The Federal Courts Have a Trust Problem — And PACER Is Only Part of It

Here’s something that deserves far more attention than it has received.

The cybersecurity attacks against the federal judiciary’s electronic case-management infrastructure are not merely an IT story.

They are a trust story.

And more than a year after the judiciary publicly acknowledged sophisticated and persistent attacks against its case-management system, we now have an extraordinary admission from the judiciary itself.

On September 17, 2026, the Administrative Office of the U.S. Courts announced that it is fast-tracking what it calls a “fundamental redesign” of the Case Management/Electronic Case Files system — CM/ECF.

Why?

Because, in the judiciary’s own words, the existing system has become “outdated and vulnerable to security breaches.” (United States Courts)

Read that sentence again.

This isn’t some critic of the federal courts saying it.

The federal judiciary is saying it.

PACER Is the Window. CM/ECF Is the Machinery Behind It.

There has been understandable shorthand describing this as the “PACER breach,” but the distinction matters.

PACER — Public Access to Court Electronic Records — is the system through which the public accesses federal court records. The judiciary says PACER provides access to more than one billion documents filed in federal courts. CM/ECF is the case-management and electronic-filing system courts use to maintain electronic case files. (PACER)

And the security problem involves the judiciary’s case-management infrastructure.

In August 2025, the Administrative Office publicly acknowledged “escalated cyberattacks of a sophisticated and persistent nature” against the judiciary’s case-management system and announced additional measures to protect sensitive documents. (United States Courts)

The response went beyond changing a few passwords.

Courts implemented new protections for sealed documents. In at least some courts, sealed and restricted documents were removed from electronic accessibility through CM/ECF and PACER under a Sealed Document Security program. (U.S. Court of Appeals for the DC Circuit)

Multifactor authentication was also rolled out for CM/ECF users — the same kind of additional credential security that ordinary Americans have been told for years is essential to protecting sensitive accounts. (PACER)

Now, in September 2026, the judiciary says the underlying system needs a fundamental redesign.

That progression should concern everyone.

Because federal court records aren’t abstractions.

They involve criminal defendants, civil litigants, victims, businesses, proprietary information, personal information and documents capable of profoundly affecting people’s lives.

Most court documents are intentionally public. Sealed documents are not publicly available through PACER. But the judiciary’s own security response demonstrates that protecting restricted and sensitive material inside the larger case-management environment has become a serious concern. (PACER)

And for me, none of this is theoretical.

I Have Seen the Power of This System Up Close

My daughter, Jennifer Kowalski, navigated the federal courts as a pro se litigant in Prudential Insurance Company of America v. Kowalski in the District of Connecticut.

I watched that case unfold not as a lawyer looking at a docket from a comfortable distance, but as a father.

And what I witnessed permanently changed the way I view judicial power.

In 2024, U.S. District Judge Victor Bolden ordered that Jennifer provide account credentials and cooperate with multifactor authentication so that the discovery vendor Epiq could search three cloud-storage accounts. When she did not comply, the court ordered that she could be remanded to the custody of the U.S. Marshals and civilly confined until she complied. (Justia Law)

On September 3, 2024, that is what happened.

The court’s later ruling confirms that after Jennifer declined to provide the requested login and multifactor-authentication credentials at a compliance hearing, she was placed in civil confinement. The court released her the following day after determining confinement had not produced compliance. (Justia Law)

She wasn’t serving a criminal sentence.

This arose from a civil discovery dispute.

You can agree with the court’s legal reasoning or disagree with it.

But you cannot seriously look at that episode and claim that the power of the federal judiciary is some academic question.

When a federal judge can order a citizen taken into custody over compliance with a discovery order involving passwords and cloud accounts, judicial power becomes very real, very quickly.

And enormous power requires enormous accountability.

Then I Began Questioning the Record Itself

As I examined the proceedings surrounding my daughter’s case, I developed concerns about discrepancies involving transcripts and the accuracy of portions of the official record.

I considered those concerns serious enough to pursue through the judicial misconduct process.

I want to be precise here: those concerns are my allegations and my interpretation of what I found. They should not be presented as an independently established finding that court transcripts were improperly altered.

But that distinction doesn’t diminish the larger issue.

It reinforces it.

Citizens must have a meaningful mechanism for raising questions about the integrity of judicial records and receiving answers worthy of the institution involved.

Because the record is everything.

Orders.

Filings.

Transcripts.

Evidence.

Docket entries.

The entire appellate process ultimately depends upon confidence that what appears in the official record accurately reflects what occurred.

Without that confidence, trust collapses.

The Courts Demand Precision From Us

Here’s where the hypocrisy question becomes unavoidable.

Federal courts demand extraordinary precision from everyone appearing before them.

Miss a deadline and there can be consequences.

Ignore an order and there can be consequences.

Fail to comply with discovery and, as my family learned firsthand, the consequences can become severe.

Federal litigants are expected to understand complicated procedural requirements, meet deadlines and comply with court orders.

Fine.

That’s how a serious judicial system operates.

But seriousness cannot travel in only one direction.

There cannot be one standard of accountability for the citizen standing before the bench and another for the institution sitting behind it.

If the federal judiciary expects meticulous compliance from everyone else, Americans are entitled to expect meticulous stewardship of the systems containing the records upon which justice depends.

And the judiciary has now acknowledged that its existing case-management system became outdated and vulnerable enough that a fundamental redesign is necessary. (United States Courts)

That deserves considerably more public discussion than it has received.

Judicial Independence Is Not Judicial Immunity From Scrutiny

Federal judges enjoy extraordinary independence for an important reason.

Justice should not change according to election cycles, political pressure or whoever happens to be shouting loudest outside the courthouse.

That independence is one of the foundations of our constitutional system.

But somewhere along the way, we have become reluctant to make an equally important distinction:

Judicial independence and judicial accountability are not opposites.

We need both.

Courts scrutinize executive agencies.

Courts scrutinize corporations.

Courts scrutinize police departments.

Courts scrutinize attorneys.

Courts scrutinize ordinary citizens.

Then citizens have every right to scrutinize the courts.

That isn’t an attack on the judiciary.

That’s accountability.

Don’t Tell Americans to “Trust the System”

My family’s experience has made me deeply skeptical whenever someone responds to legitimate institutional questions with four words:

Trust the system.

No.

Trust isn’t something government gets to demand.

Trust is earned.

It is earned through transparency.

It is earned through accurate records.

It is earned through meaningful oversight.

It is earned by acknowledging failures instead of minimizing them.

And it is earned by demonstrating that the rules apply just as seriously to the institution exercising power as they do to the citizen subjected to it.

The federal judiciary deserves credit for acknowledging the cybersecurity problem and moving toward a redesigned case-management system.

But modernization cannot simply mean better software.

It should also mean better accountability.

Congress and the judiciary should continue asking difficult questions about how sensitive judicial information is protected, who bears responsibility when safeguards fail, how restricted information is segregated, how breaches are investigated and disclosed, and whether existing oversight mechanisms remain adequate for a federal judiciary increasingly dependent upon digital infrastructure.

Because the real question isn’t whether someone can build a more secure version of CM/ECF.

Of course we can.

The real question is whether we are willing to apply the same principle to the institution itself.

The Comfortable Should Be Uncomfortable

The judiciary’s September announcement gives us an opportunity.

Build the new system.

Use modern cybersecurity.

Protect sensitive records.

Modernize the technology.

But don’t stop there.

Modernize the thinking about accountability as well.

Because a justice system ultimately runs on something no server can manufacture and no software update can install:

Public trust.

Once citizens begin questioning the integrity of the record, the security of the system or whether meaningful mechanisms exist to challenge the institution itself, replacing outdated technology solves only part of the problem.

The cyberattacks exposed weaknesses in the federal judiciary’s technological infrastructure.

The judiciary has now acknowledged that much.

What happens next will tell us something considerably more important:

Whether the institution is as willing to examine itself as it is to examine everyone who stands before it.

Judicial independence is essential.

So is judicial accountability.

Americans should never be asked to choose between the two.

To comfort the afflicted … and afflict the comfortable.

Published by Ed Kowalski

Ed Kowalski is a Pleasant Valley resident, media voice, and policy-focused professional whose work sits at the intersection of law, public policy, and community life. Ed has spent his career working in senior leadership roles across human resources, compliance, and operations, helping organizations navigate complex legal and regulatory environments. His work has focused on accountability, risk management, workforce issues, and translating policy and law into practical outcomes that affect people’s jobs, livelihoods, and communities. Ed is also a familiar voice in the Hudson Valley media landscape. He most recently served as the morning host of Hudson Valley This Morning on WKIP and is currently a frequent contributor to Hudson Valley Focus with Tom Sipos on Pamal Broadcasting. In addition, Ed is the creator of The Valley Viewpoint, a commentary and narrative platform focused on law, justice, government accountability, and the real-world impact of public policy. Across broadcast and written media, Ed’s work emphasizes transparency, access to justice, institutional integrity, and public trust. Ed is a graduate of Xavier High School, Fordham University, and Georgetown University, holding a Certificate in Business Leadership from Georgetown. His Jesuit education shaped his belief that ideas carry obligations—and that leadership requires both discipline and moral clarity. He lives in Pleasant Valley.

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.