The Thomson Reuters’ C-Track breach is a pretty stark reminder that an organization’s security is only as strong as the vendors and platforms it trusts.Don’t know what I am talking about? This will help:
https://cybernews.com/news/thomson-reuters-c-track-court-records-breach
Kevin Surace, CEO, TokenCore (https://www.linkedin.com/in/ksurace)
“Incidents like the C-Track breach illustrate the vulnerability of modern supply chains: an organization can maintain an airtight internal perimeter, but still be completely exposed through a trusted vendor. Because court and government platforms aggregate massive quantities of high-value data, they are prime targets. While the exact forensic vector is still emerging, breaches of this scale in cloud-hosted environments almost always trace back to identity compromise. Traditional multi-factor authentication, such as push notifications or text codes, is highly susceptible to adversary-in-the-middle phishing and a dozen other compromises in the wild. To truly secure interconnected systems, organizations must mandate that vendors adopt phishing-resistant, hardware-based biometric identity. Software-layer credentials pr passkeys alone are no longer enough to stop sophisticated supply-chain incursions.”
Denis Calderone, Principal/CTO, Suzu Labs (https://www.linkedin.com/in/deniscalderone)
“The same third-party vendor risk that’s been hitting banks, hospitals, and retailers all year just reached the US court system. Thomson Reuters’ C-Track case management platform was breached between March and June, and the blast radius covers appellate courts in at least a dozen US states, the US Virgin Islands, and Ontario.
“The data at risk here can be highly sensitive. Sealed filings can include protective orders, confidential informant identities, SSNs, medical records, and health insurance information. Some of that data was sealed to protect someone’s physical safety. Thomson Reuters confirmed that confidential, redacted, or sealed information may have been impacted, and the access ran nearly four months, from March 1 through June 29, before anyone noticed. A CVSS 9.1 vulnerability in C-Track from September 2024 allowed privilege escalation through a simple form field manipulation. Thomson Reuters patched it, but that was a rudimentary server side check failure that kind of which does not exactly inspire confidence for the courts that were trusting this platform with their most sensitive records.
“And then there’s the disclosure timing. Thomson Reuters detected the breach on June 30 and publicly disclosed on September 2. That’s 64 days. Many of the affected states have 60-day breach notification deadlines. Sixty-four days is not a coincidence. They rode the legal maximum. Montana and Ontario were quietly told on July 23, six weeks before the public learned.
“Legal and government sectors are no different from any other, they still need to carefully vet their third-party partners who host any part of their critical infrastructure or operation. Scrutinize contractual audit rights, backup encryption requirements, and incident notification timelines. The federal judiciary learned this the hard way after the CM/ECF breach last year and responded by pulling sealed documents out of electronic access entirely. State courts on third-party platforms need to have that same conversation before the next vendor breach decides it for them.”
John Strand, Owner, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)
“I feel like these third-party vendor, supply chain, and SaaS attacks are coming at a greater frequency, especially since the advent of AI. AI is really good at attacking third-party platforms, and while we don’t necessarily know all the details about this particular incident, it reinforces something organizations need to start taking much more seriously.
“The security of an organization is no longer just the security of that organization. It’s an ecosystem.
“Your security is tied to every cloud platform, SaaS product, third-party vendor, and external service that has access to your systems or your data. If one of those organizations gets compromised, their security problem can very quickly become your security problem. I think organizations need to start pushing back on their vendors.
“Ask your SaaS and third-party providers when they last received a penetration test. Ask for a letter of attestation. There should be something from the penetration testing firm stating that they actually evaluated the security controls of that organization and are willing to stand behind the work they performed.
“And it should be a reputable penetration testing firm. Not some stupid pen test puppy mill that ran a vulnerability scanner, generated a 400-page report, and called it a day.
“We need to start putting additional responsibility on SaaS providers and third-party vendors because they’re increasingly becoming part of the attack surface of every organization that uses them.
“But there’s another side of this that I think people need to watch very closely. A lot of organizations are looking at the SaaS products they’re paying for and asking a pretty reasonable question: ‘Why can’t we just rebuild this ourselves using AI?’
“And the answer is that, in many cases, they absolutely can.
“That’s going to create another security problem. We’re going to see organizations rapidly building internal applications that previously would have been purchased from established vendors. That’s going to lead to application sprawl, more APIs, more authentication systems, more integrations, and ultimately a much larger attack surface.
“So we’re potentially moving into a really interesting cycle. AI makes it easier to attack SaaS and third-party platforms. Those attacks make organizations less comfortable trusting third parties. AI then makes it easier for those organizations to replace third-party applications with software they’ve built themselves.
And every new application becomes another thing that has to be secured.
“That’s the part of the AI, SaaS, and third-party vendor churn that I think we’re going to be dealing with for quite some time.”
Security takes on many forms. Passwordless, MFA are two examples. It is time that all organizations take on all those forms to avoid getting pwned.
Related
This entry was posted on September 4, 2026 at 6:44 am and is filed under Commentary with tags Thompson Reuters. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
The Thomson Reuters breach should concern every organization
The Thomson Reuters’ C-Track breach is a pretty stark reminder that an organization’s security is only as strong as the vendors and platforms it trusts.Don’t know what I am talking about? This will help:
https://cybernews.com/news/thomson-reuters-c-track-court-records-breach
Kevin Surace, CEO, TokenCore (https://www.linkedin.com/in/ksurace)
“Incidents like the C-Track breach illustrate the vulnerability of modern supply chains: an organization can maintain an airtight internal perimeter, but still be completely exposed through a trusted vendor. Because court and government platforms aggregate massive quantities of high-value data, they are prime targets. While the exact forensic vector is still emerging, breaches of this scale in cloud-hosted environments almost always trace back to identity compromise. Traditional multi-factor authentication, such as push notifications or text codes, is highly susceptible to adversary-in-the-middle phishing and a dozen other compromises in the wild. To truly secure interconnected systems, organizations must mandate that vendors adopt phishing-resistant, hardware-based biometric identity. Software-layer credentials pr passkeys alone are no longer enough to stop sophisticated supply-chain incursions.”
Denis Calderone, Principal/CTO, Suzu Labs (https://www.linkedin.com/in/deniscalderone)
“The same third-party vendor risk that’s been hitting banks, hospitals, and retailers all year just reached the US court system. Thomson Reuters’ C-Track case management platform was breached between March and June, and the blast radius covers appellate courts in at least a dozen US states, the US Virgin Islands, and Ontario.
“The data at risk here can be highly sensitive. Sealed filings can include protective orders, confidential informant identities, SSNs, medical records, and health insurance information. Some of that data was sealed to protect someone’s physical safety. Thomson Reuters confirmed that confidential, redacted, or sealed information may have been impacted, and the access ran nearly four months, from March 1 through June 29, before anyone noticed. A CVSS 9.1 vulnerability in C-Track from September 2024 allowed privilege escalation through a simple form field manipulation. Thomson Reuters patched it, but that was a rudimentary server side check failure that kind of which does not exactly inspire confidence for the courts that were trusting this platform with their most sensitive records.
“And then there’s the disclosure timing. Thomson Reuters detected the breach on June 30 and publicly disclosed on September 2. That’s 64 days. Many of the affected states have 60-day breach notification deadlines. Sixty-four days is not a coincidence. They rode the legal maximum. Montana and Ontario were quietly told on July 23, six weeks before the public learned.
“Legal and government sectors are no different from any other, they still need to carefully vet their third-party partners who host any part of their critical infrastructure or operation. Scrutinize contractual audit rights, backup encryption requirements, and incident notification timelines. The federal judiciary learned this the hard way after the CM/ECF breach last year and responded by pulling sealed documents out of electronic access entirely. State courts on third-party platforms need to have that same conversation before the next vendor breach decides it for them.”
John Strand, Owner, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)
“I feel like these third-party vendor, supply chain, and SaaS attacks are coming at a greater frequency, especially since the advent of AI. AI is really good at attacking third-party platforms, and while we don’t necessarily know all the details about this particular incident, it reinforces something organizations need to start taking much more seriously.
“The security of an organization is no longer just the security of that organization. It’s an ecosystem.
“Your security is tied to every cloud platform, SaaS product, third-party vendor, and external service that has access to your systems or your data. If one of those organizations gets compromised, their security problem can very quickly become your security problem. I think organizations need to start pushing back on their vendors.
“Ask your SaaS and third-party providers when they last received a penetration test. Ask for a letter of attestation. There should be something from the penetration testing firm stating that they actually evaluated the security controls of that organization and are willing to stand behind the work they performed.
“And it should be a reputable penetration testing firm. Not some stupid pen test puppy mill that ran a vulnerability scanner, generated a 400-page report, and called it a day.
“We need to start putting additional responsibility on SaaS providers and third-party vendors because they’re increasingly becoming part of the attack surface of every organization that uses them.
“But there’s another side of this that I think people need to watch very closely. A lot of organizations are looking at the SaaS products they’re paying for and asking a pretty reasonable question: ‘Why can’t we just rebuild this ourselves using AI?’
“And the answer is that, in many cases, they absolutely can.
“That’s going to create another security problem. We’re going to see organizations rapidly building internal applications that previously would have been purchased from established vendors. That’s going to lead to application sprawl, more APIs, more authentication systems, more integrations, and ultimately a much larger attack surface.
“So we’re potentially moving into a really interesting cycle. AI makes it easier to attack SaaS and third-party platforms. Those attacks make organizations less comfortable trusting third parties. AI then makes it easier for those organizations to replace third-party applications with software they’ve built themselves.
And every new application becomes another thing that has to be secured.
“That’s the part of the AI, SaaS, and third-party vendor churn that I think we’re going to be dealing with for quite some time.”
Security takes on many forms. Passwordless, MFA are two examples. It is time that all organizations take on all those forms to avoid getting pwned.
Share this:
Like this:
Related
This entry was posted on September 4, 2026 at 6:44 am and is filed under Commentary with tags Thompson Reuters. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.