Thomson Reuters C-Track Breach Exposes US and Canadian Court Records
Thomson Reuters disclosed that an unauthorized party accessed its C-Track court case management platform from March through June 2026, potentially exposing names, Social Security numbers, medical data and sealed court records from appellate courts in 11 US…
Thomson Reuters (via its West Publishing unit, per The Hacker News) disclosed that an unauthorized party obtained files from its C-Track court case management platform. The company detected the unauthorized access on June 30, 2026 and disclosed the incident on September 2, 2026; according to Montana's notification account, access to one C-Track environment ran from March 1 through June 29, 2026. Notification letters name roughly 24 court bodies, including appellate courts in Minnesota, Ohio, Montana and Pennsylvania, with affected jurisdictions spanning appellate courts in 11 US states (The Record says 'at least 12 US states' — sources disagree on the count), the US Virgin Islands, and files tied to three Ontario courts in Canada. Exposed data may include names, Social Security numbers, driver's license numbers, dates of birth, medical and health insurance information, and confidential or sealed court records. Thomson Reuters says the courts' own networks were not the cause, financial transaction systems were not impacted, and C-Track remained operational throughout, and it has found no evidence of fraud or misuse to date; the intrusion method, attacker identity and number of affected individuals remain unknown, and the investigation into exact scope is ongoing. Affected individuals are being offered 12 months of free credit monitoring — Experian or TransUnion per The Hacker News, with The Record also citing identity theft protection. Sources note courts disagree over whether the vendor's backup cloud environment or the production platform was accessed — Ohio courts say the production platform was hit — and Minnesota has revoked Thomson Reuters access and forced password resets.
- Thomson Reuters disclosed on September 2, 2026 that an unauthorized party obtained files from its C-Track court case management platform; the unauthorized access was detected on June 30, 2026.
- Per Montana's notification account, access to one C-Track environment ran from March 1 through June 29, 2026; The Record reports the activity ran from March through June 2026.
- Notification letters name roughly 24 court bodies, including appellate courts in Minnesota, Ohio, Montana and Pennsylvania (The Hacker News).
- Scope is reported as appellate courts in 11 US states plus the US Virgin Islands (Infosecurity Magazine, The Hacker News); The Record says 'at least 12 US states' — sources disagree on the state count.
- In Canada, files tied to three Ontario courts were breached (Infosecurity Magazine).
- Data potentially exposed includes names, Social Security numbers, driver's license numbers, dates of birth, medical information, health insurance details, and confidential or sealed court records.
- Thomson Reuters says the courts' own networks were not the cause and financial transaction systems were not impacted; no evidence of fraud or misuse has been found to date.
- C-Track remained operational throughout the incident and court operations were not disrupted.
Coverage timelineoldest first · each row is one article
- · 13d agoUS and Canadian Court Records Breached Following Thomson Reuters Incident
Infosecurity Magazine· 76
Thomson Reuters disclosed a breach of its C-Track court software exposing sensitive case records across Ontario courts and 11 US states.
- · 13d agoUS and Canadian court data exposed in Thomson Reuters breach
The Record· 75
Thomson Reuters disclosed a breach of its C-Track court platform exposing sealed court records and personal data across 12+ US states and Canada.