3621 W MacArthur Blvd Suite 107 Santa Ana, CA 92704
Toll Free – (844)-500-1351 Local – (714)-604-1416 Fax – (714)-907-1115

Security glitch enabled website to publish attorney discipline records, State Bar says

Rent Computer Hardware You Need, When You Need It

A public records website inadvertently published 260,000 confidential attorney discipline documents due to a security glitch within the State Bar of California’s case management system, not as a result of a malicious computer hack, officials said Monday.

The State Bar, in what was initially described as a “breach,” first discovered Friday that judyrecords.com had published the confidential documents along with about 60,000 public State Bar court cases.

The State Bar learned the documents were public after someone who had complained about an attorney told an investigator from its Office of Chief Trial Counsel about the judyrecords website. Judyrecords removed the documents on Saturday.

Judyrecords initially posted limited case profile information for approximately 260,000 nonpublic cases. The site owner has provided the State Bar with preliminary analytical data of its website traffic, showing that approximately 1,000 unique page views by the public.

“We are working closely with judyrecords to firmly identify the cases which were actually viewed,” the State Bar said in an email.

“It is now the State Bar’s belief that there was no malicious hack of its system,” the agency said in a statement. “Instead, it appears that a previously unknown security vulnerability in the Tyler Technologies Odyssey case management portal allowed the nonpublic records to be unintentionally swept up by judyrecords when they attempted to access the public records, using a unique access method. The State Bar is working with Tyler Technologies, the maker of the Odyssey system, to remediate the security vulnerability, which we believe may not be unique to the State Bar’s implementation and could impact other users of Odyssey systems.”

Tyler Technologies did not respond Monday to a request for comment.

The State Bar and judyrecords are working together to ensure that the nonpublic records are permanently purged from the site and that public records remain available.

The State Bar Court website allows the public to search for publicly available case information. However, state law requires that all attorney disciplinary investigations remain confidential until formal charges are filed and a court proceeding is initiated.

The confidential documents published by judyrecords included case number, type, status, file date and respondent and complaining witness names. Full case records were not displayed.

State Bar Executive Director Leah Wilson has apologized for the security vulnerability within the case management system.

“Our obligation and responsibility are to the respondents and witnesses whose nonpublic information may have been shared,”  she said in a statement “We thank judyrecords for quickly removing the files and look forward to similarly working expeditiously with Tyler Technologies to take the necessary steps to address this issue.”

Related Articles


U.S. Supreme Court to hear challenge to Indian Child Welfare Act


Many Jan 6 attack cases hinge on first trial’s outcome


Georgia GOP: Trump campaign directed alternate elector scheme


3 ex-officers convicted of rights violations in Floyd killing


Consultant warned of red flags with energy project years before $20 million embezzlement

Generated by Feedzy