VMTech
Discuss a project

Thomson Reuters C-Track breach may expose court data

Thomson Reuters C-Track breach may expose court data

Thomson Reuters has disclosed that an unauthorized party obtained files from C-Track, a court case management platform sold by its West Publishing Corporation unit. The incident may affect court systems in 11 U.S. states, the U.S. Virgin Islands and Ontario, Canada. West Publishing said it discovered the activity on June 30, 2026, after the files were accessed in March.

The company said a subset of court records could contain names, Social Security numbers, driver’s licence numbers, dates of birth, medical information and health-insurance information. Its September 2 notice also warned that confidential, redacted or sealed information may have been affected for certain courts. West Publishing said it has no evidence to date of fraud or misuse.

Courts report different data environments

Public statements from affected jurisdictions provide different descriptions of the systems involved. Montana’s Supreme Court said the material taken was backup data stored on Thomson Reuters servers. The copies had been supplied to the vendor for application troubleshooting and may have included case numbers, party contact details, charge and docket-entry descriptions, and, for some criminal defendants, driver’s licence numbers and dates of birth.

Montana said unauthorized access to that storage location ran from March 1 through June 29. Alabama Appellate Courts likewise said a copy of some appellate court data was retained in a backup file in the vendor’s cloud environment, a backup the courts said they had not requested or known about.

Ohio described a different location. The Supreme Court of Ohio said Thomson Reuters Court Management Solutions told it on August 31 that unauthorized access occurred on the court’s production platform, which hosts filing-system data for 10 Ohio appellate districts using C-Track. The Eighth and Tenth districts were not affected. The Ohio court said it had not yet received comprehensive details of the enhanced security measures the vendor said it had deployed.

Scope remains unclear across jurisdictions

The notices name appellate and other court bodies in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee and Wyoming, alongside courts in the U.S. Virgin Islands and Ontario. Minnesota’s Judicial Branch separately said appellate-court data was exposed, terminated Thomson Reuters access to its electronic environments and instructed users of its appellate case-management system to change passwords.

Ontario’s three chief justices said Thomson Reuters detected activity in one of its cloud environments and that it remains unclear what information may have been compromised. They said people involved in court proceedings or mentioned in court documents could have had personal information affected. Wyoming said its preliminary review indicated limited personal information from historical data, primarily relating to people who dealt with its courts between 2015 and 2025.

North Dakota said only its Supreme Court data was involved; district courts, the Odyssey system and the nCourt financial-transaction system were not affected. The North Dakota Court System also said there is an active criminal investigation. As of September 3, no affected-person count, access method or responsible party had been publicly identified.

Support measures and vendor oversight

West Publishing is offering potentially affected U.S. individuals 12 months of Experian IdentityWorks credit monitoring, with enrolment open until December 31, 2026. Thomson Reuters Canada Limited is offering 12 months of TransUnion myTrueIdentity monitoring, with its call centre scheduled to open on September 4.

For organisations that entrust sensitive records to software suppliers, the incident underlines the practical need to document what copies and backups a vendor retains, where those environments operate, and how quickly the vendor must provide verified scope details after an incident.

#databreach#courtsecurity#vendorrisk#privacy
Open analytics
On the site 0 views
min read 4 03.09.2026
Instagram

Thomson Reuters C-Track breach may expose court data

Open the post on Instagram ↗