Thomson Reuters' C-Track court case-management platform breach reaches at least 13 US states, the US Virgin Islands and three Ontario courts
Thomson Reuters' West Publishing subsidiary disclosed on 2026-09-02 that an unauthorized party obtained files from C-Track, its court case-management SaaS platform, in March 2026, discovered on 30 June 2026 (C-Track official notice, 2026-09-02). Public disclosure did not follow until 64 days after that detection date; Thomson Reuters separately advised Ontario's Ministry of the Attorney General of the Ontario courts' exposure on 23 July 2026, itself 23 days after detection and still six weeks before any public notice (Tech Times, 2026-09-04; Ontario Courts, 2026-09-02). West Publishing's notice (C-Track official notice, 2026-09-02) names 24 affected court bodies: appellate courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio (ten of twelve appellate districts, per Tech Times, 2026-09-04), Pennsylvania (several county-level courts plus one former client), South Carolina, Tennessee, Wyoming and the U.S. Virgin Islands Supreme and Superior Courts, plus three Ontario courts (the Court of Appeal, Superior Court of Justice and Court of Justice) disclosed in a parallel notice by their Chief Justices (Ontario Courts, 2026-09-02). Neither Minnesota nor Oregon appears in West Publishing's own list above; both states' courts disclosed the exposure independently, bringing the count to at least 13 US states. Minnesota's Judicial Branch disclosed independently that its appellate courts were affected; a gap the company has not publicly explained (Tech Times, 2026-09-04). Oregon's Judicial Department likewise disclosed its appellate courts were affected, and Oregon's Chief Justice Meagan Flynn called the incident unacceptable and demanded full accountability from Thomson Reuters (Tech Times, 2026-09-04). Potentially exposed data includes names, Social Security numbers, driver's license numbers, dates of birth, and medical and health-insurance information; the company states certain confidential, redacted or sealed information may have been impacted for certain affected courts. The exposure's scope varies further by jurisdiction: Nevada officials said the type of data involved differs court by court and cautioned against assuming what was exposed in one state was exposed in another, while Montana officials said most of their affected information already appeared to be publicly available, though some driver's license numbers and dates of birth were also involved (The Record, 2026-09-03). As of 2026-09-04, no party (Thomson Reuters, law enforcement, or any affected court) had published the method by which the files were obtained or the identity of whoever was responsible (The Hacker News, 2026-09-04); The Record separately confirms Thomson Reuters itself has not said how the attacker gained access (The Record, 2026-09-03).
Individual court statements reveal the exposure was architecturally inconsistent across jurisdictions: West Publishing told Alabama's Appellate Courts that their data existed as a copy held "in a backup file within the company's cloud environment," which Alabama's Chief Justice said her courts had "neither requested nor known about"; Montana's court reported the same backup/troubleshooting-copy pattern, stating the material taken was drawn from database copies "supplied to TR for the purpose of troubleshooting the applications" (The Hacker News, 2026-09-04). Montana and Minnesota each stated that court documents specifically were not part of the accessed data (The Hacker News, 2026-09-04), though West Publishing's own notice states sealed material may have been affected for certain courts. The Supreme Court of Ohio, by contrast, was told by Thomson Reuters Court Management Solutions that "the unauthorized access took place on the Court's production platform", the live system hosting current filing data for its ten affected appellate districts, not a backup (Tech Times, 2026-09-04). Minnesota responded by terminating Thomson Reuters' access to its court systems outright and forcing a password reset for all C-Track users; North Dakota confirmed an active criminal investigation (The Hacker News, 2026-09-04). Thomson Reuters is offering 12 months of Experian credit monitoring to affected US individuals (C-Track official notice, 2026-09-02) and a parallel 12-month TransUnion Canada myTrueIdentity membership to affected Canadian individuals (C-Track Canada notice, 2026-09-02), and states C-Track remains fully operational, though Ohio's court says it has not yet received details of the security measures the vendor told it had been deployed (Tech Times, 2026-09-04).
This is not the first time Thomson Reuters has accumulated personal data beyond what affected individuals authorized: in February 2025 a federal judge granted final approval to a $27.5 million class-action settlement over the company's CLEAR platform, which had collected identifying data on roughly 40 million Californians and sold access to it as a law-enforcement and investigative tool without subject consent (Tech Times, 2026-09-04). The mechanism differs (backup copies from routine SaaS operations here, deliberate data aggregation there) but both cases show data accumulating in Thomson Reuters' systems beyond what the affected individuals knew about or authorized.
Certain confidential, redacted or sealed information may have been impacted for certain affected courts.
Thomson Reuters has not said how the attacker gained access, who was responsible or how much data was taken.
in a backup file within the company's cloud environment
neither requested nor known about
the unauthorized access took place on the Court's production platform
deeply troubled that our court users' data has been compromised