Behind the scenes look at the Thomson Reuters office branding and logo display.
Thomson Reuters says an unauthorised party got into files belonging to C-Track, the case management platform its court software business sells to judiciaries. The records involved come from appellate courts in a dozen US jurisdictions and from Ontario, Canada.
The company detected the activity in its cloud environment on 30 June, according to Reuters, which is owned by Thomson Reuters. The files were taken in March, three months before anyone noticed.
Public disclosure followed on 2 September, when court systems in several states put out notices on the same day. That is more than five months after the access and more than two after it was found.
The affected jurisdictions named so far are Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, Wyoming and the US Virgin Islands, alongside Ontario. Minnesota’s judicial branch also disclosed an exposure the same week, which would put the count higher than the twelve US jurisdictions in the wire copy.
What sits in those files is the uncomfortable part. Notices sent to court users describe names alongside Social Security numbers, driver’s licence numbers, medical information, dates of birth and health insurance information, and Minnesota warned that some confidential or sealed documents may also have been caught.
Court records are not an ordinary breach target. A case file can contain a protective order, a sealed juvenile matter or a medical filing, which makes the address and phone number attached to it worth considerably more to whoever holds it than the same details lifted from a retailer.
Thomson Reuters says the platform itself kept running. “There has been no operational disruption to C-Track” and “our products and services remain fully operational,” the company said, adding that it brought in outside cybersecurity experts and notified law enforcement.
Individual courts have been blunter. Minnesota Supreme Court Chief Justice Natalie Hudson said she was “deeply troubled that our court users’ data has been compromised,” and Montana Chief Justice Cory Swanson said his courts would keep working with the C-Track team “to ensure our courts operate without fear of compromise of personal privacy.”
Montana learned of the breach on 23 July, six weeks before the public did. The state has told anyone who has been a party to a Montana court case that they may be affected, and has stressed that the data sat on Thomson Reuters servers rather than its own.
Kentucky’s Administrative Office of the Courts said its appellate courts “were not functionally impaired” and that there is “no indication at this point that the unauthorized third party distributed the Kentucky data to any other party or entity.” Its trial courts are untouched because the state does not use an outside vendor for trial court e-filing.
Remediation is running along familiar lines. Thomson Reuters is offering twelve months of credit monitoring and identity theft protection, has stood up a call centre, and system users have been pushed through mandatory password resets.
Nobody has said who was responsible. Reuters reported that it could not independently determine either the attacker or the specifics of what was taken, and no group has publicly claimed the intrusion.
The shape of it is becoming routine. One supplier sits behind dozens of institutions, and a single intrusion reaches all of them at once, which is what happened when an attack on a software vendor rather than a school produced the largest education data breach on record, and again when LastPass customer data was stolen through a supplier.
For Thomson Reuters, which has been rebuilding its engineering organisation around AI, the timing is awkward. Its legal division is the profitable core of the company, and its pitch to courts rests on being the safe place to put a docket.
The count of affected people has not been published. Neither has the mechanism of the intrusion been published, which leaves the twelve jurisdictions describing the same incident in slightly different terms while attacks on US organisations keep shifting in character.
Get the TNW newsletter
Get the most important tech news in your inbox each week.