← Blog

NC Courts Jury Form Exposed SSNs via Guessable URLs

Share on X

North Carolina's online jury excuse portal left Social Security numbers, driver's licenses, medical records, and even a rape incident report with a victim's name reachable by anyone who changed one digit in a document URL. Charlotte station WBTV confirmed the exposure in a David Hodges investigation published September 23–24, 2026, after resident Zach Duda reported the flaw and got silence until reporters called the North Carolina Administrative Office of the Courts (NCAOC).

This is a verified access-control failure on a state court webform — not a ransomware leak-site rumor. NCAOC later restricted unauthorized access and told WBTV the webform and its repository were secure after that lock-down. Officials refused interviews on how long documents sat open, how many people were in the corpus, and whether the episode counts as a notifiable security breach under North Carolina law.

BreachHistory's canonical record is at /nc-aoc/nc-aoc-jury-excuse-idor2026. If you uploaded proof for a jury excuse or deferral in North Carolina before late September 2026, treat the documents you attached as potentially viewable by strangers until you hear otherwise from the courts.

What happened on the jury excuse form

North Carolinians summoned for jury duty still get a paper notice in the mail. To ask for an excuse or deferral, many use the judicial branch's online request for jury service excuse form. The workflow asks for supporting uploads — medical notes for surgery, death certificates for bereavement, employment letters, driver's licenses, and other proof clerks want on file.

Zach Duda had used the form for his grandmother. He returned to it after his father died, uploading a death certificate while he handled the estate. The confirmation email included a link back to what he had submitted on the NC Courts site. That is where the pattern broke open.

The uploaded file lived behind a document URL. Change one digit in that address, Duda found, and another person's upload appeared. Increment again, and another. No login wall stopped him. No per-user token seemed required. The repository behaved like sequential object storage with public read access — what security teams call an insecure direct object reference, or IDOR, when identifiers are guessable and authorization is missing.

“That's where you start to reveal, you know, a pretty dangerous pattern of information. And it could be even worse if that got automated,” Duda told WBTV.

He reported the bug through NCAOC's webmaster / bug submission channel. He said he never heard back. Only after WBTV contacted the agency did the public document pages get blocked. That gap — citizen report, no reply, then rapid restriction once television producers ask questions — is part of the verified timeline.

What WBTV found when reporters walked the URLs

Hodges and the WBTV Investigates team did not need malware or stolen credentials. They did what Duda described: step the document identifiers one number at a time. Within that walk they saw dozens of driver's licenses, employment details, Social Security numbers, and medical records tied to people who thought they were talking privately to the courts.

They also found a rape incident report that listed a victim's name. That single document type reframes the story. A jury excuse upload is not just another PDF on a government site. It can be the most sensitive paper someone has ever handed a clerk — trauma documentation filed to avoid sitting in a courtroom while still recovering. Leaving that file on an enumerable URL is an exposure of identity, health, and safety data in one click.

Gwendolyn Solomon's case shows the everyday version of the same failure. She had an operation scheduled when her jury summons arrived. She used the form the way the state designed it: explain the conflict, attach the medical proof. Her private health information was among the records WBTV could open. She told reporters she had no idea that material sat on a public website. “I'm thinking it's supposed to be private,” she said. Her message to the court system: get it right and have more privacy. “We're not protected. It doesn't seem like we're protected.”

Those quotes describe the trust model the form sold. People uploaded death certificates, surgical notes, and crime reports because the judicial branch asked for them. They did not upload those files expecting sequential URLs to act like an open filing cabinet.

How the access path worked

The technical root cause, as demonstrated on air and in print, was unauthorized read access to uploaded jury-excuse documents via enumerable document URLs. Change one digit. Get the next file. No exotic exploit chain is required when the authorization check never runs.

Insecure direct object references are an old class of bug. They show up when an application stores files under incremental IDs — document 1001, then 1002 — and serves them to whoever asks. Proper designs use unpredictable identifiers, session-bound access tokens, or server-side checks that the requester is authorized to see the object. Public court websites that accept medical and identity documents need that check more than a blog comment system does.

What this is not: a claim that hackers exfiltrated a database dump, that ransomware operators listed NCAOC on a leak site, or that a census of affected residents has been published. WBTV documented that strangers could open individual uploads by walking URLs. NCAOC has not published a headcount. Until it does, readers should assume exposure for anyone who submitted supporting documents through the online excuse flow during the vulnerable window — and treat the dozens of samples WBTV reviewed as a lower bound on what was reachable, not a complete inventory.

Automation risk is obvious. If a human can step IDs by hand, a script can step thousands. Duda flagged that out loud. Neither WBTV nor NCAOC has said whether logs show bulk scraping. Absence of a published scrape report is not proof nobody automated the walk while the URLs answered.

Who is at risk

People who used the online excuse or deferral form

Anyone in North Carolina who uploaded proof to excuse or defer jury service through the NCAOC webform is in the primary risk group. That includes caregivers uploading for relatives, as Duda did for his grandmother, and people juggling estates, surgeries, or trauma recovery. The data types WBTV listed — SSNs, driver's licenses, medical records, job information, death certificates, and at least one rape incident report — map directly to identity theft, medical privacy harm, workplace exposure, and stalking risk.

Victims named in supporting police or medical paperwork

Uploads are not always about the juror alone. A death certificate names the deceased and often family. A rape incident report names a victim who may never have touched the form. Medical notes can name providers and diagnoses. Those third parties never opted in to a public document store; their identifiers rode along in someone else's upload.

Employers and clinics that issued letters

Job letters and clinic notes often include letterhead, phone numbers, and physician names. Once those PDFs are public, phishing that spoofs HR or a surgeon's office gets easier — a handful of authentic letterheads is enough.

What we still do not know

NCAOC declined WBTV interview requests about dwell time and the size of the repository. Without those answers, “was I affected?” cannot be answered with a clean roster. There is no public portal that lets a North Carolinian learn whether their upload ID was reachable. That silence is itself a consumer-protection problem under a statute that contemplates notice when personal information is subject to unauthorized access.

What NCAOC said — and what it would not say

After WBTV's outreach, NCAOC restricted unauthorized access to information submitted through the online jury excusal form. A spokesperson said the webform is secure, as is the repository of information gathered through it — phrasing that describes the post-restriction state, not a claim that nothing was ever exposed.

The agency is overseen by North Carolina Supreme Court Chief Justice Paul Newby and NCAOC Director Ryan Boyce. WBTV reported that NCAOC denied interview requests with officials who could explain how long the vulnerability existed and what investigation, if any, was underway into how many people's information was compromised.

WBTV also asked whether NCAOC considers the incident a security breach that would require notification under state law. North Carolina's security-breach framework, summarized by the state Department of Justice, is exactly the question reporters put on the table. NCAOC did not answer.

That non-answer leaves residents in a gray zone. If the agency later concludes the episode was not a “security breach” as defined in statute, affected people may never get formal letters. If it later concludes notice is required, letters may arrive months after the URLs went dark. Either way, waiting for a postcard is a weak strategy when SSNs and driver's licenses were in the sample set WBTV described.

Sector context: court tech and sensitive uploads

State court portals sit in an awkward middle ground. They are public-facing government websites, so they inherit expectations of openness. They also collect the same identity and medical documents private hospitals and banks treat as high-sensitivity. Jury excuse systems magnify that tension: the people uploading are ordinary residents trying to reschedule civic duty. Convenience features — email confirmation links, direct file URLs — become liabilities when authorization is an afterthought.

WBTV noted this was not NCAOC's first website embarrassment. Twice in 2025, virtual hearings in Mecklenburg County were hijacked by trolls who blasted racist and pornographic material into proceedings. Those incidents were about meeting-room controls, not document IDOR. Still, they sit in the same public record of judicial-branch web reliability. When an agency asks the public to trust an online form with a death certificate or a sexual-assault report, prior hearing hijacks help explain why skepticism is rational.

Nationally, 2026 has already seen large SSN and medical exposures across healthcare and finance. The NC AOC jury excuse failure is smaller in published sample size than a multi-million-record regulator filing, but sensitivity per document can be higher. A rape incident report with a victim's name is not diluted by a low count. IDOR remains a perennial web finding: sequential IDs are trivial to walk, and court upload widgets often skip per-object authorization under deadline pressure.

Timeline (what is public)

  • Before September 2026: Duda uses the online jury excuse form for family matters, notices guessable document URLs, and reports via NCAOC webmaster / bug channels. He says he receives no response.
  • September 23–24, 2026: WBTV publishes David Hodges' investigation (September 23 sister story and the September 24 update), documenting SSNs, licenses, medical records, job details, death certificates, and a rape incident report reachable by changing URL digits.
  • Within days of WBTV contact: NCAOC restricts unauthorized access to jury-excuse uploads; spokesperson says the webform and repository are secure after the restriction.
  • As of publication: NCAOC declines interviews on dwell time and census; does not answer whether the event is a notifiable security breach under state law.

No public start date for the vulnerability has been released. Readers should not assume the problem began the week WBTV called. Sequential upload IDs imply a corpus built over whatever period the form accepted attachments without access controls — potentially far longer than the news cycle.

Was this a North Carolina “security breach”?

That is the legal question NCAOC left hanging. Under North Carolina's notice rules, unauthorized acquisition of personal information that includes elements like Social Security numbers can trigger obligations to notify affected individuals and, in some cases, regulators. WBTV put that framing to the agency. The agency did not say yes. It did not say no.

For residents, the practical distinction is thin. If your SSN or driver's license image was reachable without authentication, the harm model looks like a breach even if lawyers later argue about statutory definitions. Credit monitoring offers, when they arrive, are a start — not a substitute for freezing credit and watching for medical-identity fraud.

To be clear: BreachHistory catalogs this incident as verified because WBTV's reporting and NCAOC's responsive restriction together attest that unauthorized public access existed and was then closed. Verification here does not mean NCAOC published a victim count or admitted a statutory breach. It means the exposure itself is not an unverified leak-site claim.

What you should do

If you submitted an online North Carolina jury excuse or deferral with attachments before the late-September 2026 restriction, act as if those files were readable by strangers.

  1. Inventory what you uploaded. Death certificate? Driver's license scan? Clinic letter with diagnosis codes? SSN on an ID? Write the list down. Remediation follows the most sensitive field on that list.
  2. Assume SSN exposure if any ID document went up. Place a credit freeze with Equifax, Experian, and TransUnion. Freezes beat monitoring alone. Add fraud alerts if you prefer temporary friction on new accounts.
  3. Watch driver's license misuse. Report suspected ID theft through DMV and law-enforcement channels if you see accounts or citations that are not yours. Keep copies of your jury summons and excuse confirmation emails as proof of the upload window.
  4. Treat medical and assault-related documents as high risk. If you uploaded surgical notes or police reports, tell your provider's privacy office what happened. For sexual-assault documentation, contact local victim advocates or law enforcement if you fear doxxing — do not wait for a court letter that may never come.
  5. Expect phishing that weaponizes this story. Messages that say “NCAOC needs you to re-upload your jury excuse,” “WBTV found your file — click to remove it,” or “Chief Justice Newby directs all jurors to verify documents” are classic bait. Use only bookmarks to nccourts.gov.
  6. Rotate passwords where reuse is real. This incident was about document URLs, not a password dump. Still, if you reused a courts-related password elsewhere, change it. Turn on MFA on email — attackers who saw your address on a form will try inbox takeover next.
  7. Ask NCAOC for your status in writing. Send a dated request asking whether your upload IDs were publicly reachable, whether a breach determination has been made, and whether notice is planned. Keep the reply.
  8. Employers and clinics: If you issued excuse letters on letterhead, brief staff that authentic PDFs may circulate. Warn employees not to trust “updated jury deferral” emails that ask for more PII.

Phishing and follow-on fraud to expect

Once a local TV investigation names SSNs and medical records on a jury site, scammers do not need the original PDFs — they need the headline. Expect fake “delete your file” portals, spoofed Clerk of Court calls asking for a full SSN to “keep your deferral,” and messages claiming a WBTV partner tool will check whether your death certificate was online. Real clerks do not cold-call for SSNs after a TV story. Hang up and dial the number on your original summons letter.

What was not shown

WBTV did not publish a statewide count. NCAOC did not release forensic timelines or confirmation that no bulk download occurred. Payment cards were not part of this story — it was an excuse-document repository. Stick to what was demonstrated: jury-excuse supporting documents on enumerable URLs. Until NCAOC publishes notice lists, “was I affected” stays probabilistic: if you uploaded, assume risk; if you never used the online form, this IDOR is unlikely to have touched you.

Canonical record and sources

Full BreachHistory catalog entry: North Carolina AOC jury excuse IDOR, 2026.

Primary reporting:

The North Carolina AOC jury excuse IDOR is a case study in how a civic form becomes a privacy incident: sensitive uploads, sequential URLs, an ignored bug report, and remediation that arrives after the cameras call. If you are waiting for the courts to tell you whether your death certificate or medical letter was in the open set, do not wait passively. Freeze credit, lock down identity documents, and treat unexpected “jury excuse” messages as hostile until proven otherwise.