Featured Article

Security flaws in court record systems used in five US states exposed sensitive legal documents

The vulnerabilities allowed public access to restricted, sealed and confidential court filings using only a web browser

Comment

Concept illustration depicting messy litigation with an illustrated gavel on a multicolored background
Image Credits: Bryce Durbin / TechCrunch

Witness lists and testimony, mental health evaluations, detailed allegations of abuse and corporate trade secrets. These are some of the sensitive legal court filings that security researcher Jason Parker said they found exposed to the open internet for anyone to access, and from none other than the judiciaries themselves.

At the heart of any judiciary is its court records system, the technology stack for submitting and storing legal filings for criminal trials and civil legal cases. Court records systems are often in part online, allowing anyone to search and obtain public documents, while restricting access to sensitive legal filings in which public exposure could compromise a case.

But Parker said some court records systems used across the U.S. have simple security flaws that expose sealed, confidential and sensitive but unredacted legal filings to anyone on the web.

Parker told TechCrunch that they were contacted in September by someone who read their earlier report documenting a vulnerability in Bluesky, the new social network that emerged after Twitter’s sale to Elon Musk. The tipster told Parker that two U.S. court records systems had vulnerabilities that were exposing sensitive legal filings to anyone on the web. The tipster reported the bugs to the affected courts but said they heard nothing back, Parker told TechCrunch in a call earlier this month.

Equipped with the tipster’s findings, Parker fell down a rabbit hole investigating several affected court records systems. Parker subsequently uncovered security flaws in at least eight court records systems used across Florida, Georgia, Mississippi, Ohio and Tennessee.

“The first document I ran across was an order from a judge in a domestic violence case. The order was to grant name changes for children to basically keep them safe from the spouse,” Parker told TechCrunch, speaking about reproducing the first vulnerability. “Immediately my jaw just went to the center of the earth and stayed that way for weeks.”

“The next document that I found in the other court was a full mental health evaluation. It was thirty-pages long in a criminal case, and it was as detailed as you would expect; it was from a doctor,” they added.

The bugs vary by complexity, but could all be exploited by anyone using only the developer tools built-in to any web browser, Parker said.

These kinds of so-called “client-side” bugs are exploitable with a browser because an affected system was not performing the proper security checks to determine who is allowed to access sensitive documents stored within.

One of the bugs was as easy to exploit as incrementing a document number in the browser’s address bar of one Florida court records system, said Parker. Another bug allowed anyone “automatic passwordless” access to a court records system by adding a six-letter code to any username, which Parker said they found as a clickable link in a Google search result.

With help from vulnerability disclosure center CERT/CC and CISA’s Coordinated Vulnerability Disclosure team, which assisted in the coordination of disclosing these flaws, Parker shared details of nine total vulnerabilities with the affected vendors and judiciaries in an effort to get them fixed.

What came back was a mixed bag of results.

Three technology vendors fixed the bugs in their respective court record systems, Parker said, but only two firms confirmed to TechCrunch that the fixes took effect.

Catalis, a government technology software company that makes CMS360, a court records system used by judiciaries across Georgia, Mississippi, Ohio and Tennessee, acknowledged the vulnerability in a “separate secondary application” used by some court systems that allows the public, attorneys or judges to search CMS360 data.

“We have no records or logs indicating that confidential data was accessed through that vulnerability, and have received no such reports or evidence,” said Catalis executive Eric Johnson in an email to TechCrunch. Catalis would not explicitly say if it maintains the specific logs it would need to rule out improper access to sensitive court documents.

Software company Tyler Technologies said it fixed vulnerabilities in its Case Management Plus module in a court records system used exclusively in Georgia, the company told TechCrunch.

“We have been in communication with the security researcher and have confirmed the vulnerabilities,” said Tyler spokesperson Karen Shields. “At this time, we have no evidence of discovery or exploitation by a bad actor.” The company did not say how it came to this conclusion.

Parker said that Henschen & Associates, a local Ohio software maker that provides a court records system called CaseLook across the state, fixed the vulnerability but did not respond to emails. Henschen president Bud Henschen also did not respond to emails from TechCrunch, or confirm that the company had fixed the bug.

In their disclosure published Thursday, Parker also said they notified five counties in Florida by way of the state courts administrator’s office. The five Florida courts are thought to have developed their own court records systems in-house.

Only one county is known to have fixed the vulnerability found in their system and ruled out improper access to sensitive court records.

a photo of Sarasota County courthouse in Florida, one of the counties with an affected court case system
A photo of Sarasota County Courthouse in Florida, one of the judiciaries with an affected court records system. Image Credits: Independent Picture Service / Universal Images Group via Getty.

Sarasota County said it had fixed a vulnerability in its court records system it calls ClerkNet, which allowed access to documents by incrementing through numerically sequential document numbers. In a letter provided to TechCrunch when reached for comment, Sarasota County clerk of the circuit court Karen Rushing said the review of its access logs “revealed no occurrences where sealed or confidential information was accessed.” The county disputed the existence of a second flaw reported by Parker.

Given the simplicity of some of the vulnerabilities, it is unlikely that Parker or the original tipster are the only people with knowledge of their exploitability.

The four remaining Florida counties have yet to acknowledge the flaws, say if they have implemented fixes, or confirm if they have the ability to determine if sensitive records were ever accessed.

Hillsborough County, which includes Tampa, would not say if its systems were patched following Parker’s disclosure. In a statement, Hillsborough County Clerk spokesperson Carson Chambers said: “The confidentiality of public records is a top priority of the Hillsborough County Clerk’s office. Multiple security measures are in place to ensure confidential court records can only be viewed by authorized users. We consistently implement the latest security enhancements to Clerk systems to prohibit it from happening.”

Lee County, which covers Fort Myers and Cape Coral, also would not say if it had fixed the vulnerability, but said it reserved the right to take legal action against the security researcher.

When reached for comment, Lee County spokesperson Joseph Abreu provided an identical boilerplate statement as Hillsborough County, with the addition of a thinly veiled legal threat. “We interpret any unauthorized access, intentional or unintentional, as a potential violation of Florida Statute Chapter 815, and may also result in civil litigation by our office.”

Representatives for Monroe County and Brevard County, which Parker also filed vulnerability disclosures with, did not respond to requests for comment.

For Parker, their research amounts to hundreds of unpaid hours, but represents only the tip of the iceberg of affected court record systems, noting that at least two other court record systems have similar unpatched vulnerabilities today.

Parker said they hope their findings help make changes and spur on improvements to the security of government tech applications. “Gov-tech is broken,” they said.

Read more on TechCrunch:


You can contact Zack Whittaker on Signal and WhatsApp at +1 646-755-8849 or by email. You can also contact TechCrunch via SecureDrop.

More TechCrunch

Match Group, the company that owns several dating apps, including Tinder and Hinge, released its first-quarter earnings report on Tuesday, which shows that Tinder’s paying user base has decreased for…

Match looks to Hinge as Tinder fails

Private social networking is making a comeback. Gratitude Plus, a startup that aims to shift social media in a more positive direction, is expanding its wellness-focused, personal reflections journal to…

Gratitude Plus makes social networking positive, private and personal

With venture totals slipping year-over-year in key markets like the United States, and concern that venture firms themselves are struggling to raise more capital, founders might be worried. After all,…

Can AI help founders fundraise more quickly and easily?

Google has found a way to bring a variation of its clever “Circle to Search” gesture to iPhone users. The new interaction, launched in January, allows Android users to search…

Google brings a variation on ‘Circle to Search’ to iPhone users

A new sculpture going live on Wednesday in the Flatiron South Public Plaza in New York is not your typical artwork. It combines technology, sociology, anthropology and art to let…

Always-on video portal lets people in NYC and Dublin interact in real time

Apple’s iPad event had a lot to like. New iPads with new chips and new sizes, a new Apple Pencil, and even some software updates. If you are a big…

TechCrunch Minute: When did iPads get as expensive as MacBooks?

Autonomous, AI-based players are coming to a gaming experience near you, and a new startup, Altera, is joining the fray to build this new guard of AI agents. The company announced…

Bye-bye bots: Altera’s game-playing AI agents get backing from Eric Schmidt

Google DeepMind has taken the wraps off a new version AlphaFold, their transformative machine learning model that predicts the shape and behavior of proteins. AlphaFold 3 is not only more…

Google DeepMind debuts huge AlphaFold update and free proteomics-as-a-service web app

Uber plans to deliver more perks to Uber One members, like member-exclusive events, in a bid to gain more revenue through subscriptions.  “You will see more member-exclusives coming up where…

Uber promises member exclusives as Uber One passes $1B run-rate

We’ve all seen them. The inspector with a clipboard, walking around a building, ticking off the last time the fire extinguishers were checked, or if all the lights are working.…

Checkfirst raises $1.5M pre-seed to apply AI to remote inspections and audits

Close to a decade ago, brothers Aviv and Matteo Shapira co-founded a company, Replay, that created a video format for 360-degree replays — the sorts of replays that have become…

Controversial drone company Xtend leans into defense with new $40 million round

Usually, when something starts to rot, it gets pitched in the trash. But Joanne Rodriguez wants to turn the concept of rot on its head by growing fungus on trash…

Mycocycle uses mushrooms to upcycle old tires and construction waste

Monzo has raised another £150 million ($190 million), as the challenger bank looks to expand its presence internationally — particularly in the U.S. The new round comes just two months…

UK challenger bank Monzo nabs another $190M as US expansion beckons

iRobot has announced the successor to longtime CEO, Colin Angle. Gary Cohen, who previous held chief executive role at Timex and Qualitor Automotive, will be heading up the company, marking a major…

iRobot names former Timex head Gary Cohen as CEO

Reddit — now a publicly-traded company with more scrutiny on revenue growth — is putting a big focus on boosting its international audience, starting with francophones. In their first-ever earnings…

Reddit tests automatic, whole-site translation into French using LLM-based AI

Mushrooms continue to be a big area for alternative proteins. Canada-based Maia Farms recently raised $1.7 million to develop a blend of mushroom and plant-based protein using biomass fermentation. There’s…

Meati Foods bites into another $100M amid growth to 7,000 retail locations

Cleaning the outside of buildings is a dirty job, and it’s also dangerous. Lucid Bots came on the scene in 2018 with its Sherpa line of drones to clean windows…

Lucid Bots secures $9M for drones to clean more than your windows

High interest rates and financial pressures make it more important than ever for finance teams to have a better handle on their cash flow, and several startups are hoping to…

Israeli startup Panax raises a $10M Series A for its AI-driven cash flow management platform

The European Union has deepened the investigation of Elon Musk-owned social network, X, that it opened back in December under the bloc’s online governance and content moderation rulebook, the Digital Services Act…

EU grills Elon Musk’s X about content moderation and deepfake risks

For the founders of Atlan, a data governance startup, data has always been at the heart of what they do, even before they launched the company. In fact, co-founders Prukalpa…

Atlan scores $105M for its data control plane, as LLMs boost importance of data

It is estimated that about 2 billion people, especially those in lower and middle-income countries, lack access to quality and affordable essential medicines. The situation is exacerbated by low-quality or even killer…

Axmed raises $2M from Founderful to streamline drug supply chains in underserved markets

For decades, the Global Positioning System (GPS) has maintained a de facto monopoly on positioning, navigation and timing, because it’s cheap and already integrated into billions of devices around the…

Xona Space Systems closes $19M Series A to build out ultra-accurate GPS alternative

Bankruptcy lawyers representing customers impacted by the dramatic crash of cryptocurrency exchange FTX 17 months ago say that the vast majority of victims will receive their money back — plus interest. The…

FTX crypto fraud victims to get their money back — plus interest

Google on Wednesday launched its digital wallet in India with local integrations, nearly two years after the app was relaunched as a digital wallet platform in the U.S. As TechCrunch exclusively reported last month,…

Google Wallet is now available in India

Bluesky has launched a new product roadmap for the coming months. The decentralized social network said on Tuesday that it is planning to introduce direct messages, support for videos, improved…

Bluesky to add DMs, video support and in-app custom feed curation

Samsung Medison, a medical device unit of Samsung Electronics that specializes in developing diagnostic imaging devices, said on Wednesday it plans to acquire Sonio, a Paris-based startup that makes AI-powered software…

Samsung Medison to acquire French AI ultrasound startup Sonio for $92.7M

Kyle Kuzma is a lot of things. He’s a forward for the Washington Wizards NBA team and a 2020 NBA champion. He’s also a style icon — depending on who…

NBA champion Kyle Kuzma looks to bring his team mentality to Scrum Ventures

Ofcom is cracking down on Instagram, YouTube and 150,000 other web services to improve child safety online. A new Children’s Safety Code from the U.K. Internet regulator will push tech…

Ofcom to push for better age verification, filters and 40 other checks in new online child safety code

Lipids are fatty, waxy or oily compounds that, for instance, typically come in the form of fats and oils. As a result they are heavily used in the production of…

After a $20M Series A funding, Germany’s Insempra plans eco-friendly lipid production

Tesla CEO Elon Musk has said that lidar sensors are a “crutch” for autonomous vehicles. But his company has bought so many from Luminar that Tesla is now the lidar-maker’s…

Tesla is Luminar’s largest lidar customer