Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Jul 20, 2026 · 6 min read

PACER Hack Exposes Sealed Federal Court Records

Sophisticated hackers breached PACER and CM/ECF, the systems that hold every sealed indictment, warrant, and confidential informant record in the federal court system. Judge Michael Scudder told Congress the platform is unsustainable, and the judiciary just approved an $800 million overhaul to replace it.

Every sealed indictment against a suspect who has not yet been arrested. Every warrant application naming a confidential informant. Every piece of evidence a prosecutor has not yet made public. All of it lives in PACER and CM/ECF, the aging electronic systems that run the United States federal court system. Those systems have been under sustained attack, and the judge overseeing the response just told Congress they cannot be trusted to hold the line much longer.

Key Takeaways

  • Judge Michael Scudder, who chairs the Judicial Conference's technology committee, told the House Judiciary Committee on June 24, 2025 that federal courts face "waves of highly sophisticated and persistent cyber threats," according to The Record.
  • A breach first detected around July 4, 2025 hit PACER and CM/ECF directly, potentially exposing sealed indictments, warrants, and the identities of confidential informants.
  • Federal courts blocked roughly 200 million harmful cyber events in fiscal 2024 alone, and Scudder has said PACER is "unsustainable due to cyber risks" in its current form.
  • On June 26, 2026, the Judicial Conference's Executive Committee approved a $700 million to $800 million, six year modernization plan running through fiscal year 2030, funded partly by raising PACER's per page fee from 10 to 12 cents starting January 1, 2027.
  • Six pilot courts are already testing the replacement system in 2026, with all civil and criminal case files due to move into a secure cloud environment by the end of 2027, per the Administrative Office of the U.S. Courts.

What Actually Happened to PACER and CM/ECF?

PACER (Public Access to Court Electronic Records) is the public facing search tool for federal court filings. CM/ECF (Case Management/Electronic Case Files) is the backend system attorneys and court staff use to file and manage those same cases, including the sealed ones the public never sees. Together they hold essentially the entire working record of the federal judiciary.

A breach first detected around July 4, 2025 compromised parts of that infrastructure. The Administrative Office of the U.S. Courts has not publicly detailed the full scope or attributed the intrusion to a specific actor, but officials have acknowledged that highly sensitive, non public documents were likely accessed. It was not the first warning sign. Scudder separately disclosed a 2020 breach involving three "hostile foreign actors," and the judiciary has described the current threat environment as an escalation rather than an isolated incident.

Why Did a Federal Judge Warn Congress Directly?

Because the people who run the system concluded it can no longer defend itself. Scudder's June 2025 testimony to the House Judiciary Committee was unusually blunt for a sitting federal judge: he said external experts and members of his own committee had concluded PACER is "unsustainable due to cyber risks" and needs to be replaced outright, not patched. He also indicated that some cybersecurity incidents affecting the courts are too sensitive to disclose publicly at all, which is its own kind of warning.

The scale he cited is not small. Federal courts blocked approximately 200 million harmful cyber events in fiscal 2024, a volume Scudder characterized as reflecting threats of "extraordinary gravity." The Justice Department, for its part, requested $74 million in the fiscal 2026 budget specifically for a system overhaul, on top of the judiciary's own modernization funding.

Rows of sealed case file boxes in a dim federal courthouse records room with a server rack glowing faintly in the background

What Is Actually at Risk in a Sealed Court File?

This is not a generic data breach story about email addresses or credit card numbers. Sealed federal court records routinely contain the real names of confidential informants, cooperating witnesses, and undercover agents. They contain indictments against suspects who have not yet been arrested, meaning early exposure can let a target flee or destroy evidence before charges are unsealed. They contain wiretap applications, national security material, and business records companies submitted under a court's promise of confidentiality.

For journalists and activists specifically, the exposure runs both directions. Court filings are frequently where whistleblowers, leak sources, and government critics first become visible to the people investigating them, whether through a subpoena record, a sealed motion, or a witness list. A breach of the system that stores those documents is a breach of exactly the kind of record that recent contempt fights over reporters' confidential sources have shown federal courts already struggle to protect through the front door, let alone against a determined intruder coming through the back end.

How Is the Judiciary Responding in 2026?

Slowly, and expensively. In the immediate aftermath, the Administrative Office of the U.S. Courts rolled out multifactor authentication, a new identity credentials program to reduce reliance on passwords, expanded network monitoring, and closer coordination with the DOJ's National Security Division, the FBI, CISA, and the Office of the National Cyber Director.

The bigger move came on June 26, 2026, when the Judicial Conference's Executive Committee approved a modernization plan estimated at $700 million to $800 million over six years, running through fiscal year 2030, with the heaviest spending concentrated in fiscal years 2026 through 2028. To help fund it, Bloomberg Law reports PACER's fee is rising from 10 cents to 12 cents per page starting January 1, 2027, for a five year period, the first increase since 2012. Judge Robert J. Conrad Jr., director of the Administrative Office, called the increase "a last resort," saying that without it the courts could not cover the cost of a case management system secure enough to keep operating. Six pilot courts are already running the replacement system this year, and the judiciary expects all civil and criminal case files to sit in a secure cloud environment by the end of 2027.

What Should Reporters and Sources Do Right Now?

A federal case management system is not something an individual reporter or source can patch, but the exposure it creates is something they can plan around:

  • Assume that any document filed with a federal court, sealed or not, may eventually surface outside the court's control, and weigh what you put in writing accordingly.
  • If you are a source involved in litigation, ask your attorney directly whether case documents naming you have been filed under seal, and what the court's own security posture looks like for that district.
  • Journalists tracking a sealed case should build in redundancy, don't rely on a single docket alert or a single copy of a filing, since PACER access itself can be disrupted during an active incident.
  • Treat this as one data point in a broader pattern of pressure on source protection, alongside episodes like DHS's own HSIN system being breached ahead of the World Cup and federal agents tracking a private citizen for months after a single critical email.

The Bottom Line

A federal judge does not tell Congress a system is "unsustainable" lightly. PACER and CM/ECF were built for an earlier threat environment and now hold some of the most sensitive documents in government, sealed indictments, informant identities, national security material, while facing attackers the judiciary itself describes as sophisticated and persistent. The $800 million fix is coming, but not until 2027 at the earliest. Until then, anyone whose safety depends on a sealed court record staying sealed is relying on a system its own overseers have publicly said cannot be trusted to hold.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.