Executive Summary

In March 2026, an unauthorized party accessed Thomson Reuters' C-Track court case management platform, exposing sensitive data from courts across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. The breach, discovered on June 30, 2026, compromised backup files containing Social Security numbers, driver's license numbers, medical information, and sealed court documents. The unauthorized access persisted for nearly four months, affecting critical judicial systems that handle confidential legal proceedings and personal data of court users.

This incident highlights the growing threat to government and legal infrastructure, particularly as courts increasingly rely on cloud-based case management systems. With ransomware groups actively targeting government entities and judicial systems becoming prime targets for data theft, this breach underscores the urgent need for enhanced security controls around privileged data access and cloud backup environments.

Why This Matters Now

Court systems are increasingly targeted by cybercriminals seeking sensitive personal data and confidential legal information. This breach exposes critical vulnerabilities in judicial infrastructure that adversaries are actively exploiting to access sealed documents and personally identifiable information.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The breach exposed Social Security numbers, driver's license numbers, dates of birth, medical information, health insurance details, and confidential sealed court documents from judicial proceedings across multiple states.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely have constrained the Thomson Reuters breach by limiting lateral movement across cloud storage locations and reducing the attacker's ability to access backup data across multiple jurisdictions through segmented access controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Cloud native security fabric would likely have reduced the attack surface by implementing workload-specific access controls and identity-aware routing that could limit the scope of initial cloud service exposure.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust segmentation would likely have limited privilege escalation by enforcing identity-scoped access controls that could reduce the attacker's ability to manipulate IAM roles and access backup storage systems.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic enforcement would likely have constrained lateral movement by implementing micro-segmentation that could limit the attacker's reachability across multi-region storage locations and backup systems.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility would likely have reduced the duration of sustained access by implementing continuous monitoring that could detect persistent command and control communication patterns across cloud infrastructure.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security enforcement would likely have limited data extraction by implementing controlled outbound paths that could reduce the volume and scope of backup file exfiltration containing sensitive court records.

Impact (Mitigations)

The constrained lateral movement and reduced data extraction scope would likely have limited the geographic spread of exposed court records and may have reduced the number of affected jurisdictions and sealed documents compromised.

Impact at a Glance

Affected Business Functions

  • Court Case Management Systems
  • Electronic Filing Services
  • Legal Document Processing
  • Judicial Records Management
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Court records containing individuals' names, Social Security numbers, driver's license numbers, dates of birth, medical information, health insurance information, and confidential or sealed court documents across 24 court bodies in 11 U.S. states, U.S. Virgin Islands, and Ontario, Canada. Historical data from 2015-2025 was compromised including case numbers, party names and addresses, phone numbers, charge descriptions, and docket entries.

Recommended Actions

  • Implement Zero Trust Segmentation to prevent lateral movement across cloud storage locations and limit access to backup systems containing sensitive data
  • Deploy Egress Security & Policy Enforcement controls to detect and block unauthorized data exfiltration from cloud storage to external destinations
  • Enable Multicloud Visibility & Control with anomaly detection to identify suspicious access patterns to backup files and prolonged unauthorized activity
  • Strengthen Encrypted Traffic controls for data in transit protection when accessing and transferring sensitive court records between cloud environments
  • Establish comprehensive Cloud Native Security Fabric policies to govern third-party vendor access and monitor all interactions with sensitive government data repositories

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image