DocketWise, a case management platform used by U.S. immigration attorneys, disclosed a breach affecting 116,666 individuals after threat actors gained unauthorized access to credentials for a third-party partner instance and used valid credentials to clone repositories in a data migration pipeline containing unstructured customer data. The exposed information varied by person but may have included Social Security numbers, tax IDs, passport and driver’s license numbers, dates of birth, financial and payment data, medical information, health insurance details, and account credentials. DocketWise told Maine regulators it had no evidence the incident specifically targeted immigration firms or that the data had been publicly released.
The breach affected clients of five named law firms and added to concerns over data handling in the immigration legal sector. Separate reporting also highlighted a recent exposure involving a misconfigured Amazon bucket tied to Dalbir Singh and Associates, PC in New York City, which reportedly left about 111,000 immigration-related files accessible until it was secured after repeated outreach. Together, the incidents exposed highly sensitive records belonging to immigration law firms and their clients.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
News reports publicly disclosed the DocketWise breach, describing it as a cyber attack impacting more than 116,000 individuals who were clients of immigration law firms using the platform. This reporting brought broader attention to the scale of the incident.
A misconfigured Amazon S3 bucket tied to Dalbir Singh and Associates, PC reportedly exposed about 111,000 immigration-related files. The bucket remained accessible until it was secured after repeated outreach, indicating a separate incident from the DocketWise breach.
DocketWise notified the Maine Attorney General's Office on April 3 about the breach, reporting 116,666 affected individuals across five law firm customers, including 13 Maine residents. The company said it had no evidence the incident specifically targeted immigration firms or that the data had been publicly released.
In the DocketWise incident, unauthorized access to credentials for a third-party partner instance allowed threat actors to use valid credentials to clone repositories in a data migration pipeline containing unstructured customer data. Exposed data may have included highly sensitive personal, financial, medical, and identity documents.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.