2025 DocketWise — immigration case-management SaaS (143,480 clients; credential access in migration pipeline)
Data compromised
SSNs, passports/immigration forms, fiscal/bank fields, correspondence, PHI for subset per breach summaries—investigation may widen scope
Technical writeup
Legal-tech vendor DocketWise disclosed an incident in which an unauthorized actor used valid credentials against third-party/partner-hosted repositories feeding a migration pipeline, permitting bulk copying of highly sensitive subscriber data. DocketWise launched an investigation in October 2025 and began notifying individuals in early April 2026; an initial Maine Attorney General filing cited roughly 116,000 people, but a May 2026 update raised the count to 143,480 as the review continued. SecurityWeek reported names, addresses, SSNs, driver's licenses, passport numbers, financial and medical data for immigration-law clients. DocketWise stated unauthorized access was closed and offered two years of credit monitoring; it had no evidence the data was published online at notification time.
Root cause
Credential-supported unauthorized access against partner-hosted data stores in a SaaS migration context
References
- https://www.docketwise.com/data-incident/
- https://www.securityweek.com/docketwise-data-breach-impacts-143000/
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/5d299575-817a-40f1-88bf-d7146e8e0c1d.html
- https://www.classaction.org/data-breach-lawsuits/docketwise-april-2026
- https://oag.ca.gov/system/files/DocketWise%20-%20California%20AG%20Notice%20and%20Consumer%20Notification%20Letter_0.pdf