Stack of passports and travel documents on a wooden surface
Photo via Unsplash

TL;DR: DocketWise, a cloud-based immigration case management platform used by thousands of law firms across the US, disclosed on April 3, 2026, that hackers breached its systems and stole data belonging to 116,666 people. The stolen data includes Social Security numbers, passport numbers, driver’s licenses, financial account details, medical records, and tax IDs. The breach happened in October 2025 when attackers used valid credentials to clone repositories containing unstructured client data from immigration law firms. DocketWise waited roughly six months to start notifying victims. Multiple class action investigations are underway. If your immigration attorney used DocketWise, your most sensitive documents may be in the hands of attackers.

Your Immigration Lawyer’s Software Got Hacked

DocketWise markets itself as the go-to platform for immigration attorneys. Form preparation, case management, client communications, all in one cloud-based system. Thousands of immigration law firms trust it with their clients’ case files.[1]

Those case files contain everything an identity thief could want. Immigration cases require applicants to hand over their Social Security numbers, passport details, financial records, employment histories, and sometimes medical information. It’s the kind of data that’s nearly impossible to change and permanently damaging when stolen.

In October 2025, DocketWise discovered that login credentials to one of its third-party partner repositories had been compromised. An unauthorized actor used those valid credentials to clone repositories that were part of a data migration pipeline for the DocketWise application.[2] Those repositories contained unstructured data belonging to law firm customers, including personal information of the firms’ clients.

Translation: a hacker walked in through a side door using stolen keys, copied entire databases of immigration case files, and walked out.

What Was Stolen

The data exposed varies by individual, but the full list reads like a guide to destroying someone’s financial life:[2][3]

  • Social Security numbers
  • Passport numbers
  • Driver’s license numbers
  • Dates of birth
  • Financial account numbers and credentials
  • Payment card numbers and access information
  • Government and tax identification numbers
  • Health insurance policy numbers
  • Medical condition and treatment information
  • Usernames and access credentials for various accounts

For immigrants, this data carries extra weight. A stolen passport number combined with a Social Security number and immigration case details gives attackers a complete profile. Identity theft is devastating for anyone. For someone navigating the US immigration system, it can mean delayed cases, denied applications, or worse: a stolen identity used to commit fraud that gets flagged under their name.

Six Months of Silence

DocketWise says it discovered the breach in October 2025. The company didn’t file a breach notification with the Maine Attorney General until April 3, 2026, roughly six months later.[2] Consumer notifications started going out the same day.

Six months. In that time, 116,666 people had no idea their Social Security numbers and passport details were circulating in the hands of unknown attackers. Six months of potential identity fraud with zero warning.

DocketWise says it conducted a “detailed review of the affected data” during that period. That’s the standard excuse. Every breached company says the investigation took time. But six months between discovery and notification means half a year where victims couldn’t freeze their credit, monitor their accounts, or take any protective action.

The Immigration Data Problem

This breach sits at a dangerous intersection. Immigration attorneys handle some of the most sensitive personal data that exists. Their clients (visa applicants, asylum seekers, green card holders, people seeking citizenship) are required by the US government to hand over virtually every piece of identifying information they possess.

That data gets stored in case management software like DocketWise. And the people whose data was stolen are a particularly vulnerable population. Many may not have strong credit monitoring in place. Some may not speak English fluently enough to navigate the breach notification process. Others might be afraid to draw attention to themselves by filing fraud complaints, especially in the current immigration enforcement climate.

With ICE ramping up surveillance operations and building an $8.5 billion surveillance arsenal, the last thing immigration applicants need is their personal data floating around in hacker forums. There’s no evidence this breach is connected to government surveillance, but the exposure creates real risk for people already under heightened scrutiny.

Class Actions Are Coming

At least two law firms have launched class action investigations. Edelson Lechtzin LLP filed a breach investigation notice on April 6, describing the breach as a “significant data security incident” affecting immigration professionals and their clients.[3] Shamis & Gentile P.A. is also investigating potential claims.[4]

The legal question centers on DocketWise’s duty of care. When thousands of law firms trust a single platform with their clients’ immigration data, that platform has an enormous responsibility to secure it. Storing sensitive migration pipeline data in repositories accessible with a single set of stolen credentials raises serious questions about DocketWise’s security architecture.

What to Do If You’re Affected

If you’ve used an immigration attorney in the US in recent years, check whether your firm used DocketWise. Here’s what to do:

  • Check your mail. DocketWise began sending breach notification letters on April 3, 2026. If you received one, act immediately.
  • Enroll in free credit monitoring. DocketWise is offering 24 months of credit monitoring and identity restoration through IDX. The enrollment deadline is July 3, 2026. Call 1-844-890-7449 (Monday–Friday, 9 AM–9 PM ET) for help.[2]
  • Freeze your credit. Don’t just monitor it. Freeze it. Contact all three bureaus: Equifax, Experian, and TransUnion. It’s free and takes minutes.
  • Monitor your immigration case. Check USCIS case status regularly at egov.uscis.gov for any unauthorized changes or filings.
  • File an IRS Identity Protection PIN. With your SSN exposed, tax identity theft is a real risk. Get an IP PIN at irs.gov.
  • Watch for phishing. Attackers who have your personal details will craft convincing scam emails and calls. Be skeptical of any communication claiming to be from your law firm, USCIS, or DocketWise.

A Pattern That Won’t Stop

DocketWise is the latest in a string of breaches hitting organizations that hold especially sensitive data about vulnerable populations. Government contractor Conduent exposed 26 million Americans’ Medicaid records. Benefits administrator Navia lost data on 2.7 million people. And now the software that immigration attorneys rely on to protect their clients has failed those clients.

The common thread: companies that hold the most sensitive data often have the weakest security. When your business model involves storing Social Security numbers, passport details, and medical records for a vulnerable population, “valid credentials were compromised” isn’t an explanation. It’s an indictment.

References

  1. DocketWise: Immigration Law Firm Software
  2. ClaimDepot: DocketWise Data Breach Affects 116k People, Exposing SSNs
  3. GlobeNewsWire: Edelson Lechtzin LLP Investigates DocketWise Data Breach (April 6, 2026)
  4. DataBreaches.net: Two Data Security Incidents Affected Immigration Law Firms (April 6, 2026)
  5. Murphy Law Firm: DocketWise Data Breach: Protecting Your Information