Executive Summary
In March 2026, an unauthorized party accessed Thomson Reuters' C-Track court case management platform, exposing sensitive data from courts across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. The breach, discovered on June 30, 2026, compromised backup files containing Social Security numbers, driver's license numbers, medical information, and sealed court documents. The unauthorized access persisted for nearly four months, affecting critical judicial systems that handle confidential legal proceedings and personal data of court users.
This incident highlights the growing threat to government and legal infrastructure, particularly as courts increasingly rely on cloud-based case management systems. With ransomware groups actively targeting government entities and judicial systems becoming prime targets for data theft, this breach underscores the urgent need for enhanced security controls around privileged data access and cloud backup environments.
Why This Matters Now
Court systems are increasingly targeted by cybercriminals seeking sensitive personal data and confidential legal information. This breach exposes critical vulnerabilities in judicial infrastructure that adversaries are actively exploiting to access sealed documents and personally identifiable information.
Attack Path Analysis
Attackers gained unauthorized access to Thomson Reuters C-Track court management platform cloud environment in March 2026, maintaining persistent access for four months until discovery in June. The breach involved accessing backup data stored in cloud infrastructure, allowing extraction of sensitive court records containing SSNs, medical information, and sealed court documents across multiple jurisdictions before being detected through security monitoring.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers gained unauthorized access to Thomson Reuters C-Track cloud environment, likely through exposed cloud storage, compromised credentials, or vulnerable cloud services hosting the court management platform
MITRE ATT&CK® Techniques
Valid Accounts
Trusted Relationship
Data from Cloud Storage Object
Data from Information Repositories
Data from Local System
Exfiltration Over C2 Channel
Stored Data Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Incident Response Plan
Control ID: Requirement 12.10
NYDFS 23 NYCRR 500 – Third Party Service Provider Security Policy
Control ID: 500.12
GDPR – Security of Processing
Control ID: Article 32
CISA Zero Trust Maturity Model 2.0 – Data Categorization and Protection
Control ID: DA.L2
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Court systems breach exposed SSNs, sealed records across 11 states requiring enhanced egress security, encrypted traffic controls, and zero trust segmentation for judicial data.
Legal Services
Attorney-client privilege compromised through court management platform breach necessitating multicloud visibility, threat detection capabilities, and secure hybrid connectivity for law firms.
Information Technology/IT
Cloud-based court software vulnerability demonstrates critical need for Kubernetes security, inline IPS protection, and cloud native security fabric against backup data exfiltration.
Health Care / Life Sciences
Medical information exposure in court records highlights HIPAA compliance gaps requiring east-west traffic security and anomaly detection for healthcare data protection.
Sources
- Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Datahttps://thehackernews.com/2026/09/thomson-reuters-court-software-breach.htmlVerified
- C-Track Security Incident Notificationhttps://www.ctracknotification.com/Verified
- Supreme Court of Ohio Data Information Statementhttps://www.supremecourt.ohio.gov/DataInformationVerified
- Ontario Courts Public Statement on Cybersecurityhttps://www.ontariocourts.ca/en/public-statement-cybersecurity.htmVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have constrained the Thomson Reuters breach by limiting lateral movement across cloud storage locations and reducing the attacker's ability to access backup data across multiple jurisdictions through segmented access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud native security fabric would likely have reduced the attack surface by implementing workload-specific access controls and identity-aware routing that could limit the scope of initial cloud service exposure.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely have limited privilege escalation by enforcing identity-scoped access controls that could reduce the attacker's ability to manipulate IAM roles and access backup storage systems.
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely have constrained lateral movement by implementing micro-segmentation that could limit the attacker's reachability across multi-region storage locations and backup systems.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility would likely have reduced the duration of sustained access by implementing continuous monitoring that could detect persistent command and control communication patterns across cloud infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security enforcement would likely have limited data extraction by implementing controlled outbound paths that could reduce the volume and scope of backup file exfiltration containing sensitive court records.
The constrained lateral movement and reduced data extraction scope would likely have limited the geographic spread of exposed court records and may have reduced the number of affected jurisdictions and sealed documents compromised.
Impact at a Glance
Affected Business Functions
- Court Case Management Systems
- Electronic Filing Services
- Legal Document Processing
- Judicial Records Management
Estimated downtime: N/A
Estimated loss: N/A
Court records containing individuals' names, Social Security numbers, driver's license numbers, dates of birth, medical information, health insurance information, and confidential or sealed court documents across 24 court bodies in 11 U.S. states, U.S. Virgin Islands, and Ontario, Canada. Historical data from 2015-2025 was compromised including case numbers, party names and addresses, phone numbers, charge descriptions, and docket entries.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement across cloud storage locations and limit access to backup systems containing sensitive data
- • Deploy Egress Security & Policy Enforcement controls to detect and block unauthorized data exfiltration from cloud storage to external destinations
- • Enable Multicloud Visibility & Control with anomaly detection to identify suspicious access patterns to backup files and prolonged unauthorized activity
- • Strengthen Encrypted Traffic controls for data in transit protection when accessing and transferring sensitive court records between cloud environments
- • Establish comprehensive Cloud Native Security Fabric policies to govern third-party vendor access and monitor all interactions with sensitive government data repositories



