ThreatPaper
Weak Evidence

The unauthorized access took place on the Court's production platform

Assessment

The Hacker News reports Thomson Reuters told Ohio courts the access "took place on the Court's production platform." Alabama was told its data was in "a backup file"; Wyoming's was from "retired case management systems." These may all be accurate for different courts inside one vendor cloud tenancy, but the vendor has not reconciled them, and the Ohio statement is reported second-hand from a private communication. Whether the intruder reached live production instances, vendor-side copies, or both remains unstated.

Where this claim appeared

The Hacker News · 2026-09-03

https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

Thomson Reuters C-Track Breach: Sealed Court Records in a Vendor's Backup Nobody Asked For

Think this assessment is wrong? Report an error.