GoFirm
Back to Blog
Case Studies·4 min read

A backup nobody requested exposed sealed court records in eleven states for four months

By GoFirm

Thomson Reuters, the global information and media conglomerate, confirmed that its West Publishing Corporation subsidiary detected unauthorised activity affecting C-Track on 30 June 2026. West Publishing supplies the case management software used by courts across the United States and Canada to file, track and store litigation records, some of them sealed by judicial order. The company's own account places the unauthorised access as running from 1 March through 29 June, nearly four months inside an environment holding other people's legal history, before anyone caught it.

What that access reached depends on which court is describing it, and the accounts do not agree. Montana's Supreme Court says the material taken was backup data stored on Thomson Reuters servers, drawn from database copies supplied to the vendor "for the purpose of troubleshooting the applications", a backup the state says it had neither requested nor known about. Alabama's Chief Justice made the same point about a copy of appellate court data sitting in the company's cloud environment. Ohio told a different story: Thomson Reuters informed the state on 31 August that the access hit its production platform directly, the live filing system serving ten appellate districts. Twenty-four court bodies across eleven states, the US Virgin Islands and Ontario appear on the vendor's notification list. Names, Social Security numbers, driver's licence numbers, dates of birth, medical information and, in some jurisdictions, sealed or otherwise confidential filings were among the data potentially involved.

The vendor notified the affected courts and Ontario's Ministry of the Attorney General between 23 and 27 July, roughly a month after discovering the intrusion. Public disclosure did not follow until 2 September, a date Montana says was chosen so every state involved could announce together. As of that date, no party, Thomson Reuters included, had published a count of affected individuals, named who was responsible, or explained how access was first obtained. North Dakota has confirmed an active criminal investigation. The Alabama Appellate Courts have been blunt about where they place responsibility: "This incident occurred within our vendor's systems, not our own."

This is not an isolated case. Healthcare data firms CareCloud, Baylor Genetics and Aesto have each disclosed breaches affecting millions of patient records to federal regulators within the same few weeks, every one of them a vendor holding sensitive records on behalf of organisations that never directly controlled the systems those records sat in. Court systems, hospitals, insurers and benefits administrators increasingly outsource case management to a small number of specialist platforms, which means one vendor compromise now reaches dozens of institutions and the people whose most sensitive records those institutions hold, in a single event.

The defences that failed here were not weak by conventional standards. Thomson Reuters is a global information security operation serving courts, law firms and governments as its core business. That did not stop a backup environment, one that some of its own customers did not know existed, from sitting exposed for four months without triggering a response. Monitoring, access logging and vendor risk assessments are all detection and audit tools. None of them is a gate that stops the pull of a sealed court file, or the replication of a records database to another environment, before it happens.

That pull is the point GoFirm exists for. Extracting, copying or replicating a database of sealed and personally identifiable court records is a high-impact action, not a routine maintenance task, and it should be treated as one. Before any such export or backup operation can execute inside a system like C-Track, a real-time confirmation request goes out-of-band to the named data custodian responsible for that environment, requiring a biometric confirmation on their own registered device before the action is permitted to proceed. No confirmation, no export. It does not matter whether the request originates from a compromised credential, a misconfigured troubleshooting process, or an intruder who has been sitting inside the network for months undetected.

Whoever or whatever pulled data out of that environment across four unmonitored months could not have produced a biometric confirmation from the named custodian on a separate channel, because that confirmation was never asked for in the first place. An intruder inside a vendor's cloud environment, however it got there and however long it stayed hidden, cannot produce a confirmation that was never designed into the process. The execution boundary holds regardless of how the access was obtained.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.

References


1. Khandelwal, S. 2026. Thomson Reuters court software breach may have exposed SSNs and sealed data. The Hacker News, 3 September 2026.
2. KPAX. 2026. Data breach hit Montana state court system from March to June, chief justice says. KPAX, 2 September 2026.
3. ABC 3340. 2026. Alabama Appellate Courts investigate possible data exposure. ABC 3340, 2 September 2026.
4. Greig, J. 2026. Health data of more than 9.5 million people leaked from Aesto record system. The Record from Recorded Future News, 2 September 2026.

Share this article