ThreatPaper
Weak Evidence

The intruder got in through a vulnerability in West Publishing's infrastructure

Assessment

Wyoming's FAQ states: "Bad actors accessed West Publishing Corporation's systems through a vulnerability in its infrastructure." It is the only description of the mechanism anywhere in the public record and is Wyoming relaying what the vendor told it. Thomson Reuters has published no mechanism, no CVE, no advisory and no forensic summary, and no other affected court has repeated the statement. It is a second-hand, single-sentence account of a four-month intrusion, and it cannot be checked against anything the vendor has said.

Where this claim appeared

Wyoming Judicial Branch · 2026-09-04

https://www.wyocourts.gov/west-publishing-corp-data-breach/

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

Thomson Reuters C-Track Breach: Sealed Court Records in a Vendor's Backup Nobody Asked For

Think this assessment is wrong? Report an error.