Thomson Reuters C-Track Data Breach Exposes Court Records Across U.S. States and Ontario

Thomson Reuters has disclosed a cybersecurity incident involving its C-Track court case management platform, after an unauthorized party accessed files containing sensitive court-related information from multiple jurisdictions in the United States and Canada.

The incident affected court systems across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada, according to a September 2, 2026 notification issued by West Publishing Corporation, a Thomson Reuters business.

The unauthorized activity reportedly occurred in March 2026, while West Publishing said it discovered the incident on June 30, 2026.

Thomson Reuters C-Track Data Breach

C-Track is a court case management platform used by various courts to manage electronic filing and court-related information.

According to Thomson Reuters, files stored within its systems were accessed by an unauthorized party. Depending on the affected court, the compromised information could include sensitive personal and court-related data.

Potentially exposed information may include:

  • Names
  • Social Security numbers
  • Driver's license numbers
  • Dates of birth
  • Medical information
  • Health insurance information
  • Case numbers
  • Addresses and phone numbers
  • Court docket information
  • Charge descriptions
  • Other information contained within court databases

West Publishing also warned that certain confidential, redacted, or sealed information may have been affected for some courts.

The company said there is currently no evidence of fraud or misuse of the information.

Which Courts Were Affected?

The incident involved court systems across several U.S. states, the U.S. Virgin Islands, and Ontario.

The affected jurisdictions identified in the vendor's notification include:

Alabama

Alabama Appellate Courts.

Kentucky

Kentucky Appellate Courts.

Montana

Montana Supreme Court.

Nevada

Nevada Appellate Courts.

New Hampshire

New Hampshire Supreme Court.

North Dakota

North Dakota Supreme Court.

Ohio

Multiple Ohio appellate districts, including the First, Second, Third, Fourth, Fifth, Sixth, Seventh, Ninth, Eleventh, and Twelfth District Courts of Appeals.

The Eighth and Tenth District Courts were reported as unaffected.

Pennsylvania

Affected organizations include the Commonwealth of Pennsylvania Environmental Hearing Board, Court of Common Pleas of Washington County, Fifth Judicial District of Pennsylvania, and Court of Common Pleas of Monroe County.

South Carolina

Supreme Court of South Carolina and South Carolina Court of Appeals.

Tennessee

Tennessee Appellate Court Clerk's Office.

Wyoming

Wyoming Judicial Branch.

U.S. Virgin Islands

Supreme and Superior Courts.

Ontario, Canada

The Court of Appeal for Ontario, Ontario Superior Court of Justice, and Ontario Court of Justice.

Minnesota Reports Separate Exposure

Minnesota was not included in the court bodies listed in the West Publishing notification reviewed by The Hacker News.

However, the Minnesota Judicial Branch separately reported that appellate court data was exposed as part of the incident.

Minnesota officials said they terminated Thomson Reuters' access to the courts' electronic environments and required users of the appellate case management system to change their passwords.

Minnesota Supreme Court Chief Justice Natalie Hudson said the court was deeply concerned about the compromise of court users' information.

Backup Data Stored on Thomson Reuters Servers

Several affected courts have provided additional information about where their data was stored.

The Montana Supreme Court said the compromised information consisted of backup data stored on Thomson Reuters servers.

The databases had reportedly been supplied to Thomson Reuters for troubleshooting applications.

The affected databases could contain:

  • Case numbers
  • Names of parties
  • Addresses
  • Phone numbers
  • Charge descriptions
  • Docket entries
  • Driver's license numbers
  • Dates of birth for some individuals charged with crimes

Montana officials said unauthorized access to the storage location occurred between March 1 and June 29, 2026.

Alabama Court Data Found in an Unknown Backup

The Alabama Appellate Courts said Thomson Reuters later informed them that a copy of some Alabama appellate court data was stored in a backup file within the company's cloud environment.

According to the court, the backup had not been requested by Alabama officials and they were not aware that it existed.

Alabama Chief Justice Sarah Stewart emphasized that the incident occurred within the vendor's environment rather than the court's own systems.

Ohio Court Data Was on a Production Platform

The situation appears somewhat different in Ohio.

The Supreme Court of Ohio said Thomson Reuters Court Management Solutions informed the court on August 31 that the unauthorized access occurred on the court's production platform.

That platform hosts filing-system data for the Ohio appellate districts using C-Track.

The Eighth and Tenth appellate districts were not affected.

Ohio officials said they had not yet received comprehensive information regarding the additional security measures implemented by Thomson Reuters.

Ontario Courts Also Investigating the Incident

Ontario's Court of Appeal, Superior Court of Justice, and Court of Justice confirmed that Thomson Reuters detected unauthorized activity within one of its cloud environments.

The courts said it remained unclear what specific information may have been compromised.

Officials warned that individuals involved in court proceedings, or people mentioned within court documents, could potentially have had personal information exposed.

Wyoming Data Dates Back to 2015

The Wyoming Judicial Branch said the compromised material consisted primarily of historical court data involving individuals who interacted with Wyoming courts between 2015 and 2025.

A preliminary review indicated that limited personal information, including names, addresses, and dates of birth, was compromised.

Wyoming officials also provided a dedicated hotline for affected individuals.

Virgin Islands Courts Confirm Historical Data Exposure

The U.S. Virgin Islands courts said they received notification of the incident on July 27.

At the time of their statement, officials could confirm only that the accessed data was related to the courts' 2018 system implementation project.

The courts said the investigation into the potentially affected information was continuing.

Kentucky Court Filing System Not Fully Affected

Kentucky court administrators said trial-court electronic filing was not affected because the state does not rely on third-party vendors for that service.

Officials also said there was no indication that the unauthorized party had distributed Kentucky court data.

North Dakota Confirms Limited Impact

The North Dakota Court System said the incident involved data associated with the North Dakota Supreme Court.

The state's district courts and Odyssey system were not affected.

Officials also said there was no evidence that nCourt, the platform used for financial transactions, had been compromised.

An active criminal investigation into the incident is underway.

Thomson Reuters Says C-Track Remains Operational

Despite the cybersecurity incident, Thomson Reuters said there had been no operational disruption to C-Track.

A Thomson Reuters spokesperson said the company considers the platform safe to continue using.

The company has also implemented additional security measures intended to protect affected environments and prevent further unauthorized access.

Credit Monitoring Offered to Affected Individuals

West Publishing is offering potentially affected individuals 12 months of Experian IdentityWorks credit monitoring.

Enrollment is available until December 31, 2026, according to the notification.

For affected individuals in Canada, Thomson Reuters Canada Limited is offering 12 months of TransUnion myTrueIdentity monitoring.

A Canadian call center is scheduled to open on September 4.

Investigation Into the Data Breach Continues

As of September 3, 2026, authorities and affected organizations had not publicly disclosed:

  • The total number of affected individuals
  • The exact method used to obtain the files
  • The identity of the unauthorized party
  • Whether the stolen information was used or sold
  • The complete scope of the compromised data

Thomson Reuters notified affected courts and Ontario's Ministry of the Attorney General between July 23 and July 27.

Public disclosure followed on September 2, with several jurisdictions issuing statements around the same time.

The incident highlights the cybersecurity risks created when sensitive government and court information is stored and processed through third-party technology providers.

Why the Thomson Reuters C-Track Breach Matters

Court systems routinely handle highly sensitive information, including personal identification details, financial information, medical records, criminal case information, and sealed court documents.

A compromise involving a third-party court technology provider can therefore create significant privacy and security risks even when the affected government organization itself was not directly breached.

The Thomson Reuters C-Track incident also highlights the importance of third-party risk management, cloud security, backup-data protection, access controls, and continuous monitoring for organizations handling sensitive legal and government information.

The investigation remains ongoing, and additional details about the scope and impact of the incident may emerge as affected courts and Thomson Reuters continue their reviews.