Security1 distinct publisher3 min readPublished
Kentucky's court administrators have confirmed appellate data was taken from the vendor's file systems. The count of affected people, the other states, and the dates of the intrusion all remain undisclosed.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The containment line Kentucky drew is real, but it is narrow. It holds for a reason other states may not share. Trial-level records are outside the blast radius because Kentucky does not use third-party vendors for trial court e-filing, so only material that reached the Supreme Court or the Court of Appeals was sitting inside C-Track [3][4]. That reflects Kentucky's own procurement choices, not something specific to the breach itself. A state that routes more of its docket through the same platform has more files to account for, and it will not know which ones until Thomson Reuters CMS finishes reviewing that court system on its own schedule [11].
The multi-state claim is the vendor's, relayed through Kentucky's Administrative Office of the Courts: an unauthorized third party accessed and obtained court data from C-Track systems in more than one state [5]. Take the vendor at its own word choice and Kentucky is one of at least three affected court systems, which puts a minimum of two other jurisdictions in scope [17]. None of them are named. Neither is a threat actor, an intrusion or discovery date, a category of exposed data, or any claim of the data by an extortion group [16].
What the disclosure does say about data type, it says through the remedy. Twelve months of credit monitoring and identity theft protection, funded by Thomson Reuters CMS, points toward personal identifiers moving, and not toward public appellate opinions being copied [9]. The AOC's position is that there is no indication Kentucky's data has been shared or distributed to anyone outside [6], and the courts stayed up throughout [7]. Read together, this is exfiltration with no observed publication so far, and the observation window belongs to the vendor.
That is the structural problem for every court on the platform. The file systems, the logs, and the per-court review are all on the vendor's side [2][11]. Kentucky's leverage is a demand for prompt resolution and swift notification [12] plus status briefings with the National Center for State Courts and contact with other affected states [15]. Thomson Reuters CMS has committed to covering all breach costs and to handling notification itself [14]. The company footing the bill is also the one setting the clock: it decides when anyone is told, and the total number of affected individuals or organizations has not been determined [13].
Mitigations have been implemented across affected jurisdictions, according to the company, which is also working with outside cybersecurity specialists and law enforcement [8]. That is the standard post-incident package and it says nothing about initial access. Until the per-court reviews produce state names and notification counts, "several states" is the entire public scope of this incident [5], and any judiciary running C-Track is inside it by default.
Ranked by verification strength, evidence, and original report placement.
The Kentucky Administrative Office of the Courts confirmed that Kentucky Appellate Court data was compromised in a cybersecurity breach traced to a third-party vendor.
West Publishing Corporation, operating as Thomson Reuters Court Management Solutions, informed the AOC that the incident originated within file systems tied to its C-Track case management platform.
C-Track is the system the Kentucky Supreme Court and the Kentucky Court of Appeals use to manage case records.
Kentucky does not currently use third-party vendors for trial court e-filing, so trial-level records that were never part of an appeal remain unaffected; exposure is limited to appellate data stored in Thomson Reuters CMS/C-Track infrastructure.
According to Thomson Reuters CMS, an unauthorized third party gained access to and obtained court data from C-Track systems across several states, not Kentucky alone.
The AOC said it currently has no indication that the unauthorized party shared or distributed Kentucky's data with any outside individual or entity.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 4, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
C-Track breach reached at least twelve judiciaries, including Ontario1 distinct publisher
invest
Legal tech's two leaders are buying the field, and nobody has disclosed a price1 distinct publisher
security
Thomson Reuters dates the C-Track court records theft to March, three months before detection4 distinct publishers
build
OpenAI's top model at $4/$20 is a three-month answer to a permanent build decision1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named institutions, one retelling
The attribution chain is clean and the sources are accountable ones — a state court administrator's office confirming, a named corporate entity reporting the origin — which is why this reads as credible. But it is one outlet's summary of a single disclosure, and the disclosure itself withholds the anchors that would let anyone verify it: no dates, no data categories, no actor. Credible direction, unverifiable specifics.
One state named, nobody notified yet
Measured against real-world footprint, almost nothing has landed. Exactly one jurisdiction is on the record, the remedies exist as commitments rather than delivered notices, and the affected-party count may still turn out to be zero by the vendor's own framing. What keeps this above the floor is that a court system did confirm loss of live case data and that a multi-jurisdiction coordination channel is already convened.
Framing smaller than the event
Nothing here is inflated. The dek says outright what is unknown, the count is left open, and the 'no indication of distribution' line is presented as an absence rather than a clearance. If anything the coverage undersells itself: a vendor telling multiple state judiciaries that appellate case files were taken is a bigger story than a single regional item, and it is carried in one trade outlet on the strength of the word 'several'.
Both narrators benefit from calm
Read the sourcing and the shape of the reassurance follows from who is speaking. The vendor is the sole origin of the technical account and also the party paying for monitoring and notification, and it is the vendor that says the review needs time. The court office wants public trust in the judiciary intact, so 'courts functioned normally' and 'no indication of distribution' get prominent placement. The one detail that cuts against both interests — Kentucky publicly pressing for a faster timeline — is exactly why it deserves weight.
Solid on direction, thin on fact
We are fairly sure a breach of the vendor's C-Track file systems happened and that Kentucky appellate data is in it, because a state court office said so in its own name. We are close to blind on everything a reader would ask next. One publisher, one disclosure, no independent corroboration and no company statement of its own — that ceiling is the reason for the middling number, not any doubt about the central fact.