Case file · IOWA COURTHOUSE 2019

Hired to break in, then jailed for it: the Iowa courthouse pen test

Published 2026-09-29 · 5 min read · Missing control: Written scope approved by all owners

In September 2019 two security consultants hired by Iowa's own court system to test courthouse security spent the night in jail, charged with felony burglary for doing the job they were paid to do.[1] This case file covers how a physical security test went wrong, what it cost everyone involved, and the one control that would have kept it from happening.

What happened

Iowa's State Court Administration, which runs the state's judicial branch, hired the security firm Coalfire Labs to test how well its buildings and systems were protected. Part of the work was a physical test: trying to get into court buildings after hours, the way a real intruder might, and reporting what worked.[1]

Early on the morning of September 11, 2019, two Coalfire testers entered the Dallas County courthouse, west of Des Moines, and set off the alarm.[1] Rather than leave, they stayed to meet the officers who responded and showed paperwork saying the court system had authorized the test.[1][4]

The county sheriff arrived and decided the test had crossed a line. In his view, using tools to open the front door counted as forced entry, and he also accused the pair of trying to disable the alarm, which Coalfire denied.[1] The two men were charged with third-degree burglary, a felony, and possession of burglary tools. Bail was set at $100,000, and they spent nearly 24 hours in jail before being released.[1]

A week later the State Court Administration issued a statement saying it and Coalfire had read the scope of their agreement differently. It apologized to officials in Dallas County and in neighboring Polk County, whose courthouse had also been part of the testing, and said both sides would commission independent reviews.[2] In October the Iowa Supreme Court's chief justice also apologized publicly for the break-ins.[3]

How it went wrong

A physical penetration test is a legitimate, common service. A business or agency pays a firm to try to get past its locks, alarms and front desk, so weaknesses are found by friends instead of burglars. What makes it legal is permission from whoever has the right to grant it, written down in a scope document that says which buildings, which hours and which methods are allowed.[2]

That is where this test failed. The court administration signed the contract, but the Dallas County courthouse was a county building. The county, and its sheriff, had not agreed to anyone breaking in. Coverage of the case pointed to real uncertainty over who controlled the building, the state's courts or the county, and Coalfire's chief executive later said his firm had not understood that split.[1]

The paperwork was also vague on the details that mattered in the moment. The court administration and Coalfire disagreed about what the agreement allowed, including whether after-hours entry and opening locked doors were in bounds.[2] When the people with guns and handcuffs arrived, the letter in the testers' pocket came from a party the sheriff did not answer to.

What it cost

The felony charges were later reduced to misdemeanor trespass.[1][5] On January 30, 2020, the Dallas County prosecutor dropped the remaining charges, saying the long-term interests of justice were better served by cooperation than by prosecution.[1]

That was not the end. The two testers sued the county and the sheriff, and in January 2026 the case was settled for $600,000, just before it was due to go to trial.[6][7] The whole episode took more than 6 years to resolve.

The missing control

The missing control: a written scope approved by every owner of the thing being tested. The contract had one signature from the courts, but the building, the alarm and the police response belonged to the county, and nobody got its sign-off.

A properly approved scope would have named each building, confirmed who owned and secured it, listed the allowed methods in plain words, and carried signatures from each of those owners, plus a contact who could be called at 1 a.m. to vouch for the testers. With the county on board, the sheriff would have known about the test, or could have confirmed it with one phone call, and a routine alarm response would have ended with a handshake instead of handcuffs.[1][2]

What to do in your business

Watch the case
Hired to break into a courthouse, then jailed for itDrops 2026-12-31
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More vendors and third parties cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Krebs on Security: Iowa prosecutors drop charges against men hired to test their security
  2. Iowa Judicial Branch: State Court Administration statement
  3. Associated Press via The Washington Times: Iowa chief justice apologizes for courthouse break-ins
  4. Dark Reading: Pen testers who got arrested doing their jobs tell all
  5. Des Moines Cityview: Charges significantly reduced in Dallas County courthouse incident
  6. KCRG: Cybersecurity testers reach $600,000 settlement after wrongful arrest
  7. Iowa Capital Dispatch: Lawsuit over courthouse security break-in is headed toward trial