The Thomson Reuters’ C-Track breach is a pretty stark reminder that an organization’s security is only as strong as the vendors and platforms it trusts.Don’t know what I am talking about? This will help:
https://cybernews.com/news/thomson-reuters-c-track-court-records-breach
Kevin Surace, CEO, TokenCore (https://www.linkedin.com/in/ksurace)
“Incidents like the C-Track breach illustrate the vulnerability of modern supply chains: an organization can maintain an airtight internal perimeter, but still be completely exposed through a trusted vendor. Because court and government platforms aggregate massive quantities of high-value data, they are prime targets. While the exact forensic vector is still emerging, breaches of this scale in cloud-hosted environments almost always trace back to identity compromise. Traditional multi-factor authentication, such as push notifications or text codes, is highly susceptible to adversary-in-the-middle phishing and a dozen other compromises in the wild. To truly secure interconnected systems, organizations must mandate that vendors adopt phishing-resistant, hardware-based biometric identity. Software-layer credentials pr passkeys alone are no longer enough to stop sophisticated supply-chain incursions.”
Denis Calderone, Principal/CTO, Suzu Labs (https://www.linkedin.com/in/deniscalderone)
“The same third-party vendor risk that’s been hitting banks, hospitals, and retailers all year just reached the US court system. Thomson Reuters’ C-Track case management platform was breached between March and June, and the blast radius covers appellate courts in at least a dozen US states, the US Virgin Islands, and Ontario.
“The data at risk here can be highly sensitive. Sealed filings can include protective orders, confidential informant identities, SSNs, medical records, and health insurance information. Some of that data was sealed to protect someone’s physical safety. Thomson Reuters confirmed that confidential, redacted, or sealed information may have been impacted, and the access ran nearly four months, from March 1 through June 29, before anyone noticed. A CVSS 9.1 vulnerability in C-Track from September 2024 allowed privilege escalation through a simple form field manipulation. Thomson Reuters patched it, but that was a rudimentary server side check failure that kind of which does not exactly inspire confidence for the courts that were trusting this platform with their most sensitive records.
“And then there’s the disclosure timing. Thomson Reuters detected the breach on June 30 and publicly disclosed on September 2. That’s 64 days. Many of the affected states have 60-day breach notification deadlines. Sixty-four days is not a coincidence. They rode the legal maximum. Montana and Ontario were quietly told on July 23, six weeks before the public learned.
“Legal and government sectors are no different from any other, they still need to carefully vet their third-party partners who host any part of their critical infrastructure or operation. Scrutinize contractual audit rights, backup encryption requirements, and incident notification timelines. The federal judiciary learned this the hard way after the CM/ECF breach last year and responded by pulling sealed documents out of electronic access entirely. State courts on third-party platforms need to have that same conversation before the next vendor breach decides it for them.”
John Strand, Owner, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)
“I feel like these third-party vendor, supply chain, and SaaS attacks are coming at a greater frequency, especially since the advent of AI. AI is really good at attacking third-party platforms, and while we don’t necessarily know all the details about this particular incident, it reinforces something organizations need to start taking much more seriously.
“The security of an organization is no longer just the security of that organization. It’s an ecosystem.
“Your security is tied to every cloud platform, SaaS product, third-party vendor, and external service that has access to your systems or your data. If one of those organizations gets compromised, their security problem can very quickly become your security problem. I think organizations need to start pushing back on their vendors.
“Ask your SaaS and third-party providers when they last received a penetration test. Ask for a letter of attestation. There should be something from the penetration testing firm stating that they actually evaluated the security controls of that organization and are willing to stand behind the work they performed.
“And it should be a reputable penetration testing firm. Not some stupid pen test puppy mill that ran a vulnerability scanner, generated a 400-page report, and called it a day.
“We need to start putting additional responsibility on SaaS providers and third-party vendors because they’re increasingly becoming part of the attack surface of every organization that uses them.
“But there’s another side of this that I think people need to watch very closely. A lot of organizations are looking at the SaaS products they’re paying for and asking a pretty reasonable question: ‘Why can’t we just rebuild this ourselves using AI?’
“And the answer is that, in many cases, they absolutely can.
“That’s going to create another security problem. We’re going to see organizations rapidly building internal applications that previously would have been purchased from established vendors. That’s going to lead to application sprawl, more APIs, more authentication systems, more integrations, and ultimately a much larger attack surface.
“So we’re potentially moving into a really interesting cycle. AI makes it easier to attack SaaS and third-party platforms. Those attacks make organizations less comfortable trusting third parties. AI then makes it easier for those organizations to replace third-party applications with software they’ve built themselves.
And every new application becomes another thing that has to be secured.
“That’s the part of the AI, SaaS, and third-party vendor churn that I think we’re going to be dealing with for quite some time.”
Security takes on many forms. Passwordless, MFA are two examples. It is time that all organizations take on all those forms to avoid getting pwned.
Honeywell’s $2M settlement shows self-attestation is now a legal liability, not a formality
Posted in Commentary with tags DoJ on September 4, 2026 by itnerdThe DOJ announced Honeywell Aerospace will pay over $2 million to settle False Claims Act allegations tied to NIST 800-171 non-compliance on a DoD contract.
The Justice Department announced today that Honeywell Aerospace Inc. has agreed to pay $2,042,518 to resolve allegations that it is liable under the False Claims Act for failing to comply with cybersecurity requirements in a contract with the U.S. Department of Defense. Honeywell Aerospace, a corporation headquartered in Phoenix, Arizona, provides aerospace products and solutions to government and commercial customers. Prior to June 29, when Honeywell Aerospace became a standalone public company, it was a business segment of Honeywell International Inc., of Charlotte, North Carolina.
“Government contractors that obtain defense information in administering their contracts must follow required cybersecurity standards,” said Assistant Attorney General Brett A. Shumate of the Justice Department’s Civil Division. “The Justice Department will continue to investigate potential violations of these cybersecurity requirements to protect this critical information.”
“Cybersecurity requirements and standards for federal contractors are in place for a reason: to protect government systems and prevent unauthorized access to government data,” said U.S. Attorney Russ Ferguson for the Western District of North Carolina. “Companies that seek and profit off of government contracts have an obligation to ensure sensitive data is protected.”
The settlement resolves allegations that from April 2020 through December 2023, a business unit of Honeywell International Inc. submitted false claims for payment by failing to comply with cybersecurity requirements specified in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, with respect to one of Honeywell’s networks, as required by the contract and regulation.
Justin Beals, CEO & Founder, Strike Graph had this to say:
“”Two million dollars gets the headline, but the number I keep coming back to is eight years. NIST 800-171 has been a contractual requirement since 2017, and Honeywell Aerospace isn’t a two-person shop that couldn’t find the standard — it’s one of the most sophisticated suppliers in the defense industrial base. The government is alleging that from 2020 through 2023, one of its networks didn’t meet requirements the company had already represented to the Department of Defense that it met. That’s the part people miss when they treat a self-assessment like a checkbox. It isn’t a checkbox. When you put a score in SPRS or sign an attestation, you’re making a legal representation to the federal government, and the False Claims Act is the mechanism that turns a paperwork gap into a fraud claim. The whistleblower here was a former employee who walked away with $375,000. Every disgruntled employee, every competitor, every subcontractor in your flow-down is now someone who can see whether your practice actually matches your paperwork. I spent my career building and shipping software, and I’ll say it plainly:
I have never met the engineer who could grade their own work and be right every time. Quality assurance saved me more times than I can count. This settlement is what happens when nobody checked the work.Here’s what actually worries me about this pause. A third-party assessment was never just a hoop to jump through — it was risk mitigation. A C3PAO comes in, validates your implementation, and stands behind that determination, which absorbs exactly the kind of exposure Honeywell just paid two million dollars to resolve. Suspend the phase-two rollout and that requirement doesn’t go anywhere. 800-171 is still in the contract, and the False Claims Act is still the enforcement engine. What goes away is the guidance and the validation. So companies are now shouldering the full weight of getting it right on their own, with no assessor checking whether their self-attestation would survive contact with a whistleblower or a DCIS investigation. And here’s the operator’s reality nobody’s saying out loud: doing this without an experienced assessor usually costs more, not less. I’ve watched companies burn months on false starts because they couldn’t even identify where their controlled data lived or which systems touched it. A good assessor catches that early. Go it alone and you find it in year three, after you’ve already built the wrong thing — or you find out the way Honeywell just did. The ‘delay’ didn’t take the cost off the table. It pushed the cost downstream, pulled the guidance out of the room, and left the fine sitting right where it was. I have loved ones in and around this mission, and the people who wear the uniform are counting on this data being protected. A steady, honest path is cheaper than a settlement, every single time.”
Organizations need to ensure that they follow all rules and regulations at all times without fail. Otherwise I hope that the DoJ smacks them silly until they comply.
Leave a comment »