Thomson Reuters disclosed this week that an unauthorized party obtained certain files from its C-Track case management platform, the system many courts use to manage digital case records. The company detected the incident on June 30, investigated, and concluded that files were accessed in March. The affected footprint, according to a website maintained by a Thomson Reuters unit, runs across eleven US states and the US Virgin Islands: Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, and Wyoming, along with the Court of Appeal for Ontario, the Ontario Superior Court of Justice, and the Ontario Court of Justice. Some court records were affected, including names and personal information. The company says there has been no operational disruption, that its products remain fully operational, and that outside experts validated its remediation. Those statements are about the platform. The harder questions are about the people whose names sit inside it.

Court records are not ordinary data. A case file can contain addresses, financial details, medical records, custody disputes, victim statements, and witness information, assembled by the state and stored for decades because the law requires it. When a retailer's database is breached, the harm is credit cards and passwords. When court records are breached, the harm can be the exposure of the most sensitive chapters of a person's life, in a form the person never chose to disclose. The Thomson Reuters notice says people involved in court proceedings or mentioned in court documents could have had personal information affected, and that the company has not yet determined exactly what was compromised. The caution is appropriate. The discomfort it creates is the point.

Digitization concentrated what paper scattered

The reason one incident can touch eleven states is structural. Over the past two decades American courts moved from paper files to digital case management systems, and the market for those systems consolidated into a small number of vendors. Thomson Reuters, through its West Publishing and related units, serves a large share of state court systems with C-Track and its predecessor products. Courts did not each build their own systems, for the same reason municipalities do not each build their own email: shared software is cheaper, maintained by specialists, and updated centrally. The tradeoff, visible now, is that shared software means shared exposure. Paper records lived in thousands of courthouses, each vulnerable in its own small way. Digital records live in a handful of vendor clouds, each one a target worth the attention of sophisticated attackers, and each one a single point of failure for the jurisdictions that depend on it.

The incident occurred in what the Ontario courts described as one of the platform's cloud environments. That detail matters, because it locates the risk exactly where the consolidation happened. Courts that outsourced case management to a vendor also outsourced the security boundary to that vendor's cloud, and with it the assumption that a compromise in one environment could ripple across every customer sharing it. The affected list, spanning a third of the country plus Canada's most populous province, is what a ripple looks like when the pond is a vendor.

What the eleven states have in common

Look at the affected list and a pattern appears. The eleven states run from Alabama to Wyoming, weighted toward smaller and mid-sized court systems rather than the largest urban judiciaries, which tend to run their own platforms or choose differently. Court IT procurement favors exactly the outcome this list reveals: a vendor that can serve many jurisdictions from one architecture wins contract after contract, because each court wants proven software, hosted infrastructure, and a support organization it could never staff itself, and the vendor that has already done it for Alabama can plausibly do it for Wyoming. Every renewal deepens the dependence. The customers in this market are not choosing among equal alternatives; they are choosing between a mature platform and the near-impossible project of replacing it, and the mature platform is the same one a dozen other states already share.

That procurement logic explains the concentration, and the concentration explains the blast radius. A single cloud environment in the C-Track platform touches courts in a third of the country and Canada's busiest province. The security of all of it is, in practical terms, the security of one vendor's infrastructure and one vendor's practices. No court in any of the eleven states could have independently prevented this incident, and none could have independently detected it. They bought a service, and with the service came a dependency that no procurement document called out in plain language: your records are only as safe as a cloud you do not control, run by a company whose other customers share your exposure.

The notification patchwork

When the disclosure came, it came through a company notice and statements from courts, and the people named in the records remain the last to be reached. That ordering is not an accident. State breach-notification statutes obligate data holders to notify affected individuals within defined periods, but their application to court records is layered with questions: whether the court or the vendor is the notifying party, whether the files in a case management system qualify for the personal-information definitions the statutes use, and how you notify individuals whose records may be decades old, whose addresses have changed, and whose connection to the courts is the last thing they want to be reminded of. The practical result is that notification happens institution to institution first, and person to person later, if at all, and the later steps depend on choices each affected jurisdiction makes with its own counsel.

The courts involved are now in the position of applying to themselves the standards they apply to every other custodian of sensitive information. Some will notify broadly and quickly. Some will move slowly while the scope is assessed. The variance is itself a finding: there is no shared playbook for what a court owes the people in its records when a vendor's cloud is breached, because until recently the scenario was hypothetical. It is not hypothetical anymore. The playbook, wherever it exists, is being written this week in eleven states, one court administrator's decision at a time.

The disclosure lag is the second failure

The timeline deserves as much scrutiny as the intrusion. According to the company's account, files were accessed in March, the incident was detected on June 30, and disclosure came in September, first to affected customers and this week to the public. A gap between access and detection is common; attackers who get in quietly tend to stay quiet. The gap between detection and public disclosure is a choice, shaped by investigation, remediation, coordination with law enforcement, and notification duties. But notice what the lag means for the people named in the records. For six months after the files left the building, nobody could tell them their information had been exposed, because the exposure itself was unknown for most of that period and undisclosed for the rest. In most US states, breach-notification law obligates entities that hold personal information to notify affected individuals within defined timeframes. Whether a court vendor's obligations attach at detection or only after the scope is confirmed varies by state, and the states' own roles as the data's custodians complicate every answer.

There is a specific irony in courts being the affected institutions. The judicial system is the institution Americans trust to adjudicate disputes about privacy and disclosure. When a vendor to the courts loses court records, the custodian's obligation to the people in the records is not merely legal; it is the same obligation the courts impose on everyone else, turned on themselves. A contact center opens this week for inquiries. That is a start, and it also measures how far the response has come: the people whose information may have been taken will learn what happened through a helpline, six months after the fact.

What the next contract should say

The fix is not to abandon digitization. Paper courts were slower, less accessible, and no safer overall. The fix is to write the concentration into the contracts. Courts buying case-management systems can require incident-notification service levels measured in days, not quarters, with the court notified at detection regardless of scope. They can require retention limits, so that old case data does not sit in production systems indefinitely. They can require data minimization, so that systems do not hold more than the law and the workflow demand. They can ask hard questions about segmentation, so that one court's records do not share a cloud environment with a dozen others. And they can insist, as the Ontario statement suggests the Canadian courts are doing, on a visible chain of custody when something goes wrong: what was accessed, when, and who is accountable for telling the people affected.

None of that prevents the next breach. It changes what happens in the weeks after it, which is when the institutions involved either earn the public's trust or spend it. Thomson Reuters says the platform remains safe to use and that remediation held up to independent review. Courts in eleven states and Ontario are now managing the consequences either way, and the people whose names are in those records are learning, this week, how much of their exposure was decided by the architecture of a system they never chose. The concentration was convenient. The bill for the convenience is arriving.

Primary sources

  1. Reuters reporting via the Lufkin Daily News for the incident timeline, the March access finding, the affected jurisdictions, and Thomson Reuters' statements.
  2. Insurance Journal for the company's containment and remediation steps and the operational statements.
  3. News 3 Las Vegas for the Nevada appellate courts' notice and the C-Track vendor connection.