On September 2, Thomson Reuters told courts in eleven states, the U.S. Virgin Islands, and Ontario that someone had been inside a West Publishing storage environment since March 1. The intrusion ran for four months before anyone caught it, on June 29. In several states, the exposed material wasn't the live case management system. It was backup data, database copies pulled out of production for troubleshooting and then left somewhere nobody was watching closely enough to notice.
Montana's release put it plainly: the material taken was "backup data stored on Thomson Reuters servers, drawn from database copies that had been supplied to TR for the purpose of troubleshooting the applications." Alabama's appellate courts said much the same thing, and added a detail that should bother anyone running government IT: a backup file existed in the vendor's cloud environment that the courts themselves had "neither requested nor known about."
The software wasn't the problem. The copies were.
C-Track itself doesn't appear to be broken. Thomson Reuters says there's been no operational disruption and considers the platform safe to keep using. Ohio's Supreme Court, though, got a different story from the vendor than some of the other states did, and is still waiting on details about what security measures were actually deployed after the fact. That gap between what a vendor says happened and what an agency can independently verify is the actual failure here, not a line of code.
Every organization that runs document-heavy systems generates copies. Snapshots for testing. Extracts for support tickets. Exports for a migration that got delayed. None of that is unusual. What's unusual, and what should be unacceptable in a government context, is when those copies exist outside any system that logs where they went, who touched them, and when they were supposed to be destroyed. Wyoming's incident involved data going back to 2015. Nobody sets out to keep a decade-old backup lying around. It just happens when there's no governance layer forcing the question.
A backup file existed in the vendor's cloud environment that the courts themselves had never requested and never knew about.
Why "where did this copy go" is the wrong question to ask after the fact
By the time an agency is asking that question, the answer usually involves a hotline number and a credit monitoring offer. The affected courts in this incident are now running through the same sequence: notify individuals, stand up a call center, publish an engagement number, wait for the identity theft claims to trickle in over the next year. North Dakota confirmed an active criminal investigation. None of that undoes the exposure.
The fix isn't a stricter contract clause about data handling, though agencies should absolutely have those. It's a pipeline architecture where every movement of data, every copy, export, and transform, is tracked as it happens instead of reconstructed after a breach notice arrives. That's a structural difference, not a policy difference.
What a governed pipeline looks like in practice
AIRLIFT Connect, our integration platform, moves documents and data through four stages: capture, transform, deliver, and observe. The observe stage matters most here. Every import is tracked through queued, downloading, transforming, delivering, and completed states, with a full audit timeline attached to each one. There's no step where a copy can quietly leave the pipeline and land in an untracked location, because there's no location outside the pipeline for it to land in.
That doesn't mean troubleshooting copies never get made. It means when one does, there's a record of it: who requested it, what it contained, where it went, and whether it was retired on schedule. If a state auditor or a legislative oversight committee asks a hosting vendor to produce that trail six months later, the trail exists. Compare that to an agency finding out, after public disclosure, that a support copy of its data had been sitting in a vendor's cloud environment for years without its knowledge.

Questions to ask before the next vendor notice letter
Agencies evaluating or renewing a vendor relationship right now have a real opportunity to ask sharper questions. Does the vendor maintain a complete inventory of every copy of your data, including ones made for support or troubleshooting? Can they produce, on request, a timeline showing when a given dataset was created, transformed, moved, and destroyed? Is there a retention limit on troubleshooting copies, and is it enforced automatically or does it depend on someone remembering to clean up?
If the answer to any of those is a shrug, that's worth weighing against whatever the vendor's marketing page says about security. SOC 2 Type II and GovRAMP both look at controls like these directly, which is part of why they're worth requiring rather than treating as boxes on a procurement checklist.
The C-Track incident will keep unfolding for months as more states confirm what was actually in scope. Whatever the final count looks like, the underlying lesson is already clear: a document system is only as trustworthy as its ability to account for every copy of the data it holds. That's the standard AIRLIFT Connect is built around, and it's the standard we think every agency handling resident data should be demanding from every vendor in the chain.
