Product1 distinct publisher3 min readPublished
Court users are getting the letters and the courts are answering the phones, but the supplier that held the files set both the detection date and the disclosure date, which is where the exposure sits.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
Follow any of these and your For You feed starts watching them — no settings page required.
leadership
Thomson Reuters spent $40 million to own the layer above the open weights1 distinct publisher
product
PayPal stopped saying no. Payments teams should now plan for a Stripe-owned checkout rail3 distinct publishers
invest
Legal tech's two leaders are buying the field, and nobody has disclosed a price1 distinct publisher
product
State Department letter would make 35 countries pick an AI side, and the workaround already exists1 distinct publisher
The person at the end of this filed an appeal some years ago and wrote a Social Security number on a form because the form asked for one. They did not choose C-Track and cannot audit it [1]. What arrives is a letter listing a name alongside a Social Security number, a driver's licence number, a date of birth, medical information and health insurance information [7], and in Minnesota the possibility that a confidential or sealed document travelled with it [8].
The most useful sentence in the whole set of notices belongs to Kentucky's Administrative Office of the Courts, which said its trial courts were untouched because the state does not use an outside vendor for trial court e-filing [11]. One judiciary, one class of record, and the exposure follows the procurement decision rather than anything a courthouse did. Montana made the same point from the other side when it told parties that the data sat on Thomson Reuters servers rather than its own [12].
The timeline runs like this: the activity was detected on 30 June, according to Reuters [3], and the files had gone in March [2]. Montana was told on 23 July, 23 days after detection [3]. The public heard on 2 September [4], which is 64 days after detection once you add July's 31 days, August's 31 and two more [1]. Montana held that knowledge for 41 days before the public disclosure came [2], on a schedule the state did not set.
Both official statements about impact are statements about availability. Thomson Reuters said there has been no operational disruption to C-Track and that its products and services remain fully operational [9]. Kentucky said its appellate courts were not functionally impaired [10]. The remediation runs on the same axis: the mandatory password reset rotates the one item on the list that can be rotated, and twelve months of credit monitoring puts an expiry date on exposure that a Social Security number does not have [13].
For anyone buying a system that will hold records belonging to other people, two columns sort the vendors faster than an uptime table. The first is whether the data is rotatable, like passwords and session tokens, or permanent, like the dates of birth and medical filings in these court files [7]. The second is who tells your users on the day the vendor knows, and by when, in writing. A supplier in the permanent column with no named notification clock is one where the contract describes the wrong failure. Thomson Reuters sells courts on being the safe place to put a docket, and its legal division is the profitable core of the company [19], so the leverage to ask for that number exists. This incident produced 23 days to the customer and 64 to the public [3][1]. A renewal that cannot beat it has priced a litigant's Social Security number at twelve months of monitoring [13].
Ranked by verification strength, evidence, and original report placement.
An unauthorised party got into files belonging to C-Track, the case management platform that Thomson Reuters' court software business sells to judiciaries.
The files were taken in March, three months before anyone noticed.
Thomson Reuters detected the activity in its cloud environment on 30 June, according to Reuters, which is owned by Thomson Reuters.
Public disclosure followed on 2 September, when court systems in several states put out notices on the same day.
The affected jurisdictions named so far are Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, Wyoming and the US Virgin Islands, alongside Ontario, Canada.
Minnesota's judicial branch also disclosed an exposure the same week, which would put the count higher than the twelve US jurisdictions in the wire copy.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Dated notices, one newsroom
The spine of this story is documentary — court notices with dates on them, named chief justices, a quoted company statement — but only one outlet, The Next Web, has assembled it, and the 30 June detection date reaches us through Reuters, which Thomson Reuters owns. That is the weak joint. What holds is corroboration by parties who had no reason to coordinate: Kentucky, Montana and Minnesota each described the incident in their own terms, and Minnesota's account contradicts the tidier twelve-jurisdiction figure. Nobody independent — regulator, researcher, court filing — has yet tested the timeline.
One platform under thirteen-plus judiciaries
The breach doubles as an inventory. Alabama through Wyoming, the US Virgin Islands and Ontario all turned out to be on the same case management platform, and Minnesota's separate notice shows the published list is a floor rather than a total. The footprint appears concentrated in appellate courts — Kentucky's trial courts were spared precisely because that state never outsourced trial-court e-filing, which is the clearest measure in the story of how deep the dependency runs where it exists.
Headline undercounts its own reporting
Restraint runs slightly past the facts here. The framing counts twelve jurisdictions from the wire while the same paragraph notes Minnesota already makes that a floor. Meanwhile the two hardest facts — that sealed and confidential filings may be in the stolen set, and that no one has said how many people are affected — carry less volume than Thomson Reuters' assurance that C-Track never stopped working, an assurance that answers a question nobody asked. Nothing in this reporting is inflated; the severity is stated more quietly than the evidence permits.
The party that lost the files set the clock
Thomson Reuters established both dates that matter — when the intrusion was found and when the public learned — and the wire copy carrying the first of them is its own newsroom. Its statement leads with operational continuity, which is the reassurance a vendor can safely give; twelve months of monitoring and a call centre are the standard tariff for closing out an event like this. The courts have their own angles: Montana stressing the data sat on the supplier's servers rather than its own, Kentucky noting its trial courts were never in the vendor's hands. Both true, both usefully exculpatory. Nobody in the story is positioned to volunteer the affected-person count.
Firm on when, blank on how big
We would stand behind the sequence: the dates are documented, the arithmetic between them is not in dispute, and the officials quoted are named. Confidence drops on everything downstream of that. How many people, which files, how the intruder got in, whether the data has moved — Kentucky can only say there is no indication so far — all remain open, and a single outlet is carrying the whole account. Expect the jurisdiction count to rise before any of the rest is answered.