CSIDB logo
Incident

DocketWise

Incident posture

Attack window
Oct 2025
Location
United States of America
Status
Resolved
CIA posture
Available to members
Updated
2026-08-27 02:08

Linked entities

Victim
DocketWise
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Oct 2025
Discovered
Oct 2025
Disclosed
Apr 2026
Resolved
May 2026

Summary

DocketWise disclosed a data breach affecting over 143,000 individuals after threat actors cloned third‑party partner repositories using valid credentials, gaining access to personal, financial, and medical information. Exposed data included names, addresses, dates of birth, Social Security numbers, driver’s license numbers, passport and government ID numbers, financial account numbers, payment card details, tax identification numbers, health insurance policy numbers, medical condition information, and non‑financial account usernames.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In October 2025, DocketWise discovered that threat actors had gained unauthorized access to third-party partner repositories by cloning valid credentials. The cloned repositories were being used as a data migration pipeline for the DocketWise application, which stores law firm records. Through this access, the attackers obtained personal, financial, and medical information belonging to individuals whose data resided in the system. The compromised personally identifiable information included names, addresses, dates of birth, Social Security numbers, driver’s license numbers, passport and government ID numbers. Additionally, financial account numbers, payment card details, tax identification numbers, health insurance policy numbers, medical condition information, and non‑financial account usernames and access information were accessed.

DocketWise began notifying affected individuals in early April 2026, initially estimating that approximately 116,000 people were impacted. On April 3, 2026, the company filed a notice with the Maine Attorney General’s Office, which later revised the total number of affected individuals to 143,480, noting that the figure could increase as the investigation continued. The same day, DocketWise sent written notices to consumers and posted breach details on its website. The breach disclosure indicated that 13 residents of Maine were among those affected. To assist impacted individuals, DocketWise arranged for two years of free credit monitoring and identity restoration services through IDX, with enrollment available via a dedicated web page or by calling 1‑844‑890‑7449 before July 3, 2026.

The company stated that the unauthorized access has been closed and that there is no evidence of the compromised data being published online. Affected individuals who did not receive a notification letter but suspect they may be involved can contact a dedicated assistance line for further information. The investigation into the breach remains ongoing, with the potential for the total number of impacted individuals to change as additional findings emerge. No further details about the threat actor’s identity or motives are provided in the source material.

Sources

Sources available to members: 2 sources.

CSIDB