The Kansas Department of Justice has released an update on a cybersecurity incident that took place last month. Now, the attack have led to a data breach, after hackers stole files containing confidential information from Kansas courts.

In mid-October 2023, the Kansas Judicial Authority reported that a “security incident” occurred that impacted the availability of multiple systems (e.g., use of the eFiling system for document submission, systems , and case management systems used by district courts and appellate courts).
See also: AutoZone: Warns of data breach via “MOVEit attack”
Now, a month later, there are still significant issues, with the following services offline:
- Kansas Courts eFiling: For electronic filing of documents
- Kansas Protection Order Portal: For electronic filing of documents
- Public access to the Kansas District Court: To search for district court cases
- Appeals Court Search System: For searching for second instance court cases
- Kansas eCourt Case Management: Used by district courts to process cases
- Kansas Attorney Registration: To search for attorneys by name or bar number
- Online application for marriage license in Kansas
- Central Payment Center
The region's judicial authority called the impact on these systems temporary, but confirmed that there had been breach data.
“ While the impact on our information systems is temporary, cybercriminals stole data and threatened to publish it on the dark web if their demands were not met ,” the press release states
“Based on our preliminary analysis, it appears that the stolen information includes records from the Office of Court Administration, appellate case files, and other data, some of which may be confidential, as required by law“.
While the Kansas courts have not officially stated the nature of the attack, the description sounds like a typical attack ransomware. There was a system outage (likely due to file encryption), and the hackers stole data and threatened to leak it on the dark web. This sounds like a typical double-extortion ransomware attack.
See also: Canada: Data breach affects government employees
The Kansas authority estimates it will take several weeks for all systems to return to normal. It promises to notify affected individuals once the stolen data is reviewed.
The statement says this attack is “against all citizens of Kansas” and calls the perpetrators evil.
"This attack on the Kansas justice system is vile and criminal. Today, we express our deep sorrow that the citizens of Kansas will suffer at the hands of these cybercriminals," the statement said.

What measures should be taken?
To prevent future cyberattacks on Kansas courts, several security measures need to be taken. One key measure is to strengthen cybersecurity by upgrading the systems and software used in the courts. This includes installing the latest versions of security software and updating them regularly.
Additionally, court staff need to be trained on cybersecurity fundamentals and best practices for preventing and responding to cyberattacks. This includes training on recognizing and avoiding phishing, using secure passwords, and avoiding open Wi-Fi networks.
See also: Yamaha Motor: Ransomware attack led to employee data breach
Cyberattack prevention and detection measures should also be strengthened through the installation of advanced security solutions , such as malware scanners and intrusion detection systems. This allows for immediate detection and response to attacks, limiting the damage that can be caused.
Finally, analysis of past cyberattacks to identify weaknesses and implement improvements. should be conducted This includes evaluating security systems, upgrading protective measures, and updating security policies and procedures.
Source: www.bleepingcomputer.com
