Kentucky courts filing system part of ‘cybersecurity incident,’ judicial branch officials say

Image
PROMO 660 x 440 Tips - Computer Keyboard Padlock Technology - iStock
iStock
(Kentucky Lantern)

The Kentucky Administrative Office of the Courts said the system used for files for the Kentucky Supreme Court and Court of Appeals “experienced a cybersecurity incident.”

AOC said it was notified by the company Thomson Reuters Court Management Solutions about the incident within the company’s C-Track system files. The company said an unauthorized third party accessed and obtained court data from multiple states, including Kentucky Appellate Court data.

A company notice about C-Track said the unauthorized activity was discovered on June 30 and data had been accessed in March from courts in Kentucky, Alabama, Pennsylvania, Montana, Nevada, North Dakota, South Carolina, Tennessee, New Hampshire, Ohio, Wyoming and the U.S. Virgin Islands. Some records may contain individuals’ names and personal information like Social Security number, driver’s license number, medical information, date of birth and health insurance information, the notice said.

Image
Court gavel on a strike plate, with the Scales of Justice and books in the background
© iStock - simpson33

As of Wednesday, the number of individuals and organizations affected is not known, the AOC statement said.

“Kentucky Appellate Courts were not functionally impaired by this incident,” the AOC statement said. “The AOC has no indication at this point that the unauthorized third party distributed the Kentucky data to any other party or entity. Thomson Reuters CMS is working with third-party experts and law enforcement and has assured each affected jurisdiction that it has taken significant mitigation steps to prevent unauthorized access to the data in the future.”

As Kentucky does not use third-party vendors for trial court e-filing, trial information not in an appeals case is not affected by this, AOC said. Any person determined to be affected by the incident will be notified by Thomson Reuters CMS with further information and a year of credit monitoring and identity theft protection.

Thomson Reuters CMS is leading the investigation and AOC is cooperating with it to identify Kentucky data involved.