Tuesday, October 17, 2023

Cybersecurity Incident Disrupts Kansas Courts eFiling System

 

The Kansas Supreme Court has issued an administrative order declaring that its e-filing system would be unavailable through Sunday, October 15, due to “a security incident that has disrupted access to court systems.” Courts were operational during the downtime. Just one of the state’s counties has been able to operate as usual; Johnson County is the only county to have not yet been updates to Kansas’s new eCourt system.  
 
While the courts are operating, clerks cannot receive electronic filings or payments. All filings must be on paper or by fax. Paper filings can be sent by mail or hand delivered. Courts are being prepared to operate for at least the next two weeks on manual processes. While Jefferson County is able to continue business as usual, as the only site not to have been signed up for the state's new centralized eCourt system, it's not clear what aspect of the new system allowed it to be compromised. This introduces the consideration when introducing a new centralized system of not only measuring the overall security, but also developing viable scenarios to continue operations locally while the central system is impacted. Don't let a return to manual processing be the end of the discussion.


Given the published length of downtime, it’s safe to assume a ransomware attack as the likely culprit. Hopefully, the State court system will provide an after-action report on the sequence of events that led to the security incident. This can shed some light on security responsibilities of the system provider, Tyler Technologies.



Read more in:
- www.theregister.com: We're not in e-Kansas anymore: State courts reel from 'unauthorized incursion'
- www.govinfosecurity.com: Kansas Supreme Court Probes Potential Ransomware Attack
- www.kscourts.org: Unavailability of Electronic Filing Systems (PDF)
- www.kscourts.org: Supreme Court issues order in response to network security incident
- www.kscourts.org: Supreme Court says state courts will stay open, operate on paper while security incident examined

No comments:

Common Vulnerabilities and Exposures Updates !!

  CVE-2023-38545: curl SOCKS5 oversized hostname vulnerability. https://curl.se/docs/CVE-2023-38545.html   Last week, Daniel Stenberg...