A cyberattack on the Kansas Office of Judicial Administration in October 2023 stole files holding personal information. The state later reported the breach affected roughly 150,000 people and began notifying those it could identify.
What happened
On October 12, 2023, the Kansas judicial branch reported a cyberattack on the Office of Judicial Administration, the central administrative office for the state court system. Attackers broke into the network, copied files, and demanded a ransom, threatening to post the stolen data online if they were not paid. The LockBit ransomware group claimed responsibility.
The attack locked down court systems across the state for months. Restoration of the eCourt case management system did not begin until mid-December 2023, and full recovery took about four months. Judges and attorneys filed documents by hand while the networks were rebuilt.
What was taken
The stolen files came from appellate cases, bar applications, and other administrative records held by the office. In 2024, the state reported the breach affected roughly 150,000 people and began notifying those it could identify.
According to the state's disclosure, the exposed data could include Social Security numbers, driver's license and government ID numbers, tax identification numbers, passport numbers, payment card numbers, and health insurance information. Judges, court staff, attorneys, and members of the public whose records passed through the office were among those affected.
What this means for you
If your information moved through Kansas court systems, some of it is now outside the state's control. Data that leaks in a breach can resurface later on data broker and people-search sites, which republish home addresses, phone numbers, and relatives.
Kansas gives you a few tools for what the state itself holds. The Kansas Open Records Act lets a public agency withhold employee personnel records (K.S.A. 45-221(a)(4)), so the state does not have to release those identifying records on request. You can ask your county election officer to keep your home address off the public voter registration list (K.S.A. 25-2309(i)) when publishing it would threaten your safety. The Safe at Home program (K.S.A. 75-455) gives victims of stalking, domestic violence, sexual assault, or trafficking a substitute mailing address to use with state and local agencies.
None of those tools reach data brokers. Kansas has no equivalent of New Jersey's Daniel's Law, which lets covered public servants require brokers to take down their home address and phone number. Kansas also has no specific anti-doxxing statute. Confirm the current details of any of these programs before relying on them.
After a breach, the broker layer is the one that has to stay current, because records can reappear months later. Frontline Privacy finds those listings, files removals, and keeps checking for records that come back.
What reduces this risk
Kansas notified the people it could identify, but a breach cannot take back data that was already copied. Kansas has no equivalent of New Jersey's Daniel's Law and no specific anti-doxxing statute, so nothing in state law forces data brokers to take down a home address after it leaks. That gap is what broker removal covers. Frontline Privacy finds the listings, files removals, and keeps checking for records that come back.
Public sources
- Kansas Courts Cybersecurity Incident — Kansas Judicial Branch, 2023-10-26
- Kansas court officials confirm details of 'evil, criminal' international cyberattack — Kansas Reflector, 2023-11-21