← DocketWise

2025 DocketWise — immigration case-management SaaS (143,480 clients; credential access in migration pipeline)

2025 143.5K records affected Share on X

Data compromised

SSNs, passports/immigration forms, fiscal/bank fields, correspondence, PHI for subset per breach summaries—investigation may widen scope

Technical writeup

Legal-tech vendor DocketWise disclosed an incident in which an unauthorized actor used valid credentials against third-party/partner-hosted repositories feeding a migration pipeline, permitting bulk copying of highly sensitive subscriber data. DocketWise launched an investigation in October 2025 and began notifying individuals in early April 2026; an initial Maine Attorney General filing cited roughly 116,000 people, but a May 2026 update raised the count to 143,480 as the review continued. SecurityWeek reported names, addresses, SSNs, driver's licenses, passport numbers, financial and medical data for immigration-law clients. DocketWise stated unauthorized access was closed and offered two years of credit monitoring; it had no evidence the data was published online at notification time.

Root cause

Credential-supported unauthorized access against partner-hosted data stores in a SaaS migration context

References