A cyberattack on Thomson Reuters' C-Track court case management system has exposed personal data tied to three Pennsylvania county courts and the state Environmental Hearing Board — and the intruders were inside the vendor's environment for roughly three months before anyone noticed. For York County small businesses, the specifics of the court breach matter less than the pattern: your data is only as safe as the weakest software vendor you hand it to.
What happened
West Publishing, a division of Thomson Reuters, said it detected unauthorized activity involving its C-Track case management system on June 30. The breach had been ongoing since March and was publicly announced on Sept. 2.
In Pennsylvania, the incident affected more than two dozen courts nationwide including the Allegheny County, Monroe County and Washington County common pleas courts and the state Department of Environmental Protection's Environmental Hearing Board, which handles appeals to environmental permitting decisions.
The exposed information is significant. West Publishing said the affected court records potentially contain individuals' personal records, including names, Social Security numbers, driver's license numbers, medical information, dates of birth and health insurance information. Certain confidential, redacted or sealed information may have been impacted for certain affected courts.
Why this is a small-business story
You're not a courthouse. So why does this matter for a York County contractor, accounting office, or medical practice?
Because the attack didn't happen at the courts. Thomson Reuters said third parties gained unauthorized access to C-Track and E-Filing backup data, which was stored on TR's servers, indicating the data breach originated on its own storage servers rather than through any vulnerability in state court networks. Translation: the customer did nothing wrong. Their vendor got popped, and their data leaked anyway.
Every small business runs on the same model now — QuickBooks Online, Microsoft 365, a scheduling app, a payroll processor, a CRM, a legal-document portal. If any one of those vendors gets breached, your customer list, your employees' Social Security numbers, or your patient records can walk out the door without a single alert firing on your network.
The three-month dwell time is the real lesson
Attackers were inside C-Track from roughly March until June 30 — about 92 days — before Thomson Reuters spotted them. That's not unusual. It's typical. And it means containment tools and instant alerts didn't catch it; someone eventually looked at the right log and pieced it together.
For a small business, the takeaway is that prevention alone isn't a strategy. You need someone actively watching. A competent MSP should be doing continuous log monitoring on your Microsoft 365 tenant and firewall, reviewing sign-in anomalies (impossible-travel logins, unusual OAuth grants, mass file downloads), and keeping an inventory of every SaaS vendor that touches your data so you know who to call when one of them makes the news. That's the baseline expectation for York Computer's managed IT services — not a premium add-on.
What your MSP should be doing this week
If you already have an internal IT person or an outside provider, these are the questions they should be able to answer without stalling:
- Do we use C-Track, Thomson Reuters e-filing, or any Westlaw-connected product? (Law firms and title companies especially.) If yes, what's our exposure and are our clients being notified? - What's our current list of third-party SaaS vendors that hold customer PII, employee data, or financial records? When was the last time we reviewed their security posture? - Is multi-factor authentication enforced on every one of those vendor logins — not just Microsoft 365? - Do we have alerts configured for unusual data-export activity in our critical apps? - If a vendor tells us tomorrow that our data was in a breach, who runs point on notifying our customers, and how fast?
If your provider fumbles those questions, that's a signal. For businesses without an in-house tech lead, or those whose internal person is stretched thin, co-managed IT support can fill exactly this gap without ripping out what already works.
What York Businesses Should Do
York County law firms, title companies, healthcare offices, and municipal contractors are the most likely local businesses to have data sitting inside a Thomson Reuters product — check with your vendor and your MSP this week. If you can't produce a current list of every SaaS vendor holding your customer data, that's the first fix, not the last.
Sources
- Software breach affects three Pa. courts and Environmental Hearing Board — Pennsylvania Capital-Star
- US and Canadian Court Records Breached Following Thomson Reuters Incident — Infosecurity Magazine
- Thomson Reuters C-Track Breach Hits U.S. and Ontario Courts — TechNadu
- Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data — The Hacker News