Close-up of a padlock resting on a computer keyboard in dim lighting
Photo via Unsplash

TL;DR: DocketWise, a cloud-based immigration case management platform used by thousands of US law firms, disclosed that hackers breached its systems in October 2025 using stolen credentials. The attackers cloned repositories containing passport numbers, Social Security numbers, medical records, financial data, and login credentials for 116,666 immigration clients. DocketWise waited until April 3, 2026 -- over five months -- to notify affected individuals. Multiple law firms have launched class action investigations. In an era of aggressive ICE enforcement, having 116,000 immigration clients' most sensitive data floating around the dark web isn't just a privacy nightmare. It's a safety one.

Five Months of Silence

Sometime in October 2025, DocketWise -- the self-described "#1 rated all-in-one immigration software" -- discovered that someone had broken into its systems.[1]

The attackers used valid credentials to access third-party partner repositories. These weren't random files. They were part of DocketWise's data migration pipeline -- the plumbing that moves client information through the system. The repositories contained unstructured data belonging to law firm clients and their customers.[2]

DocketWise says it launched an investigation with third-party cybersecurity experts. They notified the FBI. They "secured their systems."

Then they went quiet for five months.

On April 3, 2026, DocketWise finally started sending notification letters to the 116,666 people whose data had been sitting in an attacker's hands since autumn. The company filed breach disclosures with attorneys general in California, Maine, Massachusetts, and Vermont.[3]

Five months. If someone stole your passport, your Social Security number, and your medical records in October, would you want to know about it in April?

Everything. They Got Everything.

This isn't a "names and email addresses" breach. The stolen data reads like a checklist for identity destruction:[2][3]

  • Full names and addresses
  • Social Security numbers
  • Dates of birth
  • Passport numbers
  • Driver's license numbers
  • Government identification numbers
  • Tax identification numbers
  • Financial account numbers and credentials
  • Payment card numbers
  • Health insurance policy numbers
  • Medical condition and treatment information
  • Usernames and passwords for both financial and non-financial accounts

Immigration case files are among the most sensitive documents in existence. They contain everything: where you were born, where you live, how much money you have, what medical conditions you carry, and -- critically -- your legal status in the country.

Thousands of immigration attorneys trusted DocketWise with this information. DocketWise trusted its third-party partners with the same data. Those partners got breached. The trust chain snapped at its weakest link.

The ICE Enforcement Problem Nobody's Talking About

Here's what makes this breach different from yet another corporate hack.

ICE has arrested roughly 400,000 people since January 2025. Two-thirds of those arrests involved people with no criminal convictions.[4] The agency is pivoting from visible raids to surveillance-driven enforcement -- using ALPR networks, Palantir's ImmigrationOS, facial recognition, and social media monitoring to identify and locate targets.

Now imagine 116,000 immigration clients' complete case files in the wrong hands. Names, addresses, immigration case details, which law firm they use. For people with pending applications, asylum cases, or undocumented family members, this breach doesn't just risk identity theft. It risks their safety.

Immigration files create what security researchers call "concentrated identity profiles" -- single repositories containing enough data to reconstruct someone's entire legal, financial, and medical identity. In the hands of a fraudster, that's identity theft. In the hands of someone with an agenda, it's a targeting database.

DocketWise's own blog, ironically, has published articles about how sanctuary cities are preparing for deportation. Meanwhile, the company's own security failures may have created exactly the kind of data exposure that puts those same communities at risk.

Stolen Credentials and the Supply Chain Problem

The attackers didn't hack through a firewall. They walked in the front door.

DocketWise's breach notification states that "an unauthorized actor used valid credentials to clone certain third-party partner repositories." Those repositories were part of a data migration pipeline for the DocketWise application and "contained unstructured data belonging to law firm clients and their customers."[1][2]

Translation: Someone's login got compromised. That login had access to repositories full of raw client data. The attacker copied everything.

This is the supply chain problem that keeps hitting healthcare and legal tech. You can lock down your own systems, but if a third-party partner stores your clients' passport numbers in a repository accessible with a single set of credentials -- your security is only as strong as that partner's weakest employee.

We saw the same pattern with the Adobe breach via an Indian BPO contractor. And with the Axios npm supply chain attack by North Korean hackers. Third-party access is the skeleton key attackers keep reaching for. Companies keep handing it out.

Five Months Is Indefensible

DocketWise discovered the breach in October 2025. Notifications went out April 3, 2026.[3]

That's over five months where 116,666 people had no idea their passports and Social Security numbers were compromised. Five months where they couldn't freeze their credit, monitor their accounts, or take any protective action.

State breach notification laws vary, but most require notification within 30 to 90 days. California requires notification "in the most expedient time possible." Maine requires 30 days. Massachusetts requires notification "as soon as practicable and without unreasonable delay."[5]

Multiple law firms think DocketWise crossed the line. Schubert Jonckheer & Kolbe LLP in San Francisco launched a class action investigation within days of the notifications going out. So did Shamis & Gentile. And Bryson Harris Suciu & DeMay. Edelson Lechtzin LLP is also investigating.[5][6]

The legal theory is straightforward: DocketWise allegedly violated state and federal notification laws by sitting on this breach for half a year while affected individuals were unknowingly exposed to identity theft and fraud.

What to Do If You're Affected

DocketWise is offering 24 months of credit monitoring and identity restoration through IDX. The enrollment deadline is July 3, 2026. Here's the number: 1-844-890-7449 (Monday-Friday, 9am-9pm ET).[3]

But don't stop there. If your immigration case data was in DocketWise's system:

  • Freeze your credit immediately at all three bureaus (Equifax, Experian, TransUnion). This is free and prevents anyone from opening accounts in your name.
  • Contact your immigration attorney. Ask them directly whether your data was stored in DocketWise and whether it was affected. Don't wait for a notification letter -- they can tell you now.
  • Monitor your immigration case. Watch for any unauthorized filings, address changes, or status changes on your case through USCIS.
  • File an IRS Identity Protection PIN. With your SSN and tax ID compromised, fraudulent tax filings are a real risk. Get an IP PIN at irs.gov.
  • Change passwords for any accounts that used the same credentials as your DocketWise-connected law firm portal.
  • Watch for targeted scams. Attackers now know you use an immigration attorney. Expect phishing emails impersonating your law firm, USCIS, or DocketWise itself. Do not click links in unsolicited emails about your "case status."

The Healthcare-Legal Data Breach Epidemic

DocketWise joins a growing list of platforms that hold deeply personal data getting breached in 2026. The HIPAA breach count hit 301 million records across 735 filings. CareCloud's EHR systems were breached for eight hours. Conduent's breach now affects 25 million Americans.

The pattern is the same every time: a company that holds your most sensitive data gets breached through a third party, waits months to tell you, offers two years of credit monitoring, and faces a class action suit that settles for pennies per victim.

For immigration clients, the stakes are higher. A breached medical record is bad. A breached immigration file -- with your legal status, your home address, your family's information, and your asylum claim details -- can be weaponized in ways that go far beyond financial fraud.

References

  1. GBlock - "DocketWise Breach Exposed 116,000 Immigration Clients' Most Sensitive Data"
  2. ClaimDepot - "DocketWise Data Breach Affects 116k People, Exposing SSNs"
  3. PR Newswire - "PRIVACY ALERT: DocketWise Under Investigation for Data Breach of Over 116,000 Records"
  4. Washington Post - "ICE Still Arrests Many Immigrants With No Criminal Record" (April 3, 2026)
  5. Schubert Jonckheer & Kolbe - "DocketWise Under Investigation for Data Breach"
  6. PR Newswire - "Edelson Lechtzin LLP Investigates DocketWise Data Breach"

Published April 10, 2026 | By the State of Surveillance team