
The Resource Center of Dallas, North Texas' largest LGBTQIA+ organization, has confirmed that a February cyberattack on its computer network exposed sensitive personal data for far more people than initially disclosed. While early reporting put the number of affected Texans at more than 9,000, official breach notifications filed with state regulators now show the true toll reached 12,490 people nationwide, including 13 residents of Massachusetts alongside the 9,048 in Texas.
The nonprofit first disclosed the breach in a notice letter saying its files were accessed by an unauthorized third party, according to reporting by The Dallas Morning News. The intrusion potentially exposed names, Social Security numbers, government ID numbers, financial information, health insurance details and medical records, according to the same report. Filings with Massachusetts regulators, reviewed by Hoodline, show forensic investigators pinpointed the unauthorized access to a window between February 4 and February 12 — but the organization did not finish confirming which identities were exposed until July 2, nearly five months later, per filings submitted to Massachusetts regulators.
That gap between intrusion and notification explains why the public didn't learn the full scope of the incident until this summer. The Resource Center notified law enforcement and determined the identities of people who may have been impacted in early July, then began mailing formal breach notification letters on July 15, per the Massachusetts filing. The organization also stood up a dedicated toll-free call center, 1-888-201-1486, staffed for 90 days to help affected clients set up fraud alerts and credit freezes.
A Legal Clock Already Ticking
Texas law sets firm deadlines for exactly this kind of disclosure. Under Section 521.053 of the Texas Business and Commerce Code, any organization whose breach affects 250 or more Texas residents must alert the Texas Attorney General within 30 days of discovery and notify affected residents within 60 days, according to an analysis from Davis Wright Tremaine. The data breach was reported to the Texas Attorney General's Office, according to The Dallas Morning News. Failing to comply with the state's breach statutes can trigger civil penalties of $2,000 to $50,000 per violation, plus up to $100 per day per affected individual, enforced by the Attorney General, per a breakdown from FindLaw.
Multiple national consumer protection law firms have already opened the door to litigation. Federman & Sherwood, Barnow & Associates, P.C., and Shamis & Gentile P.A. all launched investigations in July into whether the Resource Center maintained adequate cybersecurity safeguards, according to a post from Federman & Sherwood. No court has ruled on any negligence claim, and the responsible party for the intrusion itself remains unclear.
Who Was Exposed, and What the Center Says It's Doing
The Resource Center provides primary healthcare, mental healthcare, HIV/AIDS support services and advocacy work, serving the population most likely to have entrusted the organization with exactly the kind of sensitive medical and financial data now in question. The organization said it values individual privacy and deeply regrets the incident, and said it has reviewed and revised its information security practices and implemented additional security measures aimed at mitigating the chance of a similar event recurring.
The breach lands amid a broader surge in healthcare-sector hacking. HHS data compiled by HIPAA Journal shows 2025 set an all-time record with 772 large healthcare data breaches reported nationwide, with hacking and IT incidents behind more than 80 percent of major compromises. That national pattern offers some context for why a mid-sized nonprofit health and social-services provider like the Resource Center became a target.
Leadership Change Adds to a Turbulent Year
The disclosure arrives just as the Resource Center undergoes a major leadership transition. Former KERA Chief Operating Officer Christopher Wagley was appointed in July to take over as CEO in November, succeeding longtime CEO Cece Cox ahead of her planned retirement in early 2027, according to the Dallas Voice. Cox's exit caps a tenure that Hoodline detailed earlier this year in a piece on her remaking of the organization, which grew from its 1983 founding as the Foundation for Human Understanding during the HIV/AIDS crisis into the nation's second-largest LGBTQIA+ community center, with an annual operating budget of roughly $35 million serving more than 60,000 people a year.
That growth has been visible on the ground in Oak Lawn, where the Resource Center opened the 84-unit, $31 million Oak Lawn Place affordable senior housing development in 2024, followed by a 20,000-square-foot integrated health facility in 2025. The breach notification now complicates that expansion narrative, arriving just as the organization prepares to hand off leadership and continues to build out its footprint as a hub for healthcare and housing in the neighborhood.









