By NACABAR.org Editorial Staff

Hipolito F. Garcia Federal Building and U.S. Courthouse, San Antonio. Photo by Joshua J. Cotten / Unsplash.
Washington, D.C., New York, Los Angeles, Miami. June 15, 2026.
The Silence After the Breach
In August 2025, Federal judicial officials have acknowledged that the nation’s court filing systems were targeted by sophisticated and persistent cyberattacks. They have warned that sensitive documents were at risk. They have moved certain highly sensitive filings out of ordinary electronic channels. But months after public reporting exposed renewed federal court breaches, the deeper questions remain largely unanswered: what exactly was compromised, what has been contained, which legacy systems remain exposed, and whether the public can trust that the digital docket itself has not been manipulated.
That silence is no longer a technical footnote. It is the story. A new report from coordinated cyber experts working through the Bridge-Gate ESS Division’s Restricted-Access Portal Solutions Unit warns that the danger may extend beyond stolen sealed filings or unauthorized access to confidential court documents. The report argues that the federal judiciary’s aging e-filing architecture, trusted electronic notices, legacy “.dcn” servers, SMTP relays, and restricted-access portals may create an attack surface capable of producing something more corrosive than disclosure: procedural distortion.
The concern is not that every missing notice, strange docket entry, or abrupt case outcome is the product of a hack. That would be too easy, and too reckless. The concern is that, in a system where court access now depends on credentials, email authentication, routing tables, portal logs, and old servers still sitting inside the trust chain, a sophisticated actor may not need to break down the courthouse door. The actor may only need to control what the system shows, what it sends, what it withholds, and what the record later claims happened.
When a Portal Becomes the Gatekeeper
According to the February 23, 2026 report, the core vulnerability sits where identity, workflow and trust converge. A portal is not just a website. It is the gatekeeper for filing lawsuits, serving orders, paying fees, renewing licenses, moving money and proving that a deadline was met. A single stolen credential can become a master key across email, document management, case management and outside filing portals. An end-of-life desktop, a forgotten on-premise Exchange server, or a Windows Server 2012 machine kept alive because “it still works” can become a quiet observation post from which an attacker watches browser sessions, cookies, saved passwords and internal notices.
This is the part of the story that rarely makes it into public explanations. Court systems are often discussed as if “online filing” is one thing. It is not. It is a chain. That chain can include public login pages, internal routing servers, mail relays, clerk workstations, sealed-document procedures, payment systems, single sign-on environments, DNS records, authentication policies, and legacy machines that nobody outside the building can see. If one weak link sits inside the trust path, the court may believe the system is working while a user on the outside experiences silence, rejection, delay, or a record that does not match reality.

Portal integrity flow. The chain runs from authentication to workflow, routing, observable consequences and expert review.
The Public Warnings Were Already There
The report lands against a public record that should already have forced sustained attention. In January 2021, the Administrative Office of the U.S. Courts announced new procedures for highly sensitive documents after what it described as an apparent compromise of CM/ECF confidentiality. Those documents were to be filed on paper or secure physical media, not uploaded through the ordinary electronic filing system. In July 2022, Reuters reported that congressional leaders had been briefed that three hostile foreign actors had attacked the courts’ document filing system, a breach described as having startling breadth and scope. In August 2025, after Politico reported another sweeping compromise, the federal Judiciary publicly acknowledged recent escalated cyberattacks of a sophisticated and persistent nature against case management systems. BleepingComputer reported the same month that protecting legacy systems was becoming increasingly difficult.
In other words, the first premise of the portal-security report is no longer speculative. The court technology stack has been breached before. Federal officials have said so. Judges have said the system is under constant attack. Senator Ron Wyden, in an August 2025 letter to Chief Justice John Roberts, called the federal courts’ case-management system insecure, antiquated and expensive, and argued that repeated compromises exploited unresolved weaknesses known since 2020. Circuit Judge Michael Scudder told Congress in June 2025 that judiciary cyber defenses blocked about 200 million harmful events in fiscal year 2024 and that PACER and CM/ECF modernization had become urgent because the old architecture was unsustainable due to cyber risk.
Yet the public conversation largely stalled at a narrow formulation: sealed files may have been accessed. That is bad enough. But it is not the only question. The harder question is whether the same access paths that allow threat actors to read sealed filings could also allow them to affect routing, notice, docket visibility, service records, or the timing and shape of what judges and litigants see.

Public record and expert-warning timeline, with response priorities for court and legal-infrastructure operators.
Sealed Filings Are the Pressure Point
Sealed criminal complaints, cooperation materials, warrants, informant references and emergency civil applications are not ordinary PDFs. They can reveal investigative strategy, witness exposure, national-security equities and the location of evidence before the government or a private litigant is ready to move. When the judiciary responded in 2021 by moving highly sensitive documents away from ordinary CM/ECF upload paths, it effectively acknowledged that confidentiality could no longer be assumed inside the standard electronic rail.
The report pushes the logic one step further: if confidentiality was at risk, integrity may be at risk too. A system that can be read by an unauthorized actor may, at higher privilege, be shaped by one. If a sealed filing can be viewed by the wrong person, can a notice be delayed? Can a docket entry be suppressed? Can a document appear in one internal view but not another? Can a filing be truncated before chambers sees it? Can a party be made to look nonresponsive because the system claims service occurred when the real message never arrived?
These are uncomfortable questions. They also flow directly from the architecture. Once the courthouse becomes a networked system, justice depends not only on judges and clerks, but on whether that network can prove what happened.
The Attack Often Looks Ordinary
The answer is disturbing because it is mundane. In the report’s model, attackers do not always need Hollywood malware. They use normal features. They log in with valid credentials. They change service lists. They alter notification emails. They add new authentication devices. They route mail through authorized servers. They exploit the difference between “the system sent it” and “the intended person actually received it.” The portal does not know whether the person behind the password is a lawyer, a clerk, a thief, or a private cyber cell. It only knows that the login was accepted.
That is the layperson’s version of the green-padlock problem. TLS encryption protects the tunnel between a browser and a server. It does not prove that the user is legitimate. It does not prove that the server behind the tunnel is clean. It does not prove that an internal relay, a docketing host, a mail gateway or a legacy application server has not already been bent into an attacker’s workflow. The report asks readers to stop treating the padlock as a moral certificate. The padlock means privacy in transit. It does not mean integrity at destination.
That distinction is essential. A court notice can pass through a familiar system and still be compromised if the identity, relay, routing, or content-authentication layer has been abused. A filing can be accepted by a clerk and still fail to reach the right judicial workflow if the internal routing layer is unreliable or under unauthorized control. The user sees a portal. The attacker sees a chain of dependencies.

The green-padlock problem. TLS protects the tunnel; it does not prove the identity, relay, server or docket workflow is clean.
When a Cyber Failure Looks Like a Judicial Act
Court cybersecurity differs from ordinary enterprise security because the consequences can masquerade as legal procedure. If a retail portal is compromised, the damage can be measured in refunds, chargebacks and identity-theft notices. If a court portal is compromised, the damage can look like a judicial act. A forged notice can become a missed deadline. A suppressed order can become a default. A truncated filing can make a judge see an incomplete record. A manipulated service list can make one side invisible. By the time anyone asks whether the process was real, the docket may already carry the authority of finality. The technology failure has been laundered into procedure.
For the public, the distinction is brutal. A litigant does not experience DNS hijacking as DNS hijacking. She experiences it as a portal that will not accept a payment, an email that never arrives, a receipt that looks right but does not correspond to the court’s record, or a judge ruling as if a key exhibit never existed. The value of the report is that it teaches institutions to read these experiences as telemetry. The witness is not merely complaining. The witness may be reporting the only visible smoke from a fire burning inside the trust chain.
Reading Docket Anomalies as Cyber Telemetry
The report’s most important contribution is its procedural lens. Cybersecurity reports often stop at indicators of compromise: IP addresses, hashes, malware families, domain changes. This report follows the compromise to the clerk’s counter. It treats missing filings, undocketed orders, misrouted notices, sequence anomalies, false deficiency notices and payment irregularities as possible symptoms of portal compromise. That is not paranoia. It is incident response adapted to law. If a bank customer reports that a wire instruction changed without authorization, investigators do not begin by blaming the customer for being confused. They examine logs. Courts need the same reflex.
The uploaded expert record reviewed by the portal-security team describes a pattern across legal infrastructure: credential theft, DNS manipulation, mail relay abuse, suspicious docket behavior and synchronized attacks around litigation milestones. According to the Cyber-N.E.T. Forensics e-Forensic Integrated Expert Report dated October 22, 2025, investigators analyzed hundreds of domains, thousands of mail records and portal logs tied to legal-industry systems. That report describes bursts of domain-name-server changes, mail-exchanger anomalies and unauthorized portal access in the same windows. According to the Marlin Technologies Expert Report dated December 5, 2024, a law office environment under review showed escalating anomalous activity in spring and summer 2024, including alleged unauthorized control over network permissions, DNS and cloud storage.
The report is careful not to make every anomaly dispositive. That restraint matters. Courts are human institutions. Clerks mistype docket text, mail gets delayed, lawyers misunderstand rules, and software fails for boring reasons. But the report argues that the security baseline changed once public authorities acknowledged repeated compromise of the same broad ecosystem. In that environment, clusters matter. Timing matters. A missing notice plus a DKIM failure plus a DNS flip plus a rapid adverse procedural result is no longer a shrug. It is a pattern demanding escalation.
How the Portal Experts Followed the Trail
The methodology matters because the report is not built around one strange email, one missing docket entry, or one frustrated litigant’s account of what went wrong. It is built around correlation: the disciplined comparison of what the court record says happened, what the electronic systems appear to have done, what the parties actually received, and what the technical infrastructure was doing at the same time.
The unit began with the visible record. Docket sheets, clerk notices, court orders, sealed-case records, file-room copies, service events, and procedural timelines were reconstructed first, before any broader theory was imposed on the evidence. That sequence is important. The court file was treated as the starting point. The next question was whether the digital trail behind that file supported or contradicted the official sequence of events.
From there, the analysis moved into the technical layer. The report describes review of raw email headers tied to federal court notices, including SMTP relay paths, internal “.dcn” routing references, gateway hosts, sender-authentication results, timestamps, IP addresses, and inconsistencies between envelope data and message-header data. In plain English, the experts examined the mailroom: where the message said it came from, which servers handled it, whether the authentication checks passed, and whether any part of the path suggested alteration, delay, substitution, or relay abuse.
The same approach was applied to DNS and portal infrastructure. The report describes review of DNS history, MX records, SPF records, nameserver changes, low time-to-live patterns, cloud-provider shifts, orphaned or “lame” delegations, and domain-routing behavior around litigation events. That work matters because DNS is the internet’s direction system. If the direction system is altered, a user may believe they are entering the courthouse portal while the traffic is being routed, mirrored, delayed, or shaped somewhere else.
The report also compared its findings against prior expert work rather than merely adopting it. It states that it incorporated earlier CNF findings, federal-court audit findings, CM/ECF header analysis, and broader integrity reports, then tested core elements against independent evidence. That independence is central to the report’s credibility. The question was not simply whether another expert saw compromise. The question was whether the portal-security team could see the same compromise manifesting at the portal level as real-world procedural harm.
The result is a methodology designed for the digital courthouse. It looks for the point where cyber indicators become legal consequences: a missing notice, a strange assignment path, a filing that appears truncated, a deficiency notice that never arrives, an order that exists in one system view but not another, or a docket entry whose timing does not fit the normal workflow. In that sense, procedure itself becomes telemetry. The docket is not just paperwork. It is an output of a technical system. When that output bends, the question becomes whether the machine behind it has been touched.

Modern data center corridor. Photo by Brett Sayles / Pexels.
How the Report Tested the Pattern
The report does not merely repeat earlier conclusions. It says it validated core elements against its own evidentiary base, including email headers, DNS history, MX and SPF records, packet captures, court dockets and physical file-room records where available. Its job, as the report frames it, is to test whether technical compromise produces visible procedural consequences. That is the bridge most institutions avoid crossing, because once a cyber event becomes a court-access event, the stakes move from IT cleanup to due process.
Consider electronic service. A court notice may pass SPF because it came from an authorized IP range. But if the notice carries no DKIM signature, or a DKIM signature that fails, and the sending domain uses a DMARC policy that only monitors rather than rejects bad mail, the system may tolerate the very signals that should trigger an alarm. The report calls this a favorable environment for adversary-in-the-middle control. Translated: an attacker who can use or mimic an authorized relay may send or alter a court-like notice that looks official enough to pass downstream filters, while the recipient never gets the real order, or gets a doctored one.
This matters because court process is built on presumptions. If the docket says notice was sent, the court tends to presume notice was sent. If the docket says a party failed to respond, the system tends to treat that as a procedural fact. But a cyber-compromised notice environment creates a different possibility: the court’s own system may record an event that did not function as legally meaningful notice in the real world.
The Threat Model Is Not Exotic
This problem has a public analogue. CISA and MITRE have long warned that adversaries abuse valid accounts, manipulate DNS, hijack domains and position themselves between users and services. MITRE’s adversary-in-the-middle technique includes manipulating DNS so victims are redirected through attacker-controlled systems. Its domain-hijacking entry describes how attackers may seize or alter domain registrations and cloud DNS control. The portal-security report is applying those ordinary threat models to extraordinary civic infrastructure.
The legal profession has been warned about this for years. In June 2023, Reuters reported that French and British cyber authorities had seen mercenary hackers increasingly targeting law firms to steal data and gain the upper hand in business or legal disputes. Reuters’ earlier reporting on Indian hack-for-hire networks described private cyber operatives stealing litigation material from hundreds of lawyers and law firms. The point is not that every court anomaly comes from a foreign intelligence service. The point is that litigation itself has become a target. A case can be worth more than a ransom demand.
That is what makes federal court silence so dangerous. The public does not need panic. It needs a clear accounting. Were the affected systems rebuilt, segmented, monitored, or merely patched? Were legacy servers forensically imaged? Were authentication logs preserved? Were suspicious docket or service anomalies audited? Were litigants notified if their matters crossed compromised infrastructure? Without answers, the public is left with a half-disclosed breach and a fully functioning justice system that continues to demand trust.
The Criminal Infrastructure Is Mature
The Microsoft, Google, Sophos and DXC cases cited in the expert record show how mature this economy has become. Microsoft Digital Crimes Unit experts described cracked Cobalt Strike infrastructure as a global malware delivery system capable of backdoor access, credential theft, lateral movement and ransomware deployment. Microsoft’s 2025 final judgment in the Cobalt Strike matter permanently enjoined operators associated with Conti, LockBit and related threat groups and ordered action against command-and-control domains and IP addresses. Google, in its Glupteba case, described a botnet that used cloud services, proxies and even blockchain fallback mechanisms to keep command channels alive. Sophos and DXC, in 2020 declarations, described sophisticated actors using domains, cloud masking and infrastructure rotation to evade disruption.
The portal-security report’s alarm is that pieces of that same criminal operating model now appear in court-adjacent workflows: living off the land, using legitimate relays, hiding behind cloud providers, shifting DNS, reusing infrastructure and exploiting stale endpoints. The attack is not always a bang. Sometimes it is a courthouse whisper: a missing notice here, a substituted record there, a filing fee that cannot be paid, an order that exists internally but is never meaningfully served.
This is why the issue rises beyond routine IT governance. A criminal network that steals bank credentials can drain accounts. A criminal network that manipulates court-access infrastructure can alter the path by which rights are recognized, defended, or extinguished. That is a national-security-level risk because the legitimacy of courts is not just a domestic administrative concern. It is a pillar of democratic stability.
Aging Endpoints Are Not a Side Issue
A federal or court-related server does not need to be famous to be dangerous. It only needs to sit in the trust chain. If a legacy internal host scans sealed paper filings into a docketing environment, it becomes a gateway. If an old mail relay is authorized by SPF but does not sign mail with enforceable DKIM, it becomes a forgery surface. If a clerk’s workstation stores credentials and browser cookies, it becomes the courtroom key ring. If an electronic filing portal trusts profile data from a professional membership database, then a compromised membership portal can become a path into the filing portal.
This is where modernization rhetoric can become misleading. A new public interface may sit on old machinery. A user-facing portal can look polished while the back end still depends on infrastructure designed for a different threat era. The danger is not merely that an old machine exists. The danger is that everyone has forgotten how much authority that old machine still has.
What the Report Says Must Change
The report’s prescription is correspondingly blunt. Segment and, where possible, decommission legacy CM/ECF and internal docketing servers. Treat systems that sat in the environment between 2020 and 2025 as suspect until memory-level forensics and authentication-log review prove otherwise. Require DKIM signing for court notices. Move DMARC from passive monitoring toward quarantine or rejection. Narrow SPF to known, well-documented mail infrastructure. Monitor DNS and MX records continuously. Use registry locks and multi-party approval for name-server changes. Eliminate lame delegations and orphaned name-server records. Compare internal docket logs, PACER-visible entries, physical file jackets and mailing records in periodic integrity audits.
The procedural fixes may be even more important. Critical orders in sealed or cyber-sensitive matters should move through dual channels: electronic service plus certified or otherwise verifiable physical notice. Courts should use digitally signed orders verifiable against public court keys. Chambers should have tools to reconcile what they actually received against what the docket says exists. When a sealed, conventionally filed case generates an order referring to CM/ECF notice, that discrepancy should trigger review, not indifference. In high-risk matters, early status conferences should confirm that foundational filings and orders were actually received by all parties.
Above all, the judiciary needs an emergency integrity path that does not force cyber-integrity evidence back through the same contested infrastructure. Courts have procedures for fires, floods, hurricanes, sealed warrants, emergency injunctions and after-hours filings. They now need a narrow, authenticated route for litigants, lawyers and designated cyber experts to place threshold evidence of court-system compromise before an authorized decision-maker without relying exclusively on the portal whose integrity is being questioned.
Modernization Without Integrity Is Theater
The threat changes the ethics of modernization. Courts have spent years debating electronic access as a public-service issue: fees, transparency, usability, search and the democratic promise of open records. The report does not reject that promise. It insists that access without integrity is theater. A beautiful portal sitting on brittle back-end trust is like a courthouse with a polished lobby and an unlocked evidence room. Modernization cannot be a new skin over the same exposed organs. It has to include cryptographic proof, centralized monitoring, incident drills and independent review authority capable of asking uncomfortable questions when the record itself becomes suspect.
None of this requires courts to abandon technology. It requires courts to stop pretending technology is neutral after compromise. Paper is not nostalgia when the network is burning; it is a temporary firebreak. Out-of-band confirmation is not inefficiency when email authenticity is uncertain; it is due process. A signed order that can be independently verified is not a luxury; it is the digital version of a seal.
The country does not need a judiciary that explains every technical detail to the public in real time. Some information may properly remain restricted during incident response. But the public does need assurance that containment happened, that legacy systems were examined, that impacted records were audited, and that the courts are not relying on breached assumptions to validate their own outputs.
The Exploit Path Is Institutional Trust
The most dangerous sentence in any institution is still: this is how we have always done it. In the digital courthouse, that sentence has become an exploit path. Courts built around trust now operate inside a threat environment built around abusing trust. The adversary does not need to defeat justice openly. It can make justice miss a deadline, fail to notice a filing, misread a docket, or believe a message was served when it was not.
The report is not asking the public to believe in ghosts. It is asking the judiciary to hunt for them in the logs. That means preserving headers. It means comparing internal and external docket states. It means validating notice. It means reviewing sealed-case handling. It means accepting that procedure itself can be a cyber artifact.
This is a hard shift for courts. Judges are trained to resolve disputes based on records, not to suspect the record as a possible attack surface. Clerks are trained to process filings, not to perform adversary-in-the-middle analysis. Lawyers are trained to meet deadlines, not to reverse-engineer mail relays. But that is exactly why a coordinated expert response is necessary. The legal system cannot outsource trust to software and then refuse to audit the software when the breach record says the trust chain was targeted.
The Constitutional Emergency Behind the IT Problem
The courthouse door is still there. But behind it now sits another door, made of software, credentials, relays, records and old machines nobody wants to admit are still central. If that door is compromised, then access to justice becomes conditional on the attacker’s permission. That is not a technology problem. That is a constitutional emergency wearing an IT badge.
Federal judicial officials do not need to inflame public fear. They do need to answer the containment question. Which systems were compromised? Which were rebuilt? Which were retired? Which notices, sealed filings, and docket events were audited for integrity? Which litigants were affected? Which safeguards now prevent the next adversary from turning a court portal into a procedural weapon?
Until those questions are answered, the silence after the breach remains part of the breach.