BlackTree Security · Infrastructure · Automation · AI

Who Had Access to America’s Sealed Court Records?

A cloud service used by courts across North America was accessed for months, potentially exposing sealed, confidential and redacted case files that were never meant to leave judicial control.

West Publishing, part of Thomson Reuters, has disclosed unauthorized access to files in its C-Track court case-management environment. The affected service is used by appellate and other courts to manage filings, case records and operational data.

The intrusion began in March 2026. Thomson Reuters says the activity ended or was detected on 30 June. Public notices now connect the incident to at least 12 US jurisdictions as well as Ontario, Canada.

A breach of the copies, not necessarily the courts

The distinction matters. Several courts said their own networks were not compromised and operations continued. The exposed data sat with a third-party cloud provider that had been entrusted with copies of court records and backups.

The Supreme Court of Ohio said on 2 September that the affected files could include names, personal information and sealed or confidential material. The court stressed that the incident involved the vendor’s environment, not Ohio’s own technology systems.

Montana’s Judicial Branch issued a similar notice. Nevada and Wyoming also confirmed that C-Track data connected to their court systems was involved.

Sealed records carry a different kind of risk

A normal breach can expose personal data. A court-records breach can expose information that a judge deliberately removed from public view. That may include details about minors, witnesses, victims, confidential business disputes, protected addresses or sensitive evidence.

Even when the files are old, the consequences can be current. A sealed document can reveal relationships, allegations, legal strategy or private identifiers that create risks of harassment, fraud and coercion.

The concentration of records inside one case-management provider also turns a vendor incident into a multi-jurisdiction event. Each court remains responsible for notifying affected people, but the technical failure happened outside its direct network.

What is known and what is still missing

Thomson Reuters has not publicly identified the threat actor or disclosed the initial access method. The company says the incident did not disrupt court operations. It is reviewing affected files and working with customers, law enforcement and cybersecurity specialists.

Wyoming’s notice, last updated on 2 September at 12:00 MDT, offers one of the clearest public timelines. Other jurisdictions have said their reviews may take time because the exposed material must be mapped back to individual cases and people.

Nevada’s appellate courts said they were responding to the vendor incident and evaluating potential exposure. Reuters reported the disclosure on 2 September at 23:11 and updated it one minute later.

The operational lesson for courts

Judicial organizations should inventory which records, backups and attachments are stored in external case-management systems. Contracts should specify how sealed material is segregated, logged, encrypted and deleted, and how quickly the provider must identify exactly which files were accessed.

Security teams should also test whether a vendor breach can be investigated without waiting for the vendor’s full internal review. Useful controls include customer-visible audit logs, independent export inventories, strong tenant isolation and separate encryption keys for highly restricted records.

The incident is a reminder that a sealed record is only as private as every copy. Courts can close a courtroom and restrict a docket, but if the cloud copy is broadly reachable, the legal protection does not become a technical boundary.

Leave a Reply

Your email address will not be published. Required fields are marked *