US federal judiciary agency hit by 'escalated cyber attacks' which exposed highly sensitive data
The agency says it plans to step up cybersecurity capabilities in the wake of the incident
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
The US federal judiciary agency has fallen victim to what it is calling 'escalated cyber attacks' targeting its electronic case filing system.
The attack involved the breach of data from Case Management/Electronic Case Files, used by legal professionals to upload and manage case documents, and PACER, which gives the public limited access to the same data.
Information exposed includes sealed indictments detailing information about alleged crimes that is not available to the general public, along with arrests and search warrants.
"The vast majority of documents filed with the Judiciary’s electronic case management system are not confidential and indeed are readily available to the public, which is fundamental to an open and transparent judicial system," said the Administrative Office of the United States Courts.
"However, some filings contain confidential or proprietary information that are sealed from public view. These sensitive documents can be targets of interest to a range of threat actors.
The judiciary said it is working with Congress, as well as the Department of Justice, the Department of Homeland Security, and others, to mitigate the risks and impacts of these cyber attacks.
Who’s behind the federal judiciary attacks?
It's not yet clear how the hackers gained access, nor who was responsible for the attack, although it's suspected to be nation state-affiliated actors.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Nick Tausek, lead security automation architect at Swimlane, described the incident as a “serious breach with far-reaching implications” due to the nature of the data exposed.
"What’s especially concerning is how little is still known about the attack, including the method of entry, the actors behind it, and the full scope of the breach,” Tausek said.
“While investigations are still underway, the limited visibility may point to the involvement of a highly sophisticated threat actor, gaps in cybersecurity measures, or a combination of both."
The breach is just the latest in a series of attacks, which have led to calls for improvements in security.
In June, Court of Appeals judge Michael Scudder testified before a House Judiciary subcommittee, pledging to modernize the agency's IT systems and introduce more rigorous procedures to restrict access to sensitive documents.
He said that replacing Case Management/Electronic Case Files and PACER was a top priority, but that this would take time.
"It’s reassuring to see the chair of the Committee on Information Technology for federal courts call for modernization of the department’s cybersecurity defenses. The sooner these measures are implemented, the better," said Tausek.
"Additionally, proactive security measures should be incorporated into the federal courts systems’ defenses in order to mitigate future attacks that will inevitably be inspired by the success of this one.”
Campaign group Fix The Court said that the Federal Judiciary needs to speed up its modernization work if it's to avoid similar attacks in the future.
"You know what would fix this? The Open Courts Act, a bill that would beef up cybersecurity by using modern technology to maintain the court records system, replacing the awkward, patchwork architecture exists today," it said. "Without it, this is going to happen again."
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
MORE FROM ITPRO
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Anthropic promises ‘Opus-level’ reasoning with new Claude Sonnet 4.6 modelNews The latest addition to the Claude family is explicitly intended to power AI agents, with pricing and capabilities designed to attract enterprise attention
-
Researchers call on password managers to beef up defensesNews Analysts at ETH Zurich called for cryptographic standard improvements after a host of password managers were found lacking
-
Researchers called on LastPass, Dashlane, and Bitwarden to up defenses after severe flaws put 60 million users at risk – here’s how each company respondedNews Analysts at ETH Zurich called for cryptographic standard improvements after a host of password managers were found lacking
-
‘They are able to move fast now’: AI is expanding attack surfaces – and hackers are looking to reap the same rewards as enterprises with the technologyNews Potent new malware strains, faster attack times, and the rise of shadow AI are causing havoc
-
Ransomware gangs are using employee monitoring software as a springboard for cyber attacksNews Two attempted attacks aimed to exploit Net Monitor for Employees Professional and SimpleHelp
-
Notepad++ hackers remained undetected and pushed malicious updates for six months – here’s who’s responsible, how they did it, and how to check if you’ve been affectedNews Hackers remained undetected for months and distributed malicious updates to Notepad++ users after breaching the text editor software – here's how to check if you've been affected.
-
CISA’s interim chief uploaded sensitive documents to a public version of ChatGPT – security experts explain why you should never do thatNews The incident at CISA raises yet more concerns about the rise of ‘shadow AI’ and data protection risks
-
Former Google engineer convicted of economic espionage after stealing thousands of secret AI, supercomputing documentsNews Linwei Ding told Chinese investors he could build a world-class supercomputer
-
90% of companies are woefully unprepared for quantum security threats – analysts say they need to get a move onNews Quantum security threats are coming, but a Bain & Company survey shows systems aren't yet in place to prevent widespread chaos
-
LastPass issues alert as customers targeted in new phishing campaignNews LastPass has urged customers to be on the alert for phishing emails amidst an ongoing scam campaign that encourages users to backup vaults.
