Back to all lessons
Awareness Lessons
last month

Court Case Management Platform Breach Exposes SSNs and Sealed Records Across 11 States

The Thomson Reuters C-Track breach highlights the critical risk of storing highly sensitive government and personal data — including Social Security numbers, medical records, and sealed court documents — within third-party SaaS platforms without adequate access controls or monitoring. Unauthorized access persisted for approximately three months (March to June 2026), suggesting a significant failure in anomaly detection and real-time alerting that should have identified suspicious activity far sooner. Court case management systems are high-value targets precisely because they aggregate legally protected, sensitive data on a massive scale across multiple jurisdictions. The extended dwell time of the attackers amplifies the potential damage, as prolonged access allows for thorough data exfiltration that may not be fully scoped for weeks or months. This incident underscores that organizations processing government and legal data must hold their third-party vendors to the same — or higher — security standards they apply internally.

Tactical Insight

Immediate actions

  • Audit all third-party court and case management platforms for active unauthorized sessions and revoke suspicious credentials immediately.
  • Require Thomson Reuters and similar vendors to provide detailed access logs covering the full breach window for forensic review.
  • Notify all potentially affected individuals promptly and provide credit monitoring and identity protection services without delay.

Long-term improvements

  • Establish contractual security requirements with third-party SaaS vendors including mandatory breach notification SLAs, penetration testing, and right-to-audit clauses.
  • Implement data minimization and field-level encryption for PII fields (SSNs, medical data) so that even unauthorized access yields unusable ciphertext.
  • Enforce least-privilege access controls and role-based access management so users and systems can only access records directly relevant to their jurisdiction and role.

Detection measures

  • Deploy continuous User and Entity Behavior Analytics (UEBA) to flag anomalous query volumes, off-hours access, or bulk data exports from case management systems.
  • Establish a maximum acceptable dwell-time threshold (e.g., 72 hours) with automated alerting tied to SIEM rules monitoring privileged access to sensitive record categories.
  • Conduct quarterly third-party security assessments and review vendor SOC 2 Type II reports to verify ongoing compliance with agreed security controls.