Episode Summary
Executive Summary: The episode revisits the Iowa courthouse penetration-testing arrest of Coalfire testers Justin Wynn and Gary DiMecario (now Gabby), then provides a years-later update: the criminal case was dismissed, they pursued a civil suit, and after years of delays and legal battles they ultimately won a substantial settlement. The story highlights the clash between cybersecurity work, local law enforcement, and legal misunderstandings about authorization, while underscoring the need for clearer rules and precedent in physical security testing.
Main Topics: Darknet Diaries framing and sponsor messages (Priority: 2/5): The episode opens and closes with sponsor spots and a familiar Darknet Diaries anecdote about the host’s father struggling with modern tech, establishing the show’s tone before moving into the main investigation story. Original Iowa courthouse penetration test (Priority: 5/5): Justin and Gary explain how Coalfire was contracted for a full-scope red team assessment of Iowa Judicial Branch facilities, including physical access testing, door bypass techniques, credential/card testing, and post-entry security review. Arrest, booking, and criminal charges (Priority: 5/5): At the Dallas County Courthouse, the testers were detained, charged with burglary and possession of burglary tools, jailed overnight, and initially treated as criminals despite presenting authorization paperwork and contacts. Legal confusion over authority and jurisdiction (Priority: 5/5): A central conflict emerged over whether the state judicial branch could authorize testing of county courthouse property; later investigation found the state had authority as tenant/administer of the buildings, but county prosecutors still pursued charges for a long period. Industry response and AwarenessCon (Priority: 3/5): The cybersecurity community organized educational outreach in Iowa to explain physical penetration testing to the public and law enforcement, with Sheriff Leonard later acknowledging the profession and the need for better coordination. Civil lawsuit and eventual settlement (Priority: 5/5): After criminal charges were dropped, Justin/Gabby and Gary pursued a civil rights lawsuit against the county/sheriff’s office, fought qualified and sovereign immunity hurdles, and after years of delays secured a $600,000 total settlement. Impact on careers, reputation, and precedent (Priority: 4/5): The incident affected their backgrounds, job prospects, and mental health, but also helped establish a stronger real-world precedent for how legitimate physical red-team work should be treated in future incidents.
Key Arguments: The testers argued they were lawfully contracted and fully authorized by the Iowa Judicial Branch to conduct physical security assessments at named courthouses. The county’s response was based on misunderstanding and jurisdictional confusion, not on actual criminal intent; burglary requires intent to commit a felony after entry, which they did not have. The arrest and prosecution imposed severe consequences even though the testers were cooperating, which shows how the legal process itself can become punishment. The later civil case demonstrated that governments can be held accountable for wrongful arrests tied to legitimate security work, even when qualified immunity makes such cases difficult. The story proves that physical penetration testing is a real profession requiring clear communication, rules of engagement, and coordination with all relevant authorities. Community education mattered: once local residents and officials learned what physical pen testing is, many became more supportive and recognized the mistake. The final settlement created a valuable precedent for future testers who may face similar situations, encouraging careful documentation and cooperation while also validating the legitimacy of the work.
Data Points: Initial physical test window: September 8–13, 2019 - Rules of engagement for the Iowa Judicial Branch security assessment Number of locations in scope: 5 locations - The assessment covered multiple courthouses and judicial facilities Original show episode: Episode 59 - The story first aired in February 2020 and was revisited years later Years since original event: 6 years - The update interview was conducted at DEF CON six years after the incident Bail amount per person initially set: $50,000 - After being charged, both testers were assigned high bail Total bail paid to secure release: $100,000 - Coalfire later posted bail for both individuals Potential prison exposure: 7 years - They were facing felony burglary and possession-of-tools charges Overnight jail time: About 20 hours - They were released after roughly a day in custody once bail was posted Final civil settlement: $600,000 total - A later settlement resolved the civil lawsuit before trial Settlement split: $300,000 each - The final offer accepted by Justin/Gabby and Gary Initial low settlement offer: $50,000 each - The county’s early settlement posture matched their original bail amount Public outreach event: AwarenessCon - Cybersecurity professionals gathered in Iowa to educate the community after the arrests
Pivotal Quotes: "You must think I’m stupid." — Judge: The judge’s reaction when Gary tried to explain the authorization and testing context during the initial criminal hearing "We do things by the letter, by the contract. Like everything we do is meticulously perfect for that reason." — Gabby (Gary DiMecario): Describing their testing approach and why the arrest felt unjust "This isn’t a matter of if you win, this is a matter of how much money you’re going to get." — Arbitrator: During civil proceedings, signaling that the case against the county was unusually strong
Implications: The case underscores the need for clearer authorization chains, better law-enforcement coordination, and stronger legal protections for legitimate security testing. It also shows that documentation and persistence can eventually produce accountability, precedent, and compensation.
About Darket Diaries
Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.