numbers and driver's license numbers. Protected health information (PHI) was also compromised, including medical information and health insurance information.
Individuals who receive a notification letter from TPIS Industrial Services should review it carefully for details about what specific personal information of theirs was involved in the breach. The letter may also contain information about any protective steps or resources the company is providing for affected individuals, along with contact details for questions or concerns.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)