Justice Apologizes For Iowa Court System Authorizing Security Vulnerability Testing That Led To Break-Ins

Justice Apologizes For Iowa Court System Authorizing Security Vulnerability Testing That Led To Break-Ins

At a legislative hearing Friday, court administrators answered questions about their decision to hire “penetration testers” who were arrested for burglary last month.

The chief justice of the Iowa Supreme Court publicly apologized Friday for the court system’s authorization of security vulnerability tests that led to the arrests of two Coalfire employees for courthouse break-ins. 

The state senate’s Government Oversight Committee held a hearing to hear testimony about the break-ins at the Dallas and Polk County courthouses in September. According to reporting from The Des Moines Register, the Coalfire employees were following through on a contract signed by Iowa court system officials hiring them to test the “adequacy and effectiveness” of security at government buildings. 

"In our efforts to fulfill our duty to protect confidential information of Iowans from cyberattacks, mistakes were made," Chief Justice Mark Cady said during the hearing. "We are doing everything possible to correct those mistakes, be accountable for the mistakes and to make sure they never, ever occur again." 

Now, information technology officials with the state court system say that the employees, who were able to gain access to two courthouses over the course of two nights, acted outside of the scope of the contract. 

The Iowa court administration hired the company to test for cybersecurity vulnerabilities and "did not intend, or anticipate, those efforts to include the forced entry into a building," according to a statement given to the Register last month. 

In turn, local law enforcement were not warned about the break-ins and responded to an alarm at the Dallas County courthouse as if it were a real burglary. While the two employees arrested for third-degree burglary are free and there are no proceedings scheduled for their cases, legislators and local police say that the situation was dangerous for all involved. 

Legislators will continue their investigation until more facts are gathered, according to Sen. Amy Sinclair, the chair of the committee.  

"It is outside the scope of the judicial branch to authorize individuals to illegally break into facilities that they neither own nor provide security for," she told the Register. 

Todd Nuccio, the state court administrator, said that the contract had not been reviewed by a legal team and that oversight steps will be considered in the future, according to the Register. Sen. Claire Celsi told the Register that the court’s shrinking budget may have played a role, leading to them signing the contract and take the most “efficient” route. 

"It’s faintly disturbing that a contract of this magnitude was allowed to move forward without further review from someone higher up the food chain maybe," Celsi said. 

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • Securing the Future

    Two security experts sit down with Security Today’s editor in chief Ralph C. Jensen to discuss what they see emerging and changing over the next several years along with how security stakeholders can harness these innovations into opportunities. Read Now

  • Collaboration Made Easy Using a Work Management Platform

    Effective collaboration between security operators, teams and other departments is critical to the smooth functioning of organizations. Yet, as organizations grow in complexity, it becomes more difficult for teams to coordinate with each other. This is compounded by staffing shortages, turnover and ineffective collaboration tools. Read Now

  • Creating a Safer World

    Managing and supporting locks and door hardware within a facility is a big responsibility. A building’s security needs to change over time as occupancy and use demands evolve, which can make it even more challenging. Read Now

  • Report: 78 Percent of CISOs Seeing Significant Impact from AI-Powered Cyber Threats

    Darktrace recently unveiled its 2025 State of AI Cybersecurity report. The findings reveal that 78% of Chief Information Security Officers (CISOs) surveyed say that AI-powered threats are having a significant impact on their organizations, a 5% increase1 from 2024. While an increasing number of CISOs report feeling a significant impact from AI threats, more than 60% now say that they are adequately prepared to defend against these threats, an increase of nearly 15% year-over-year. However, insufficient AI knowledge and skills and a shortage of personnel and talent continue to be listed as the two top inhibitors to a successful defense. Read Now

New Products

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge.