Court-System Breach Shows Third-Party Cloud Risk Can Reach Regulated Data

3 September 2026

Executive Summary

A cybersecurity incident affecting Thomson Reuters’ C-Track court case-management platform has demonstrated how a breach within a third-party cloud environment can expose sensitive information held across multiple jurisdictions.

Thomson Reuters detected the incident on 30 June.

Its subsequent investigation found that an unauthorised party had obtained certain C-Track files as early as March.

The affected platform is used for digital court-record management.

The incident affected C-Track environments serving 11 US states, the US Virgin Islands and Canada, including Ontario’s court system.

Some affected court records contained names and personal information.

However, the precise extent and nature of all compromised information remains under investigation and responsibility for the incident has not been publicly established.

Thomson Reuters said it took steps to contain the activity, engaged external cybersecurity specialists, notified law enforcement and secured the affected environment.

Importantly, the company says there has been no operational disruption to C-Track and that its products and services remain operational and safe to use.

That distinction matters.

A cyber incident does not need to shut down a system to create potentially significant privacy, regulatory and liability exposure.

UK Impact

The incident has direct relevance to UK organisations increasingly dependent upon cloud-based third-party systems.

Particularly exposed sectors include:

  • Financial services.
  • Insurance.
  • Legal services.
  • Accountancy.
  • Healthcare.
  • Government contractors.
  • Professional services.
  • Technology.
  • Education.
  • Critical infrastructure.

Businesses frequently focus cybersecurity investment upon their own systems.

But commercially sensitive information may simultaneously exist within:

  • Cloud platforms.
  • CRM systems.
  • Payroll providers.
  • Legal platforms.
  • Accountancy systems.
  • Data rooms.
  • Software-as-a-service providers.
  • Outsourced administrators.
  • Supply-chain systems.

The company’s own network can therefore remain uncompromised while its information is exposed elsewhere.

Global Impact

Cloud outsourcing has created increasingly complex chains of digital dependency.

A single organisation may use dozens or hundreds of external technology providers.

Those providers may themselves rely upon other cloud providers, subcontractors and infrastructure companies.

That creates an important risk-management problem.

Businesses may know their immediate supplier.

They may have considerably less visibility over their supplier’s suppliers.

When an incident occurs, questions can arise concerning:

  • Data ownership.
  • Data location.
  • Regulatory notification.
  • Contractual liability.
  • Cyber insurance.
  • Technology errors and omissions.
  • Privacy liability.
  • Incident-response costs.
  • Legal expenses.
  • Business interruption.
  • Reputational damage.

Determining whose system was actually compromised can become critical when establishing which contractual indemnity or insurance policy responds.

Our View

Third-party cyber risk should be treated as an extension of the company’s own cyber perimeter.

Businesses should ask:

  • Which third parties hold our sensitive data?
  • Exactly what information do they hold?
  • Where is that information physically hosted?
  • Which cloud provider is being used?
  • Can the supplier subcontract data processing?
  • Do we know who those subcontractors are?
  • Is sensitive data encrypted?
  • Who controls privileged access?
  • How quickly must the supplier notify us following an incident?
  • Does the contract require immediate notification or only notification after confirmation?
  • Who pays forensic investigation costs?
  • Who pays regulatory-response costs?
  • What contractual indemnities apply?
  • Does our cyber policy cover dependent-system incidents?
  • Does contingent business interruption extend to technology providers?
  • Have we tested what happens if a critical cloud supplier is unavailable?

The fundamental question has changed.

It is no longer sufficient to ask:

“Who can access our systems?”

Businesses must also ask:

“Whose systems contain our information?”

Risk Indicator: HIGH – CYBER, CLOUD & THIRD-PARTY DATA RISK

Does This Risk Affect Your Business?

Invictus Risk Solutions helps businesses find practical solutions to insurance, risk and commercial challenges.

From individual businesses to major international organisations, risk is our business.

TALK TO INVICTUS →

Scroll to Top