Thomson Reuters disclosed on September 2, 2026, that an unauthorized party accessed files from its C-Track court case management platform, exposing sensitive records tied to courts in 11 US states, the US Virgin Islands, and three courts in Ontario, Canada. The disclosure lands in the same week as reporting on a separate 153 million driver’s license breach under FBI investigation, underscoring how frequently large-scale identity exposures are now surfacing across unrelated sectors. The intrusion itself is not new. According to Reuters and The Hacker News, the unauthorized access ran from March 2026 until West Publishing, the Thomson Reuters unit that sells C-Track, caught it on June 30, 2026, a gap of roughly three months during which files including Social Security numbers, medical information, and sealed court filings sat exposed to whoever had gotten in.
Don't miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
What Happened: Inside the C-Track Court Records Breach
C-Track is described on Thomson Reuters’s own legal product page as a court case management system built for digital court record management, used by state and provincial judiciaries to handle filings, dockets, and case workflows, with confidentiality markings meant to restrict sensitive case information to authorized personnel. That last detail matters, because the breach did not just expose ordinary public docket data. According to The Hacker News, West Publishing’s notice stated that certain confidential, redacted, or sealed information may have been impacted for certain affected courts, though the company said it had found no evidence to date of fraud or misuse.
Reuters reported that a unit of Thomson Reuters detected the cybersecurity incident on June 30, based on a company notice and a joint statement from the chief justices of three Ontario courts. The company has not disclosed exactly how many individuals or records were affected, and multiple outlets, including TechRadar Pro, note that Thomson Reuters had not determined the precise scope of accessed data or the number of people affected as of early September.
The Timeline: A Three-Month Gap Between Intrusion and Detection
The reconstructed timeline, drawn from Reuters, The Hacker News, and the security blog Hard2Bit, shows a slow-moving incident that only became public knowledge more than two months after it was caught internally:
- March 1, 2026: Unauthorized access to C-Track files reportedly begins, according to Hard2Bit’s reconstruction of the timeline.
- June 29-30, 2026: West Publishing detects the suspicious activity in its cloud environment and starts an investigation, per The Hacker News and Reuters.
- August 31, 2026: Thomson Reuters Court Management Solutions formally notifies the Supreme Court of Ohio that unauthorized access occurred on the court’s production platform, according to an official statement published by Court News Ohio.
- September 2, 2026: Thomson Reuters issues its public notice, timed alongside statements from affected courts including Ontario’s chief justices and the Montana Supreme Court.
- September 2-4, 2026: Reuters, The Hacker News, TechRadar Pro, BreachNews, and Hard2Bit publish detailed coverage of the breach’s scope and the data types involved.
That roughly three-month window between initial access and detection is a recurring theme in enterprise breaches involving cloud-hosted vendor platforms, and it is one of the details security commentators have focused on in reactions to this incident.
Which Courts and Jurisdictions Are Affected
TechRadar Pro published the most complete list of affected US states, naming Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, and Wyoming, in addition to the US Virgin Islands. In Canada, Reuters reported the incident touched three Ontario courts: the Court of Appeal for Ontario, the Ontario Superior Court of Justice, and the Ontario Court of Justice. Not every court that uses Thomson Reuters products was affected. Court News Ohio specifically clarified that Ohio’s 8th District Court of Appeals (Cuyahoga County) and 10th District Court of Appeals (Franklin County) do not use C-Track and were therefore unaffected, while 10 of Ohio’s 12 Courts of Appeals do rely on the platform.
| Jurisdiction | Type | Status | Source |
|---|---|---|---|
| Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, New Hampshire, Wyoming | US states | Confirmed affected | TechRadar Pro |
| Ohio | US state | 10 of 12 Courts of Appeals affected; 8th & 10th Districts unaffected | Court News Ohio |
| US Virgin Islands | US territory | Confirmed affected | Reuters, TechRadar Pro |
| Ontario (Court of Appeal, Superior Court of Justice, Court of Justice) | Canadian province | Confirmed affected | Reuters |
What Data Was Exposed: SSNs, Medical Records, Sealed Filings
According to The Hacker News’s review of West Publishing’s notice, the potentially exposed data includes names, Social Security numbers, driver’s license numbers, dates of birth, medical information, and health insurance information. BreachNews independently confirmed exposure of SSNs, medical data, and sealed records in the stolen C-Track files. What sets this breach apart from a typical consumer data leak is the presence of sealed and redacted court filings, records that were never meant to be visible outside judicial chambers and authorized court personnel in the first place. That category can include everything from juvenile case records to protective order details to confidential settlement terms, information whose exposure carries risks beyond standard identity theft.
Not every affected court experienced the same type of exposure. The Montana Supreme Court’s September 2 statement, cited by the security blog Hard2Bit, specified that the files reached by the intruder were “copies of the compromised databases, which had been supplied to TR for the purpose of troubleshooting the applications.” In other words, Montana’s exposure involved backup or support copies rather than a live production system. Ohio’s situation was different: Court News Ohio’s statement said Thomson Reuters Court Management Solutions informed the court on August 31 that unauthorized access took place on the court’s production platform itself, the system that actively hosts the filing data for its Courts of Appeals.
How Thomson Reuters and Courts Are Responding
Reuters reported that Thomson Reuters has taken containment steps, engaged external cybersecurity experts, notified law enforcement, and secured the C-Track environment. The company is also offering mitigation to individuals who may be affected. According to The Hacker News, West Publishing is providing 12 months of Experian IdentityWorks credit monitoring for potentially affected individuals through a publicly posted enrollment code and hotline. TechRadar Pro reported that, at the time of its coverage, there was no indication that systems handling court-related financial transactions were affected, no evidence of identity theft tied to the breach, and no threat actor had claimed responsibility for the intrusion or threatened to leak the stolen files.
That combination, no claimed responsibility and no leak-site listing, is notable. It leaves open the possibility that the access was more opportunistic reconnaissance than a targeted extortion operation, though Thomson Reuters and outside investigators have not published a conclusion on attacker motive.
Statements From Thomson Reuters and Court Officials
Reuters quoted a Thomson Reuters spokesperson saying, “There has been no operational disruption to C-Track as a result of this incident,” and that “Our products and services remain fully operational and are safe to continue to use.” The company also said independent cybersecurity experts had validated the remediation measures it implemented.
The chief justices of the three affected Ontario courts issued a joint statement, reported by Reuters, saying Thomson Reuters “detected unauthorized activity in one of its cloud environments” and that “We are advised that Thomson Reuters responded by taking steps to contain the activity, engaging external cybersecurity experts to advise and investigate, notifying law enforcement, and securing the C-Track environment.” Those statements, taken together, describe a fairly standard incident-response playbook: contain, investigate with outside help, notify law enforcement, and secure the environment, but they stop short of confirming the full scope of what was taken or how many people are affected.
Ransomware or Something Else? What We Know About the Attack
Public reporting so far does not classify this as a confirmed ransomware attack. There has been no mention of file encryption, no ransom note, and no leak-site posting by a known extortion group. The Hacker News, Reuters, and BreachNews all describe the event as unauthorized access and file exfiltration rather than a system lockup. Based on the available reporting, the incident is best understood as a data-exfiltration breach: someone got into a Thomson Reuters cloud environment tied to C-Track and pulled files over an extended period before being caught, rather than a smash-and-grab ransomware deployment.
That distinction matters for how affected courts and individuals should think about risk. A ransomware attack typically announces itself immediately through disrupted operations. A quiet, months-long exfiltration means the stolen data could already be circulating privately among criminal buyers well before any public leak site listing appears, if one ever does.
The Third-Party Vendor Risk Problem
One thread running through the coverage is how much of the exposure traces back to support and troubleshooting copies of data rather than core production systems, at least in some jurisdictions. Montana’s case, where the compromised files were database copies supplied to Thomson Reuters for application troubleshooting, is a textbook example of a problem that shows up repeatedly in vendor-risk assessments: sensitive data that leaves its primary, hardened environment for a legitimate support purpose often ends up with weaker controls than the system it came from. Hard2Bit’s analysis frames this as a broader lesson for any organization that hands vendors live or near-live copies of sensitive databases for debugging, since those copies can become the softest target in the entire chain.
Ohio’s experience shows the other side of the risk: even production systems, not just backup copies, were reportedly accessed in at least one jurisdiction. That combination, some courts exposed through support copies and at least one through a production platform, suggests the intrusion was not confined to a single narrow access point, which is part of why the investigation has taken months to characterize publicly.
Regulatory and Legal Exposure Across 11 States and Canada
Because the exposed data spans 11 US states, a US territory, and an Ontario court system, the breach potentially triggers a patchwork of different state data-breach notification laws in the US alongside Ontario’s provincial privacy framework in Canada. Reuters and TechRadar Pro both report that relevant authorities have been notified, and Thomson Reuters has stated it notified law enforcement as part of its response. As of this reporting, no outlet has confirmed specific fines, consent decrees, or enforcement actions from state attorneys general, Canadian privacy regulators, or federal agencies. Given the sensitivity of the exposed categories, particularly sealed court filings and medical information, that could change as individual state investigations proceed on their own timelines. Regulatory follow-through on breaches like this can take months to materialize into real penalties; the Fidelity data breach settlement, which produced $3.75 million in combined fines, is a recent example of how long that process can run before dollar figures appear.
Market Impact: Thomson Reuters Investor Reaction
Financial coverage of the incident has been comparatively muted. Seeking Alpha reported the breach as a news item for investors, framing it as a cybersecurity incident affecting the C-Track platform, but did not report a specific stock price move tied to the disclosure. No outlet in this reporting cycle has published a confirmed percentage decline or dollar-figure market reaction for Thomson Reuters shares (ticker TRI) directly attributable to the breach. That relatively contained financial reaction likely reflects two factors reporters have emphasized: the company’s insistence that C-Track remains fully operational with no service disruption, and the fact that the affected product, court case management software sold to government judiciaries, represents a narrower slice of Thomson Reuters’s overall business than its larger legal, tax, and news information segments.
Historical Context: Court Systems as a Growing Target
Reporting on this incident does not point to a prior, comparably large breach specifically involving Thomson Reuters’s C-Track platform, suggesting this is the first widely covered, multi-jurisdiction exposure of its kind for this particular product. But the broader pattern, of court and legal-record systems becoming attractive targets, fits a trend that has been building for several years as judiciaries digitize case files that were once paper-only. Sealed records, juvenile case files, and protective order details were historically protected simply by being physically inaccessible, locked in a courthouse filing cabinet rather than stored in a searchable cloud database. Digitization brought efficiency for courts and legal researchers, but it also concentrated decades of sensitive judicial data into systems that, as this incident shows, can be accessed by outsiders for months before anyone notices. It joins a run of 2026 mega-breaches that includes the 8.7 million-record airports hack and the healthcare-sector McKesson breach, both of which similarly involved third-party data exposure at a scale that outpaced the affected organizations’ ability to quantify the damage quickly.
Competitive Landscape: Court Case Management Vendors Under Scrutiny
Thomson Reuters’s C-Track competes in a niche but consequential market of court case management systems sold to state and provincial judiciaries, a category that also includes other government-focused case management and e-filing platforms used across US state courts. This breach is likely to put every vendor in that category under renewed scrutiny from court administrators, not just Thomson Reuters. Courts evaluating case management vendors are likely to ask sharper questions going forward about how long support and troubleshooting copies of data are retained, whether those copies are encrypted and access-logged to the same standard as production systems, and how quickly a vendor commits to detecting and disclosing unauthorized access. The Montana Supreme Court’s disclosure about troubleshooting copies, in particular, is likely to become a reference point other courts cite when negotiating data-handling terms with any case management vendor, not just Thomson Reuters. It’s part of a broader pattern tracked across this year’s cybersecurity threat landscape, where third-party and vendor-side exposure has become as consequential as direct attacks on primary targets.
What Affected Individuals Should Do
If you have been a party, witness, juror, or otherwise involved in a court case in Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming, the US Virgin Islands, or Ontario since 2026 began, security guidance points to a few concrete steps.
- Check for a direct notification. West Publishing is reportedly notifying individuals whose data may have been affected and providing an enrollment code for credit monitoring.
- Enroll in the offered credit monitoring. The Hacker News reports West Publishing is providing 12 months of Experian IdentityWorks monitoring at no cost to eligible individuals.
- Place a credit freeze if you handled a case involving SSNs or financial disclosures. This is a free protection available through Equifax, Experian, and TransUnion in the US, or Equifax Canada and TransUnion Canada for Ontario residents.
- Be alert to unusual contact referencing your case. Because sealed or confidential filings may be involved, individuals with sensitive case history (family court, protective orders, juvenile matters) should be especially cautious of unsolicited contact that references specific case details.
- Watch official court communications. Court News Ohio’s public statement is an example of how individual courts are communicating directly with affected parties; check your state court system’s website for similar notices.
- Organizations handling similar vendor risk should audit their own exposure. IT and security teams can start with a basic vulnerability scan of systems that share data with third-party case management or verification vendors.
What Happens Next: Predictions
Based on how the story has developed so far and how comparable multi-jurisdiction breaches have typically played out, here is what is likely over the coming weeks:
- More states will issue individual notifications. Expect additional statements similar to Ohio’s and Montana’s from the remaining affected states as each judiciary completes its own review of what C-Track data it stored.
- Class action filings are likely. Given the presence of SSNs and sealed records, plaintiffs’ attorneys are likely to file suits against Thomson Reuters or West Publishing in one or more affected states, following the pattern seen in other recent large-scale breaches.
- Court vendor contracts will face new scrutiny. State court administrators are likely to revisit data-retention and support-copy handling terms with C-Track and competing case management vendors.
- A firmer number on affected individuals will eventually surface. Thomson Reuters has not yet disclosed a specific record count; that figure typically emerges as state notification requirements force more precise disclosure.
- Limited near-term stock impact, unless new facts emerge. Absent a confirmed large-scale identity theft campaign traced to this data, the market reaction is likely to remain muted, consistent with the coverage so far.
| Date | Event | Source |
|---|---|---|
| March 1, 2026 | Unauthorized access to C-Track files reportedly begins | Hard2Bit |
| June 30, 2026 | West Publishing detects the intrusion in its cloud environment | Reuters, The Hacker News |
| August 31, 2026 | Ohio Supreme Court formally notified of access to its production platform | Court News Ohio |
| September 2, 2026 | Thomson Reuters issues public notice; Ontario and Montana courts issue statements | Reuters, Hard2Bit |
| September 3-4, 2026 | Widespread security and financial press coverage of scope and data types | The Hacker News, TechRadar Pro, BreachNews, Seeking Alpha |
Frequently Asked Questions
What is C-Track and who uses it?
C-Track is a court case management system sold by West Publishing, a Thomson Reuters unit, to state and provincial judiciaries for managing case filings, dockets, and confidential case information.
Which states and regions were affected?
TechRadar Pro reported Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming, and the US Virgin Islands, along with three Ontario, Canada courts, per Reuters.
Was this a ransomware attack?
No ransomware, encryption, or extortion demand has been publicly confirmed. Reporting describes it as unauthorized access and file exfiltration rather than a ransomware deployment, and no threat actor had claimed responsibility as of this reporting.
How many people are affected?
Thomson Reuters had not disclosed a specific number of affected individuals or records as of early September 2026, according to TechRadar Pro and other outlets.
What kind of data was exposed?
Reported categories include names, Social Security numbers, driver’s license numbers, dates of birth, medical and health insurance information, and confidential or sealed court filings, according to The Hacker News and BreachNews.
Is C-Track still operational?
Yes. Thomson Reuters told Reuters there has been no operational disruption and that the platform remains fully operational and safe to use.
What is Thomson Reuters offering affected individuals?
According to The Hacker News, West Publishing is offering 12 months of free Experian IdentityWorks credit monitoring to potentially affected individuals through a posted enrollment code and hotline.
Why were some courts affected differently than others?
The type of exposure varied. Montana’s Supreme Court said the accessed files were troubleshooting copies of its databases, while Ohio’s Supreme Court said the intrusion affected its live production platform, according to Hard2Bit and Court News Ohio respectively.


