A data breach at Thomson Reuters made its way to appellate courts in twelve different US jurisdictions.
Thomson Reuters has reported that an unauthorized individual accessed files belonging to C-Track, a case management platform offered by its court software division to judicial systems. The compromised records originate from appellate courts across twelve US jurisdictions and Ontario, Canada.
The company detected the breach within its cloud environment on June 30, as per Reuters, which is owned by Thomson Reuters. The data was accessed in March, three months prior to the breach being discovered.
Public announcements were made on September 2, when several states’ court systems issued notices simultaneously. This disclosure occurred over five months after the unauthorized access and more than two months after it was identified.
The jurisdictions that have been reported as affected include Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, Wyoming, and the US Virgin Islands, including Ontario. Minnesota’s judicial branch also reported an exposure that week, suggesting the overall number of affected jurisdictions may exceed the twelve mentioned.
The contents of the files are concerning, as notifications sent to court users indicate that the data includes names, Social Security numbers, driver’s license numbers, medical information, birth dates, and health insurance details. Minnesota also cautioned that some confidential or sealed documents could have been included.
Court records are not typical targets for breaches. A case file can contain sensitive information such as protective orders or sealed juvenile matters, making the attached address and phone number significantly more valuable to anyone who acquires them compared to similar data obtained from a retailer.
Thomson Reuters stated that the platform continued to operate without disruption. “There has been no operational disruption to C-Track” and “our products and services remain fully operational,” the company noted, also mentioning that it had enlisted external cybersecurity professionals and contacted law enforcement.
Individual courts have expressed greater concern. Minnesota Supreme Court Chief Justice Natalie Hudson said she was “deeply troubled that our court users’ data has been compromised,” while Montana Chief Justice Cory Swanson indicated that his courts would continue collaborating with the C-Track team “to ensure our courts operate without fear of compromising personal privacy.”
Montana was informed of the breach on July 23, six weeks before the public announcement. The state has notified anyone involved in a Montana court case that they might be affected, emphasizing that the data resided on Thomson Reuters servers, not their own.
Kentucky’s Administrative Office of the Courts stated that its appellate courts “were not functionally impaired” and that there is “no indication at this point that the unauthorized third party distributed the Kentucky data to any other party or entity.” The trial courts remain unaffected because the state doesn't utilize an outside vendor for trial court e-filing.
Remediation efforts are following a typical approach. Thomson Reuters is providing twelve months of credit monitoring and identity theft protection, established a call center, and required system users to undergo mandatory password resets.
No one has indicated who is responsible for the breach. Reuters reported that it was unable to independently identify the attacker or the specific data that was compromised, and no group has stepped forward to claim responsibility for the intrusion.
The incident reflects an emerging pattern, in which a single supplier services multiple institutions, resulting in a widespread impact from one breach, similar to incidents involving attacks on a software vendor leading to significant data breaches in education, as well as the LastPass breach.
For Thomson Reuters, which is in the process of restructuring its engineering division around AI, the timing of this incident is unfortunate. Its legal division represents the company's profitable core, and its appeal to courts is based on being the secure option for case management.
The total number of affected individuals has not been disclosed, nor has the method of the intrusion been revealed. This leaves the twelve jurisdictions discussing the same incident in slightly different terms while attacks on US organizations continue to evolve.
Other articles
A data breach at Thomson Reuters made its way to appellate courts in twelve different US jurisdictions.
Thomson Reuters has reported that an unauthorized individual gained access to files from C-Track, its court case management system, which has led to the exposure of appellate court records in 12 US jurisdictions as well as Ontario.
