North Carolina Courts Failed to Report Data Breach
The state's administrative office did not notify the Attorney General of an exposure affecting jury duty records.
Updated on Sept. 28, 2026 in Cybersecurity

Live Poll
Do you trust your local government agencies to securely handle your sensitive personal information?
A security vulnerability in a North Carolina Administrative Office of the Courts website exposed sensitive personal records for hundreds of residents. The office failed to provide a mandatory breach notification to the state's Department of Justice following the incident.
Why it matters
The failure to report the breach directly contravenes the North Carolina Identity Theft Protection Act, which mandates disclosure of security incidents to the Attorney General. This lapse raises questions regarding compliance and data oversight within state judicial digital infrastructure.
A website feature intended for uploading jury excuse forms inadvertently stored sensitive documents on publicly accessible links. These files, containing Social Security numbers, driver's licenses, and medical records, lacked authentication requirements.
The players
North Carolina Administrative Office of the Courts
The administrative body responsible for the digital systems and document management portals used by the state's judicial system.
North Carolina Department of Justice
The state agency tasked with enforcing the North Carolina Identity Theft Protection Act and managing legal responses to data breaches.
The details
The vulnerability originated from a web portal feature that allowed prospective jurors to upload supporting documentation alongside their excuse forms. These documents were stored in directories accessible via direct links, bypassing any security authentication protocols. The data remained exposed until a media investigation prompted the office to block public access to the files.
Timeline
September 28, 2026: Reporting surfaced regarding the lack of breach notification.
The Tech Race
State judicial systems are currently in a transition to modernize document intake via centralized web portals. This incident marks a significant compliance failure relative to the standards mandated by the North Carolina Identity Theft Protection Act.
Individuals summoned for jury duty in North Carolina whose personal documents were uploaded to the portal may have had their private records exposed. Residents should remain vigilant for identity theft and monitor their financial accounts for unauthorized activity.
The takeaway
The event highlights the critical importance of authentication in public-facing state portals handling sensitive legal and medical data. Residents should watch for upcoming audits or policy changes within the North Carolina Administrative Office of the Courts regarding their data handling protocols.
Further reading
For broader trends in digital security policy, visit Cybersecurity.
Live Poll
Do you trust your local government agencies to securely handle your sensitive personal information?









