Thomson Reuters Court Data Breach Exposed Files From 11 U.S. States and Canada
- The Mess: An unauthorized party accessed files stored in Thomson Reuters’ C-Track case management environment. The intrusion began in March 2026, but Thomson Reuters did not detect the unauthorized activity until June 30.
- The Damage: Court records may contain names, personal information and, in some cases, confidential, redacted or sealed material, turning a software-vendor breach into a potential privacy problem for people involved in court proceedings.
- The Fix: Organizations using C-Track should review the incident notices, determine which records were affected, enforce credential resets where applicable and treat the vendor environment as a compromised third-party dependency.
Court data just became someone else’s problem.
Then everyone else’s problem.
Thomson Reuters has confirmed a cybersecurity incident involving its C-Track case management platform, which is used by courts to store and manage digital case records. The company says an unauthorized party obtained certain C-Track files in March 2026. The intrusion was discovered on June 30.
The affected environment is not some obscure development server.
C-Track sits inside court operations.
And the affected footprint stretches across multiple jurisdictions.
Reuters reports that the incident affected courts in 11 U.S. states, the U.S. Virgin Islands and Canada. The U.S. jurisdictions identified include Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee and Wyoming.
Ontario’s courts were also affected.
The Court of Appeal for Ontario, Ontario Superior Court of Justice and Ontario Court of Justice all use C-Track for some court documents and records. Ontario’s three chief justices confirmed that Thomson Reuters detected unauthorized activity in its cloud environment on June 30 and subsequently determined that some Ontario court information had been accessed.
The timeline is uncomfortable.
According to the investigation, the attacker obtained certain files in March.
Thomson Reuters discovered the unauthorized activity roughly three months later.
And the public disclosure came in early September.
That gap matters because court systems contain information that is far more sensitive than the typical customer database.
The C-Track notification says affected records may contain individuals’ names and personal information. It also warns that certain confidential, redacted or sealed information may have been impacted for some courts.
That does not mean every court record was exposed.
It does not mean every person mentioned in those records was affected.
And it does not mean all of the potentially accessible information was actually taken.
The investigation is still determining the exact scope.
That distinction is important.
Thomson Reuters has not published a final number of affected individuals, and authorities have not publicly identified the attacker.
There is also no current evidence from the Ontario courts that the incident resulted in identity theft. The courts say financial transaction systems were not affected, while C-Track remains operational.
But the potential contents of the affected files make this breach different from another stolen marketing database.
A court document can contain a person’s name, date of birth, driver’s licence information, medical information or other identifying details. Some proceedings can also involve sealed filings or highly confidential material.
Minnesota’s judicial branch has separately warned that some confidential or sealed documents may have been caught up in the incident.
The attack also highlights a familiar security problem:
The court does not necessarily have to be hacked for court data to be stolen.
A third-party provider can become the entry point.
That is exactly what makes vendor compromise so painful. One supplier may host information belonging to multiple institutions. Attackers only need to compromise the supplier once to potentially reach data belonging to many customers.
In this case, the affected courts were not necessarily the systems that were breached.
The Ontario courts explicitly state that the incident involved Thomson Reuters Canada’s C-Track environment rather than the courts’ own networks.
Thomson Reuters says it contained the activity, secured the C-Track environment, engaged external cybersecurity specialists and notified law enforcement. The company also says there has been no operational disruption to C-Track.
Affected individuals are being offered additional support.
The C-Track notification says Thomson Reuters is providing 12 months of complimentary credit monitoring and identity-theft protection through TransUnion’s myTrueIdentity service. A dedicated contact centre is also being established for inquiries.
For organizations using C-Track, however, the more important question is not whether the platform is working today.
It is whether the data that passed through it was exposed yesterday.
That is the problem with cloud and SaaS dependencies. A customer can have solid endpoint security, properly configured firewalls and locked-down internal systems — and still have sensitive information sitting in somebody else’s environment.
Bugstoday’s take: The C-Track incident is another reminder that your security boundary ends wherever your data goes. The courts didn’t need to be directly breached for their records to become part of an incident. A third-party platform was enough. And the three-month gap between unauthorized access and detection is exactly why vendor risk cannot be reduced to checking whether a supplier has a security badge on its website.
Today’s Bugs. Tomorrow’s Breaches.
Technical Sources
- Thomson Reuters — C-Track Cybersecurity Incident Notification
- Ontario Courts — Public Statement Regarding the C-Track Cybersecurity Incident
- Reuters — Thomson Reuters Detects Cybersecurity Incident, September 3, 2026
- Montana Supreme Court — Unauthorized Access to Court Data, September 2, 2026
- C-Track Canada — Incident Notification and Identity Protection Information




