Kansas officials blame 5-week disruption of court system on ‘sophisticated foreign cyberattack’
Advertisement
Read this article for free:
or
Already have an account? Log in here »
To continue reading, please subscribe:
Digital Subscription
One year of digital access for only $205*
- Enjoy unlimited reading on winnipegfreepress.com
- Read the E-Edition, our digital replica newspaper
- Access News Break, our award-winning app
- Play interactive puzzles
*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.
To continue reading, please subscribe:
Add Free Press access to your Brandon Sun subscription for only an additional
$1 for the first 4 weeks*
- Enjoy unlimited reading on winnipegfreepress.com
- Read the E-Edition, our digital replica newspaper
- Access News Break, our award-winning app
- Play interactive puzzles
*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.
Read unlimited articles for free today:
or
Already have an account? Log in here »
Hey there, time traveller!
This article was published 21/11/2023 (1043 days ago), so information in it may no longer be current.
MISSION, Kan. (AP) — Cybercriminals hacked into the Kansas court system, stole sensitive data and threatened to post it on the dark web in a ransomware attack that has hobbled access to records for more than five weeks, officials said Tuesday.
The announcement of a “sophisticated foreign cyberattack” was confirmation of what computer security experts suspected after the state’s Judicial Branch said Oct. 12 that it was pausing electronic filings. Until now, state officials had released few details, describing it simply as a “security incident.”
Upon learning about the attack, the state disconnected its court information system from external access and notified authorities, the Judicial Branch said in a statement. That disrupted daily operations of the state’s appellate courts and all but one county. Johnson County, the state’s most populous, operates its own computer systems and had not yet switched over to the state’s new online system.
In recent weeks many attorneys have been forced to file motions the old fashioned way — on paper.
“This assault on the Kansas system of justice is evil and criminal,” the statement said. “Today, we express our deep sorrow that Kansans will suffer at the hands of these cybercriminals.”
A preliminary review indicates that the stolen information includes district court case records on appeal and other potentially confidential data, and those affected will be notified once a full review is complete, the statement said.
Analyst Allan Liska of the cybersecurity firm Recorded Future said no ransomware group leak site has published any information yet.
Judicial Branch spokesperson Lisa Taylor declined to answer questions including whether the state paid a ransom or the name of the group behind the attack, saying the statement stands on its own.
If organizations don’t pay a ransom, data usually begins to appear online within a few weeks, said analyst Brett Callow of the cybersecurity firm Emsisoft. Victims that pay get a “pinky promise” that stolen data will be destroyed, but some are extorted a second time, he said.
In the weeks since the Kansas attack, access to court records has only partially been restored. A public access service center with 10 computer terminals is operating at the Kansas Judicial Center in Topeka.
The Judicial Branch said it would take several weeks to return to normal operations, including electronic filing, and the effort involves “buttressing our systems to guard against future attacks.”
A risk assessment of the state’s court system, issued last year, is kept “permanently confidential” under state law. But two recent audits of other state agencies identified weaknesses. The most recent one, released in July, said “agency leaders don’t know or sufficiently prioritize their IT security responsibilities.”