A breach at Thomson Reuters has reached appellate courts in twelve different jurisdictions across the United States.
Thomson Reuters reports that an unauthorized party accessed files from C-Track, the case management system sold by its court software division to judicial bodies. The records in question originate from appellate courts across twelve US jurisdictions as well as Ontario, Canada. According to Reuters, which is owned by Thomson Reuters, the company identified the suspicious activity in its cloud environment on June 30. The files were compromised in March, three months prior to detection.
Public notification occurred on September 2, coinciding with announcements from court systems in several states. This disclosure came more than five months after the breach and over two months after it was identified. The jurisdictions affected thus far include Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, Wyoming, and the US Virgin Islands, in addition to Ontario. Minnesota’s judicial branch also reported a similar exposure that week, indicating that the total number of impacted jurisdictions may exceed the twelve mentioned in the news.
The contents of these files are particularly concerning. Notifications sent to court users list sensitive information, including names, Social Security numbers, driver’s license numbers, medical information, dates of birth, and health insurance details, with Minnesota cautioning that some confidential or sealed documents might also have been involved.
Court records are a notable target for breaches. A case file may contain a protective order, a sealed juvenile matter, or a medical filing, making the associated personal information significantly more valuable to any malicious actor than similar details obtained from a retailer.
Thomson Reuters has stated that the platform itself continues to operate without any disruption. “There has been no operational disruption to C-Track” and “our products and services remain fully operational,” the company noted, mentioning that it has engaged external cybersecurity experts and informed law enforcement.
Responses from individual courts have been more forthright. Minnesota Supreme Court Chief Justice Natalie Hudson expressed being “deeply troubled” by the data compromise involving court users, while Montana Chief Justice Cory Swanson announced that his courts would collaborate with C-Track to ensure operations continue without compromising personal privacy.
Montana became aware of the breach on July 23, six weeks before the public announcement. The state has notified all individuals who participated in a Montana court case that they may be affected, emphasizing that the data was stored on Thomson Reuters servers rather than its own.
Kentucky’s Administrative Office of the Courts stated that its appellate courts “were not functionally impaired” and there is “no indication at this point that the unauthorized third party distributed the Kentucky data to any other party or entity.” Its trial courts remain unaffected as the state does not employ an external vendor for electronic filing in trial courts.
Remediation efforts are following a common pattern. Thomson Reuters is providing twelve months of credit monitoring and identity theft protection, has established a call center, and users have been required to undergo mandatory password resets.
The identity of the attacker remains undisclosed. Reuters reported being unable to independently verify the details of the intruder or the specifics of the data accessed, and no group has publicly claimed responsibility for the breach.
This situation is becoming more familiar. One supplier can serve multiple institutions, and a single breach can impact all of them simultaneously, as seen in the largest education data breach on record due to a software vendor attack, and in the incident involving LastPass customer data theft through a supplier.
For Thomson Reuters, which is reorganizing its engineering division around AI, the timing of the breach is problematic. Its legal division is a key revenue generator for the company, and its appeal to courts relies on being a secure option for case management.
The number of affected individuals has not been disclosed, nor has the method of intrusion, leaving the twelve jurisdictions to characterize the same incident in slightly varied terms as the nature of attacks on US organizations continues to evolve.
Other articles
A breach at Thomson Reuters has reached appellate courts in twelve different jurisdictions across the United States.
Thomson Reuters reports that an unauthorized individual gained access to files from C-Track, its court case management system, revealing appellate court records in 12 US jurisdictions and Ontario.
