Sep 4
/
Latest News
Thomson Reuters Confirms C‑Track Breach Exposing Court Records Across U.S. and Canada
Thomson Reuters has disclosed a data breach involving its C-Track court case management platform, exposing court records and sensitive personal information across multiple U.S. jurisdictions, the U.S. Virgin Islands, and Canadian courts.
The company said it detected unauthorized activity involving certain C-Track information on June 30, 2026, and launched an investigation with external cybersecurity experts and law enforcement. The investigation determined that, in March 2026, an unauthorized third party obtained C-Track files associated with a wide range of court systems, including appellate and supreme courts in Alabama, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, New Hampshire, several Ohio appellate districts, the entire Wyoming Judicial Branch, the U.S. Virgin Islands Supreme and Superior Courts, and multiple courts in Ontario. The Oregon Judicial Department later confirmed its appellate courts were also affected, and the full scope continues to expand as more courts issue their own disclosures.
Thomson Reuters emphasized that the incident occurred within its own cloud environment and was not caused by the networks, systems, or data security of the affected courts. The company said C-Track remains fully operational and that it has implemented additional security measures reviewed and approved by outside experts.
The nature of the exposed information varies by jurisdiction. In the United States, affected records may include individuals’ names along with one or more of the following: Social Security numbers, driver’s license numbers, dates of birth, medical information, and health insurance information. The U.S. notification also notes that confidential, redacted, or sealed court information may have been affected at some courts. In Canada, the chief justices of the three impacted courts said it remains unclear exactly what information was compromised or how many people were affected, but anyone involved in or mentioned in court proceedings could potentially be impacted.
Thomson Reuters stated that it has no evidence to date that the exposed information has been used for fraud or otherwise misused, nor that systems used to process financial transactions were affected. The company is offering all affected individuals 12 months of free credit monitoring and identity theft protection and continues to work with courts, government partners, and cybersecurity specialists to assess the impact and refine its response.
The company said it detected unauthorized activity involving certain C-Track information on June 30, 2026, and launched an investigation with external cybersecurity experts and law enforcement. The investigation determined that, in March 2026, an unauthorized third party obtained C-Track files associated with a wide range of court systems, including appellate and supreme courts in Alabama, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, New Hampshire, several Ohio appellate districts, the entire Wyoming Judicial Branch, the U.S. Virgin Islands Supreme and Superior Courts, and multiple courts in Ontario. The Oregon Judicial Department later confirmed its appellate courts were also affected, and the full scope continues to expand as more courts issue their own disclosures.
Thomson Reuters emphasized that the incident occurred within its own cloud environment and was not caused by the networks, systems, or data security of the affected courts. The company said C-Track remains fully operational and that it has implemented additional security measures reviewed and approved by outside experts.
The nature of the exposed information varies by jurisdiction. In the United States, affected records may include individuals’ names along with one or more of the following: Social Security numbers, driver’s license numbers, dates of birth, medical information, and health insurance information. The U.S. notification also notes that confidential, redacted, or sealed court information may have been affected at some courts. In Canada, the chief justices of the three impacted courts said it remains unclear exactly what information was compromised or how many people were affected, but anyone involved in or mentioned in court proceedings could potentially be impacted.
Thomson Reuters stated that it has no evidence to date that the exposed information has been used for fraud or otherwise misused, nor that systems used to process financial transactions were affected. The company is offering all affected individuals 12 months of free credit monitoring and identity theft protection and continues to work with courts, government partners, and cybersecurity specialists to assess the impact and refine its response.
Executive IT Forums, Inc.
Educational Programs on Information Technology, Governance, Risk Management, & Compliance (GRC).
Our Newsletter
Get regular updates on CPE programs, news, and more.
Thank you!
Copyright © 2026 Executive IT Forums, Inc. All Rights Reserved.
Get started
Let us introduce our school
Write your awesome label here.