Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Cybersecurity Workers Arrested While Performing Courthouse Security Test

Cybersecurity Workers Arrested While Performing Courthouse Security Test

By: Morgan Cipher Senior Privacy Journalist

Last updated: August 4, 2026

Human Written
Cybersecurity Workers Arrested While Performing Courthouse Security Test
  • Two cybersecurity workers locked up while testing security at an Iowa courthouse for the state court system.

  • The men worked for Coalfire and said their job involved trying to gain unauthorized access through different methods.

  • Authorities charged both men with burglary-related offenses after they entered the Dallas County courthouse during the test.

Justin Wynn and Gary Demercurio faced arrest while testing the security of Iowa’s Dallas County courthouse. Police detained the two men around 12:30 a.m. on Wednesday, according to the Des Moines Register report.

The two men were not breaking into the courthouse for personal gain. The state court administration had hired them to test its security. Their work focused on finding ways to gain unauthorized access to court documents.

Security Test Leads to Arrests

Wynn and Demercurio work as physical penetration testers for cybersecurity company Coalfire. Their role involves testing physical security to find weaknesses that could allow unauthorized entry.

The two men reportedly entered the Dallas County courthouse as part of that security exercise. However, local law enforcement apparently did not know about the test.

The state court administration later said it never expected the security exercise to involve forcing entry into a building. According to the Des Moines Register, officials said they did not intend or expect the testing work to include forced entry.

The incident highlights the importance of clearly defining what security testers can and cannot do. Security tests can involve digital systems, buildings, employees, or other parts of an organization.

However, everyone involved needs to understand the limits of the test before the work begins. That includes the people responsible for security and local law enforcement when physical entry forms part of the exercise.

Physical Testing Creates Confusion

Physical penetration testing involves testing whether someone can enter a protected location without permission. Security professionals use these exercises to identify weaknesses in buildings and other physical security measures.

Coalfire lists penetration testing among its security services. The company says its work includes regular updates during an engagement and quick reporting of serious risks. It also says clients receive information about security weaknesses and ways to fix them.

The company describes penetration testing as a process that helps organizations understand weaknesses in their systems and environments. It also says the work includes sharing knowledge with the client’s technical team. Physical security tests are not unusual in the cybersecurity field. Security testers may attempt to enter buildings or restricted areas to see whether existing protections work.

One physical security tester, who uses the name Jek Hyde on Twitter, has also shared details about similar testing activities. The tester’s posts describe security exercises carried out with client permission. The Dallas County courthouse test, however, ended differently.

The two testers found themselves dealing with police instead of simply reporting security weaknesses to their client. The case shows how a security exercise can quickly become a legal problem when people outside the testing team do not know about it.

It also shows why the rules of a physical security test must be clear to everyone involved. Law enforcement actions against crime take many forms, from arresting security testers to arresting individuals involved in dark web drug sales, as seen in a recent New South Wales police operation.

The original report does not state that police knew about the planned exercise before the arrests. The state court administration instead said it did not expect the test to involve forced entry.

Testers Face Criminal Charges

Authorities charged Wynn and Demercurio with possession of burglary tools and third-degree burglary, according to the Des Moines Register. The charges followed their arrest inside the Dallas County courthouse.

The two men also faced a $50,000 bond. Their arrests came while they were carrying out work they had reportedly been hired to perform for the state court administration. The incident also raised questions about the exact limits of the security test. The men had been asked to attempt unauthorized access to court documents using different methods.

However, officials later said the testing assignment was not meant to include forced entry into the courthouse. That difference became central to the case. The courthouse security system did appear to respond to the attempted entry.

The incident therefore showed that the building’s alarm system could detect the activity. The available report does not provide further details about what happened after the arrests. It also does not state how the criminal case was ultimately resolved.

For security companies and their clients, the case demonstrates the need for clear testing rules. Physical security exercises can involve real buildings, real alarms, and real police responses.

Everyone involved must understand the agreed testing methods and limits before the exercise begins. Otherwise, a planned security test can quickly lead to confusion, arrests, and criminal charges.

Share this article

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.