Your Legal Software Vendor Just Exposed Sealed Court Records. Here's What Every Business Leader Must Know.
Thomson Reuters' C-Track platform was breached in March 2026, exposing SSNs, sealed court records, and sensitive personal data from 12 US states and Canada — undetected for three months. Here's what it means for your business.
Last week, Thomson Reuters disclosed that an unauthorized party had been inside its C-Track court case management platform for roughly three months — from March through the end of June 2026 — before anyone noticed.
The breach affected courts in 12 U.S. states, the U.S. Virgin Islands, and three major Ontario courts. Among the data potentially exposed: names, Social Security numbers, driver's license numbers, medical information, dates of birth, health insurance information — and, in the words of the disclosure itself, "certain confidential, redacted or sealed information" that courts never intended to share with anyone.
Sealed records. Let that sink in.
Witness protection filings. Juvenile records. Protective orders with home addresses. Documents sealed for national security or public safety. All of it sitting in a vendor's cloud environment, accessible for 90+ days without a single alarm going off.
The Breach Isn't the Headline. The Dwell Time Is.
Thomson Reuters is a $7 billion company. They have security teams, external experts, and sophisticated infrastructure. They were not asleep at the wheel. And still, an unauthorized party spent approximately 90 days inside their systems, exfiltrating court records, before discovery.
This is the reality of modern cybersecurity that most business leaders don't appreciate: attackers don't break in and immediately announce themselves. They move quietly. They map your environment. They take what they came for. And they leave — sometimes before you even know they were there.
Three months of access is not exceptional. It's increasingly typical. According to IBM's Cost of a Data Breach Report, the global average dwell time before detection remains measured in weeks, not hours. The question isn't whether attackers can get in. It's how long they can stay before someone notices.
For Thomson Reuters, the answer was 90 days.
Your Vendor's Cloud Is Now Your Liability
Here's the part that should make every business leader sit up straight: Thomson Reuters was explicit that the breach "was not caused by the networks, systems or data security of the affected courts." The courts did nothing wrong. Their data was stored in a vendor's cloud environment, and the vendor's environment was compromised.
This is third-party vendor risk at its most consequential.
Your organization almost certainly has vendors who store, process, or have access to your sensitive data. Payroll providers. HR platforms. Legal software. Finance tools. Medical billing systems. CRM platforms. Every one of those relationships creates a data custody chain — and a liability exposure — that your own security team may have zero visibility into.
The courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Oregon, South Carolina, Tennessee, Wyoming, Pennsylvania, the Virgin Islands, and Ontario didn't get hacked. Their vendor did. And they're spending this week notifying individuals, standing up call centers, and managing the reputational fallout.
When your vendor gets breached, it's still your problem.
The Sealed Record Problem Is a Warning for Every Industry
The exposure of sealed court records deserves special attention — not because most businesses hold sealed court records, but because of what it represents.
Every organization holds some category of information that was never supposed to leave its environment. Sealed records for courts. Proprietary formulas for manufacturers. Personnel investigations for HR. Strategic acquisition plans for executives. Source code for software companies. Patient records for healthcare providers.
The question isn't whether you have a category of data that is catastrophic if exposed. You do. The question is: who else has access to it? Where does it live? And what would you know if someone spent 90 days reading through it?
For most organizations, the honest answer is: not enough, in more places than we know, and probably not much at all.
What Business Leaders Should Be Asking This Week
You don't have to run an appellate court to take something actionable away from the Thomson Reuters breach. Here are three questions worth asking your IT or security team right now:
One: Where does your most sensitive data actually live? Not where you think it lives — where it actually lives. Most organizations have a gap between their data classification policy and the reality of which vendors have copies of which records. A data inventory exercise is not glamorous. It is essential.
Two: What would you know if a vendor's environment was compromised tomorrow? Do your vendor contracts include breach notification requirements with defined timelines? Thomson Reuters notified Ontario's Ministry of the Attorney General on July 23 — 23 days after internal discovery on June 30. That's relatively fast. Many breach notifications arrive months later. Your contract language determines how quickly you find out and what you can demand by way of forensic specifics.
Three: What is your dwell time detection capability? The 90-day gap between the Thomson Reuters intrusion and discovery wasn't a failure of perimeter security — the attacker was already inside. It was a failure of behavioral detection. If someone is quietly reading and exfiltrating records in your environment or a vendor's environment, would your current monitoring surface it in days, weeks, or not at all?
The Unsexy Truth About Cybersecurity
Businesses love to talk about the sophistication of cyberattacks. Nation-state actors. Zero-day exploits. AI-powered malware. Those threats are real, but they're often not the story.
The Thomson Reuters breach had no CVE assigned. No nation-state was attributed. No sophisticated zero-day was identified. An unauthorized party got access to a cloud environment and spent three months inside it. That's the whole story — and it cost courts across two countries their most sensitive records.
Your exposure is not primarily about the sophistication of the threat. It's about how long it takes to notice, how much you can see, and whether your vendors are as accountable as your own team.
Three months is a long time. Don't let that be your answer.
At TrustPoint Cyber, we help business leaders build the visibility, vendor accountability frameworks, and detection capabilities that close the dwell time gap — before an attacker has time to find what they came for. If you're not sure where your organization stands, start with a conversation.
Ready to strengthen your security?
TrustPoint Cyber delivers Zero Trust architecture, incident response, managed security, and vCISO services — built for your business.