North Carolina Courts Failed to Report Data Breach

The state's administrative office did not notify the Attorney General of an exposure affecting jury duty records.

Updated on Sept. 28, 2026 in Cybersecurity

Bold flat-color editorial illustration showing a stoic, geometric building facade, evoking state administrative opacity.
The North Carolina Administrative Office of the Courts failed to notify the Attorney General of a data breach involving jury duty records, violating state law. AI Illustration. Upload story photo >

Live Poll

Do you trust your local government agencies to securely handle your sensitive personal information?

A security vulnerability in a North Carolina Administrative Office of the Courts website exposed sensitive personal records for hundreds of residents. The office failed to provide a mandatory breach notification to the state's Department of Justice following the incident.

Why it matters

The failure to report the breach directly contravenes the North Carolina Identity Theft Protection Act, which mandates disclosure of security incidents to the Attorney General. This lapse raises questions regarding compliance and data oversight within state judicial digital infrastructure.

A website feature intended for uploading jury excuse forms inadvertently stored sensitive documents on publicly accessible links. These files, containing Social Security numbers, driver's licenses, and medical records, lacked authentication requirements.

The players

North Carolina Administrative Office of the Courts

The administrative body responsible for the digital systems and document management portals used by the state's judicial system.

North Carolina Department of Justice

The state agency tasked with enforcing the North Carolina Identity Theft Protection Act and managing legal responses to data breaches.

The details

The vulnerability originated from a web portal feature that allowed prospective jurors to upload supporting documentation alongside their excuse forms. These documents were stored in directories accessible via direct links, bypassing any security authentication protocols. The data remained exposed until a media investigation prompted the office to block public access to the files.

Timeline

  1. September 28, 2026: Reporting surfaced regarding the lack of breach notification.

The Tech Race

State judicial systems are currently in a transition to modernize document intake via centralized web portals. This incident marks a significant compliance failure relative to the standards mandated by the North Carolina Identity Theft Protection Act.

Individuals summoned for jury duty in North Carolina whose personal documents were uploaded to the portal may have had their private records exposed. Residents should remain vigilant for identity theft and monitor their financial accounts for unauthorized activity.

The takeaway

The event highlights the critical importance of authentication in public-facing state portals handling sensitive legal and medical data. Residents should watch for upcoming audits or policy changes within the North Carolina Administrative Office of the Courts regarding their data handling protocols.

Further reading

For broader trends in digital security policy, visit Cybersecurity.

Live Poll

Do you trust your local government agencies to securely handle your sensitive personal information?