Kansas court system down nearly 2 weeks in 'security incident' that has hallmarks of ransomware

This photo shows that a computer terminal normally used by the public to access Kansas court records has been shut down, Wednesday, Oct. 25, 2023, at the Shawnee County Courthouse in Topeka, Kansas. Most of the state's courts have been offline since Oct. 12, 2023, in what officials are calling a "security incident" that experts say has all the hallmarks of a ransomware attack. (AP Photo/John Hanna)

TOPEKA, Kan. (AP) 鈥 Kansas officials are calling a massive computer outage that鈥檚 kept most of the state鈥檚 courts offline for two weeks a 鈥渟ecurity incident鈥 and, while they had not provided an explanation as of Wednesday, experts say it has all the hallmarks of a ransomware attack.

The disruption has left attorneys unable to search online records and forced them to file motions the old fashioned way 鈥 on paper. Courts are limping along, although the growing piles of paper are a mess that will have to be sorted and scanned eventually.

鈥淚t's really just slowed the whole system down," said Chris Joseph, a Lawrence-based criminal defense attorney.

Since 2019, ransomware groups have targeted 18 state, city or municipal court systems, said analyst Allan Liska of the cybersecurity firm Recorded Future. That includes one in , where some jury trials had to be canceled this year.

But state-focused attacks have been much less frequent, and have not yet rivaled what is happening in Kansas.

鈥淲e are treating this matter with the highest priority,鈥 Lisa Taylor, the Judicial Branch's spokesperson, said in an email Wednesday.

Liska noted Tuesday that a short-lived attack in 2019 in shut down some court and forced some court dates to be rescheduled. A cybersecurity threat forced offline for about a week in 2021. top criminal and civil courts were hit with a ransomware attack in 2020 but the filing system remained operational and trial courts weren't affected.

In Kansas, came on Oct. 12 when the state's Judicial Branch announced a pause in electronic filings because of a 鈥渟ecurity incident." The details released since have been sparse.

Taylor said only that an investigation is ongoing in response to questions of whether the courts had determined that this was a malicious attack, whether there鈥檚 been a demand for a ransom or when the systems will be back up. The court system has set up a website dealing with the incident, and Taylor said its officials will cooperate with any law enforcement investigation.

The Kansas Bureau of Investigation said only that is is 鈥渆ngaged鈥 in examining the problems, along with 鈥渇ederal partners,鈥 said spokesperson Melissa Underwood.

No ransomware group has come forward to claim credit for the prolonged outage, analysts said. But Liska said it is 鈥渉ighly unlikely鈥 that this is anything but a ransomware attack.

鈥淭he fact that they鈥檙e calling it a cyber incident says that it鈥檚 nefarious,鈥 Liska said.

Notably spared was Johnson County in the Kansas City area, the state鈥檚 most populous county. It operates its own computer systems and had not yet switched over to the state's new online court system.

The effort to switch to a single, statewide system for tracking and managing cases started in 2018 under a 10-year, $11.5 million contract with Dallas-based Tyler Technologies. Tyler, which has similar contracts in around a dozen other states, referred questions to state court officials.

States have been moving toward statewide systems for more than a decades. On the security front, there are pros and cons, said analyst Brett Callow of the cybersecurity firm Emsisoft.

鈥淥n the pro side, economies of scale mean more resources should be able to be committed to protecting and securing that system," he said. "On the con side, when an attack does succeed ... it鈥檚 going to knock out the entire state system rather than simply an individual county or municipality.鈥

Additionally, if security is not adequately built in during the rollout, systems can be more vulnerable, Liska said.

A risk assessment of the state's court system, issued last year, is kept 鈥減ermanently confidential鈥 under state law. But two recent audits of other state agencies identified weaknesses. The most recent one, released in July, said that 鈥渁gency leaders don鈥檛 know or sufficiently prioritize their IT security responsibilities.鈥

With the system down, courts haven鈥檛 been able to accept electronic filings, process payments, manage cases, grant public access to records, allow people to file electronically for protection-from-abuse orders and to apply electronically for marriage licenses.

In Sedgwick County, home to the state鈥檚 largest city of Wichita, Judge Phil Journey said Wednesday that although he is known as a 鈥渢echie鈥 judge, he鈥檚 still maintained extensive paper files. That's allowing him to move forward with his family law cases. But, he said, other judges who were more reliant on digital files are faced with postponing trials.

鈥淎ll I know is that we鈥檙e on paper for at least another week,鈥 he said. 鈥淲e鈥檒l be killing a lot of trees.鈥

In Wyandotte County, also in the Kansas City area, the outage has caused some delays, but trials are proceeding, said Jonathan Carter, a spokesman for the district attorney鈥檚 office. A massive ransomware attack last year in the county crippled key services, including the court system. Whether that is related to what is happening now is unclear.

Meanwhile, older attorneys are finding their skills in high demand, as they teach younger attorneys to use faxes and file with paper, said Karla Whitaker, interim executive director of the Kansas Bar Association.

鈥淭he wheels of justice are turning,鈥 she said Wednesday. 鈥淏ut I think it鈥檚 just happening in a different way at a different pace right now.鈥

___

Hollingsworth reported from Mission, Kansas.

The 春色直播 Press. All rights reserved.

More Science Stories

Sign Up to Newsletters

Get the latest from 春色直播News in your inbox. Select the emails you're interested in below.