CSIDB logo
Incident

Administrative Office of the U.S. Courts

Incident posture

Attack window
Jan 2021
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-21 19:06

Linked entities

Victim
Administrative Office of the U.S. Courts
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jan 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Administrative Office of the U.S. Courts experienced a compromise of its electronic filing and case management system (CM/ECF), likely linked to the broader SolarWinds Orion product breach. The incident, which prompted collaboration with the Department of Homeland Security for a system audit, raised concerns about potential exposure of sensitive corporate and legal documents. The extent of data compromise remained unclear due to decentralized control over filings, as individual courts determined what information was stored within the system, leading to variability in potential impacts across jurisdictions.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On January 6, 2021, the Administrative Office of the U.S. Courts publicly disclosed an “apparent compromise” of its electronic filing and case management system (CM/ECF), which handles federal court documents nationwide. The agency attributed the breach to a likely connection with the SolarWinds Orion supply chain attack that impacted multiple U.S. government entities and private organizations. The Administrative Office confirmed it was collaborating with the Department of Homeland Security to conduct a comprehensive audit of the compromised system. No specific technical details about the intrusion method or timeline of unauthorized access were provided in the disclosure. The CM/ECF system’s centralized infrastructure supports critical functions across all federal courts, though individual courts retain autonomy over document filing protocols.

The breach’s full scope remained undetermined at the time of reporting, with the Administrative Office acknowledging uncertainty regarding which documents or data might have been exposed. Impacts varied across jurisdictions due to decentralized control over filings, as individual courts independently determine what sensitive information—including corporate secrets, sealed records, or classified materials—gets uploaded to the system. No specific compromised cases, litigants, or document types were identified publicly. The Administrative Office declined to provide further details about potentially affected data categories or operational consequences beyond confirming the system audit. Response efforts focused exclusively on the joint forensic investigation with DHS, with no disclosed containment measures, restoration timelines, or notifications to affected parties at the time of initial reporting.

Sources

Sources available to members: 1 source.

CSIDB