
Hundreds of North Carolinians who tried to get out of jury duty online instead had their Social Security numbers, driver's licenses and medical records exposed for anyone to find. Nearly a week after the leak came to light, the state agency that runs the court system still has not told North Carolina's Attorney General's office that a breach happened at all.
How the Leak Was Found
The problem traced back to a jury-excuse form the North Carolina Administrative Office of the Courts made available online in many counties, letting residents summoned for jury duty submit an excuse request and upload supporting documents, according to WBTV. Those uploaded files, meant to justify why someone should be excused, ended up sitting on a publicly accessible link. A person investigating the site discovered that simply changing the web address by a single number let him pull up documents other people had uploaded through the same form.
From there, the station's own digging turned up dozens of copies of driver's licenses, private employment details, Social Security numbers and medical records, all reachable by anyone who knew the trick. Among the files was a copy of a rape incident report that listed the victim's name. The exposure was described as involving the personal information of hundreds of people who had submitted jury-excuse requests.
Courts Blocked Access, But Haven't Notified the AG
The exposed material was blocked from public view only after WBTV began investigating and brought the issue to the attention of state officials, the station reported. An NCAOC spokesperson later said the agency had restricted unauthorized access to information submitted through the online jury-excusal form and described the form and its information repository as secure. But when WBTV asked whether the courts considered the incident a security breach, the NCAOC did not respond, and the agency has denied requests to interview any officials about how long the vulnerability existed or how many people's information was compromised.
Per the same account, an NCDOJ spokesperson confirmed that the Administrative Office of the Courts has not provided a breach notice to the Attorney General's office. That matters because North Carolina's Identity Theft Protection Act requires businesses and state and local governments to notify affected people when personal identifying information is exposed in a security breach, and to report qualifying breaches to the Attorney General's Consumer Protection Division as well as the three major consumer reporting agencies. The statute, laid out by the North Carolina General Assembly, says notice must go out without unreasonable delay once law enforcement determines that disclosure won't interfere with an investigation or threaten public safety.
What the Law Requires — and What's Still Unknown
The North Carolina Department of Justice notes that, beginning July 1, 2026, businesses and government agencies alike must report security breaches to both the Consumer Protection Division and the major credit bureaus. Attorney Naz Ahmed, cited in the WBTV report, wrote that the exposed information generally falls within what would require notice to the NCDOJ, though the specifics depend on more detail from the agency itself. A formal breach notice, per that reporting, may still come once an agency investigates and pins down exactly who was affected and how many people were compromised.
This is not the first time the Administrative Office of the Courts has drawn scrutiny over its digital systems. Twice in 2025, virtual web hearings in Mecklenburg County were hijacked by trolls who shared racist and pornographic material, the outlet noted. The jury-form exposure also lands amid a wider pattern flagged by TechCrunch, which identified at least a dozen juror websites built on Tyler Technologies software that appeared similarly vulnerable in states including California, Illinois, Michigan, Nevada, Ohio, Pennsylvania, Texas and Virginia. TechCrunch separately reported a 2023 flaw that exposed sealed and confidential data in some U.S. court-record systems, and found that a Texas county jury portal had leaked names, birth dates, occupations, emails, phone numbers and home addresses.
For now, the central questions in North Carolina remain open. The court system has not said whether it classifies the exposure as a security breach, whether it has notified the people whose documents were exposed, or whether it has reported the incident to the credit-reporting agencies as state law requires. The NCDOJ, for its part, says it simply hasn't received anything from the Administrative Office of the Courts yet.









