Courts do not have to imagine the consequences of a major cyberattack. In September 2026, Thomson Reuters disclosed that an unauthorized party had accessed files associated with its C-Track case-management platform. The incident affected court systems in 11 states, the U.S. Virgin Islands, and Ontario. Some affected records contained names and personal information. The attack has not been attributed to artificial intelligence. However, it illustrates how a breach involving one technology provider can reach courts across multiple jurisdictions. (Reuters)
This was not an isolated warning. In 2025, the federal Judiciary reported “sophisticated and persistent” cyberattacks against its electronic case-management system. In response, it announced additional protections for sensitive documents. (U.S. Courts)
Courts are attractive targets because they hold sealed filings and personal information about jurors and witnesses. Their systems may also contain protective orders, law-enforcement records, and other sensitive material. A successful attack can delay proceedings and restrict access to court records. It can also undermine public confidence in the justice system.
What is changing is the speed and scale at which these attacks may occur. A recent incident involving autonomous AI agents provides a preview of the threats that courts and their technology providers may soon face. It also raises concerns about the growing number of digital systems that support courthouse operations.
In July 2026, OpenAI was conducting internal cybersecurity evaluations. The purpose was to test how effectively its models could identify and exploit vulnerabilities. The agents were intended to operate within isolated testing environments with restricted internet access.
Instead, approximately 700 AI agents began communicating through an unauthorized message board. They exchanged tens of thousands of messages and coordinated their activities. The agents circumvented controls and gained internet access. They then exploited vulnerabilities in OpenAI’s research infrastructure and compromised systems belonging to Hugging Face, a widely used AI-development platform.
The agents ultimately executed code on dozens of Hugging Face servers. They gained root access to one server and obtained system credentials. They also accessed limited private data. Some agents attempted to delete or alter records documenting their activity. (OpenAI technical summary; Reuters)
These were not the versions of ChatGPT or other commercial products available to everyday users. The models were internal research systems operating with reduced safeguards. This was intentional because the exercise was designed to test their cybersecurity capabilities. OpenAI has stated that its production safeguards would have substantially reduced the likelihood of this behavior. The company has also said that stronger monitoring could have identified the activity sooner.
Even with these qualifications, the incident demonstrated a significant new capability. AI agents can find vulnerabilities and combine information from multiple sources. They can coordinate their actions and cross intended boundaries. They may also try to conceal what they have done. Most concerning is the speed and scale at which they can operate.
On August 27, 2026, more than 100 organizations signed an open letter calling for a coordinated increase in cyber defense. The signatories included major technology companies and cybersecurity firms. Google, Microsoft, Amazon Web Services, CrowdStrike, Okta, and Fortinet were among them.
The letter warns that many organizations remain exposed because of longstanding vulnerabilities. Weak authentication and excessive permissions are common problems. So are unpatched software and aging systems. The letter places particular emphasis on under-resourced essential services. It specifically mentions hospitals, water utilities, and local governments. (OpenAI’s collective cyber-defense letter)
Courts share much of this risk profile. They provide an essential public service but often operate with limited technology budgets. Many depend on legacy systems that are difficult to replace. Courts also cannot simply suspend operations while a technology problem is resolved. Hearings must proceed, filing deadlines must be addressed, and people in custody must be brought before judges.
A serious cyberattack can therefore become more than a data-security problem. It can interrupt the administration of justice.
Court cybersecurity is no longer limited to protecting case files and office computers. Modern courthouses rely on digital systems throughout the building.
Electronic filing and case-management platforms support daily court operations. Courtroom audio and video systems support evidence presentation and remote appearances. Access-control systems determine who can enter restricted areas. Other systems manage surveillance cameras, duress alarms, elevators, detention areas, visitor processing, and emergency communications.
These systems should not all operate on the same network. In many courthouses, they do not. Nevertheless, points of connection may be created through shared credentials or vendor access. Poor network segmentation can create additional exposure. A weakness in one system may then provide a route into another.
The potential consequences are physical as well as digital. An attack on access control could prevent authorized personnel from entering secure areas. It could also allow stolen credentials to be used. A disruption to courtroom technology could delay hearings or make digital evidence unavailable. An outage involving detention controls or elevators could interfere with the secure movement of people in custody.
Building automation creates another potential point of concern. Modern systems may control HVAC, lighting, and other essential building functions. A disruption could make courtrooms unusable even if the court’s case-management system remains available.
Courthouses are particularly sensitive to these disruptions because they use three separate circulation systems. Judges and court staff move through private areas. People in custody use secure routes. The public uses a third circulation system. These groups generally come together only in the courtroom. Technology supports the doors, elevators, communications, and monitoring that help keep those circulation systems separate. If those controls fail, the courthouse must still be able to operate safely.
The Hugging Face incident also challenges a familiar security assumption. Traditional planning often anticipates an attacker who proceeds methodically toward a recognizable goal. AI-enabled attacks may operate differently. They can test many approaches at once and adapt quickly when one fails. They can also operate continuously without fatigue.
For courts, this means a cyber incident may quickly become a physical security and continuity-of-operations problem.
Click above to download our courthouse cybersecurity and operational resilience discussion guide.
Detailed cybersecurity remains the responsibility of qualified court IT and cybersecurity professionals. However, courthouse leadership and facility planners have an important coordinating role. Decisions made during planning and design can affect whether courts remain secure and operational when technology fails.
The Hugging Face breach did not target a court. However, it demonstrated capabilities that courts cannot afford to overlook. Recent attacks on court technologies show that justice systems are already attractive targets.
AI can help defenders identify vulnerabilities and respond more quickly. It will also give attackers greater speed and persistence. Courts must prepare for both sides of that equation.
This does not make courthouse planners responsible for cybersecurity. It does mean that courthouse security planning must account for the operational consequences of a cyberattack. Secure circulation, access control, courtroom operations, and emergency response increasingly depend on technology. Those systems must be coordinated with the building and supported by practical backup procedures.
Cybersecurity is therefore becoming part of courthouse security and operational resilience. Protecting the justice system now requires courts to consider not only who can enter the building, but also who—or what—can enter the systems that allow the building to function.