Breached in March. Courts told in July. Public told in September.
Three of this year’s worst disruptions to local government didn’t start on a single city network. They started at a software vendor. That changes what “we’re covered” has to mean.
In early September, Thomson Reuters disclosed that an intruder had been inside the cloud environment behind C-Track — the case management platform a number of state appellate courts run on — for roughly three months.
The C-Track timeline
At least twelve U.S. jurisdictions were affected, along with the U.S. Virgin Islands and courts in Ontario. The data potentially exposed includes names, Social Security numbers, driver’s license numbers, dates of birth, medical information and health insurance information — and, per reporting on the disclosure, confidential, redacted or sealed court records. Thomson Reuters says the platform itself was never disrupted and that it has seen no evidence of fraud so far, and is offering twelve months of credit monitoring.
Georgia was not among the jurisdictions reported affected, though reporters noted the list was still growing as individual courts issued their own notices.
Here is the part worth sitting with. Every court on that list had its own IT. Some of them had very good IT. None of it was the deciding factor. The records left through a door none of those courts owned, on a clock none of them controlled.
It wasn’t a one-off. It was the third time this year.
February
BridgePay Network Solutions — a payment processor — was hit with ransomware, and card payments went dark for cities, utilities and counties across several states, including Denton, Coppell and Frisco in Texas, Grand Traverse County in Michigan, Wichita, Kansas, and Clackamas County, Oregon, which told customers plainly that nobody would be charged a late fee because of the outage. BridgePay reported no payment card data was compromised. Residents still could not pay a water bill online.
May
Instructure's Canvas — the learning platform — was breached on April 25, detected April 29, disclosed May 1, and hit again on May 7 with a ransom message on the login screen. Georgia was squarely on this one: Fulton, DeKalb, Cherokee and Forsyth county school systems, Georgia Virtual School, Georgia Tech and Emory were among those affected. Instructure said passwords, Social Security numbers and financial information were not involved. Districts pulled access during final exams out of caution.
September
Thomson Reuters C-Track, above.
48%
of breaches involved a third party
Up from 30% the year before. (Verizon 2026 Data Breach Investigations Report, published in May)
31%
entered through a software vulnerability
Now the single most common way in, passing stolen credentials for the first time in the report's nineteen-year history.
Your IT provider secures the part of the system you can walk up to and touch. Increasingly, that is not where your data lives.
The assumption that quietly stopped being true
“We have managed IT, so we’re covered” was a reasonable sentence ten years ago, when the servers were in the closet down the hall. Managed IT covers your network, your endpoints, your accounts, your patching and your backups. That is real work, and it stops most of what comes at a small agency. It does not cover the vendor’s cloud. Nobody’s endpoint agent runs on Instructure’s servers, and no local backup restores a platform you don’t host.
Meanwhile, look at what a small city, county or district actually runs on today: utility billing, court case management, CAD and records, the learning platform and student information system, payroll, the permit portal, the pay-by-phone line, camera and alarm monitoring, email. Nearly all of it is somebody else’s cloud. The perimeter your provider defends is no longer the perimeter your operations depend on.
Why it lands on your desk and not the vendor’s
Under Georgia’s breach notification statute (O.C.G.A. §§ 10-1-910 to -912), the obligation to notify affected individuals runs to the entity that collects the data — the agency, the district, the business — not to whoever happened to be hosting it. A party maintaining covered information on a data collector’s behalf is required to notify that collector within 24 hours of discovering a breach.
So when the vendor is the one that gets hit, the letters still go out over your letterhead. Your clerk’s phone rings. Your council meeting gets the questions. And that 24-hour clause is worth exactly what your contract and your willingness to enforce it are worth. In the C-Track case, the reported gap between the vendor’s discovery and notification of some courts was over three weeks.
A note before you act: This is general information, not legal advice — confirm the specifics with your attorney.
What to do, in this order
Build the list of what isn't yours
One page. Every system holding your data that does not run on your network: billing, court, CAD/RMS, payroll, SIS and LMS, permits, payment processing, email, backup, camera cloud, alarm monitoring. If that page doesn't exist, nothing else on this list can happen.
Put a human name next to each one
For every vendor: a named contact, a direct number, and their public status page URL — not the general support queue, which on the morning of an outage is where you wait in line behind everyone else.
Read the breach clause in each contract
Four questions: How fast must they tell you? What must they tell you? Who pays for notification and credit monitoring? Will they cooperate with your investigation? If the clause isn't there, it goes on the renewal list now, not next budget cycle.
Decide your day-one workaround before you need it
For each system, write down what happens the morning it's gone. Payments: drop box, phone, counter — and a written decision on late fees, which Clackamas County published within days. Court and dispatch: paper forms, printed rosters, where they're stored. Nobody improvises this well at eight in the morning.
Turn on MFA and single sign-on at every vendor portal
This is the one control that is genuinely yours rather than theirs, and it keeps working when the vendor's environment is the compromised one. Where SSO is supported, use it, so you can cut access from your side in one step.
Assign someone to watch the vendors
Somebody has to own the question “did any of our vendors publish a notice this week?” If no one owns it, put it in your managed services scope in writing. An MSP watching only your network is watching a shrinking share of your risk.
Check your cyber policy for dependent business interruption
Many policies cover an outage on your systems and treat a vendor's outage differently, or not at all. Ask your carrier about third-party and dependent business interruption coverage before renewal, not after an incident.
Georgia schools and local governments: state cyber grant money is real and it has been flowing
On March 25, 2026, GEMA/HS and the Georgia Technology Authority announced $9,873,903 in State and Local Cybersecurity Grant Program awards to 44 entities, with emphasis on K-12. The same announcement cited a Center for Internet Security analysis finding 82% of reporting K-12 organizations experienced cyber threat impacts between July 2023 and December 2024.
Application windows and match requirements have shifted between funding years, and the program’s federal reauthorization has been moving through Congress. Confirm current dates and eligibility directly with GEMA/HS before you plan a budget around them.
What this is not
This is not an argument for hauling servers back into a closet. A vendor-hosted platform is usually more secure than what a five-person city can operate on its own, and the aging box under a desk running an unpatched OS fails in cheaper and more frequent ways. The argument is narrower: moving a system to someone else’s cloud moved the risk. It did not delete it. Your response plan has to move with it — and a plan built around “restore from backup” does not survive contact with an incident that happened somewhere you cannot restore.
If nobody has built your list, we’ll build it with you
Southern Technology Partners is a managed services provider and low-voltage contractor based in Hazlehurst, serving cities, counties, utilities, 911 centers, fire and EMS agencies, schools and small businesses within roughly 100 miles. Fully managed IT, cybersecurity and compliance, cloud and telecom, cabling, cameras and access control, fire and alarm — so when a vendor outage becomes an operations problem, we’re not handing you off to another contractor.
Call and we’ll walk your vendor inventory, your contract breach clauses and your day-one workarounds with you. You don’t have to be a client to ask.
Sources
- 1.The Record — US and Canadian court data exposed in Thomson Reuters breach.
- 2.Help Net Security — Thomson Reuters reveals breach that exposed U.S. and Canadian court records (Sept. 3, 2026).
- 3.FOX 9 Minneapolis–St. Paul — MN court data breach: private user data exposed after third-party vendor hacked.
- 4.Government Technology — Cyber attack disrupts local government payment systems (Feb. 11, 2026).
- 5.Clackamas County Water Environment Services — Temporary service disruption for payments.
- 6.The Atlanta Journal-Constitution — Georgia schools, colleges affected by cyberattack on online classroom platform (May 2026).
- 7.Verizon — 2026 Data Breach Investigations Report newsroom summary (May 19, 2026).
- 8.Dark Reading — Third-party breaches teach education sector a costly lesson in vendor risk (June 27, 2026).
- 9.Davis Wright Tremaine — Georgia data breach notification statute summary (O.C.G.A. §§ 10-1-910 to -912).
- 10.GEMA/HS — Nearly $9.9 million in cybersecurity grants awarded to Georgia schools and state/local entities (March 25, 2026).
- 11.GEMA/HS — State and Local Cybersecurity Grant Program (SLCGP).
- 12.National Association of Counties — Congress considers bills to reauthorize the State and Local Cybersecurity Grant Program.
