A significant data breach at RemoteCOM, a provider of surveillance and monitoring software for the US criminal justice system, has resulted in the exposure of highly sensitive personal information belonging to nearly 14,000 individuals under court supervision. The breach, attributed to a hacker known as "wikkid," targeted RemoteCOM's proprietary SCOUT software, which is widely used by law enforcement agencies across 49 US states to monitor pretrial, probation, and parole clients. SCOUT operates as a comprehensive surveillance tool, recording keystrokes, capturing screenshots, tracking locations, and sending alerts based on specific keywords typed by monitored individuals. The leaked data was split into two main files: one containing detailed records of monitored clients, and another listing thousands of criminal justice employees who used RemoteCOM's services. The "clients" file included names, home addresses, phone numbers, email addresses, IP addresses, and specific charges or offenses, ranging from sex offenses and narcotics to terrorism, stalking, and hacking. The "officers" file exposed the names, work addresses, phone numbers, email addresses, unique IDs, and job titles of nearly 7,000 criminal justice professionals. The breach has raised concerns about the security of surveillance data, especially given the sensitive nature of the information and the potential risks to both monitored individuals and law enforcement personnel. Some records labeled clients as "tech savvy," and the data also revealed the financial burden placed on offenders, with installation and recurring monitoring fees for each device. The exposure of such detailed information could lead to threats, harassment, or violence against both clients and officers, particularly as some clients may not have been convicted but were merely under investigation or awaiting trial. The hacker described the breach as "one of the easiest" they had ever carried out, highlighting possible weaknesses in RemoteCOM's security posture. The incident has prompted calls for greater scrutiny of surveillance technology vendors and the protection of sensitive data managed by third-party providers. The leak also underscores the broader risks associated with the use of aggressive spyware-like tools in the criminal justice system. Law enforcement agencies and affected individuals now face heightened risks of doxxing, identity theft, and targeted attacks. The breach has sparked debate about the ethics and oversight of digital monitoring in the justice system, as well as the responsibilities of vendors handling such critical data. Security experts warn that the fallout from this breach could be long-lasting, with the potential for further exploitation of the leaked information by malicious actors. The incident serves as a stark reminder of the need for robust cybersecurity measures in organizations handling sensitive personal and law enforcement data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
A breach at U.S. surveillance provider RemoteCOM exposed sensitive data tied to court records and surveillance operations, reportedly affecting information connected to sex offenders, suspected terrorists, and drug dealers. The incident became public through reporting in late September 2025.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.