Thomson Reuters’ C-Track Breach Exposes Sensitive Court Records Across Multiple Jurisdictions

Thomson Reuters has revealed a significant data breach in its C-Track court case management platform, a tool handled by its West Publishing Corporation unit. The company discovered in late June 2026 that files were accessed without authorization between March 1 and June 29 in its cloud environment. Affected records span courts across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. Sensitive data such as names, Social Security numbers, driver’s license numbers, dates of birth, medical and health insurance information may have been exposed. In some cases, sealed or otherwise confidential court documents might also have been impacted.

Which Courts Are Affected

The courts involved include appellate and supreme courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, South Carolina, Tennessee, and Wyoming. Also named were Pennsylvania’s Commonwealth Environmental Hearing Board and several Courts of Common Pleas, plus appellate courts in Ohio and Ontario’s Court of Appeal, Superior Court of Justice, and Court of Justice. In Wyoming, data from court cases between 2015 to 2025 appears to have been part of the breach.

Minnesota’s Judicial Branch said its appellate data was also exposed, though state notices largely omitted it initially. In Montana, the affected data surfaced from backup databases provided by courts for troubleshooting, not active case documents. Kentucky’s trial court e-filing system was unaffected because it doesn’t use third-party systems like West Publishing in that function.

What’s Being Done

Thomson Reuters has rolled out credit monitoring services for those potentially impacted. In the U.S., individuals can access 12 months of Experian IdentityWorks; in Canada, 12 months of monitoring via TransUnion myTrueIdentity will be available. Hotlines have also been established, including one opening September 4 in Canada.

Court systems are reviewing what information was accessed. In Ohio, courts were told the breach affected the production platform that houses the filing system for the majority of appellate districts using C-Track. Courts in multiple states emphasized there’s no evidence yet of data misuse, and operations of the C-Track platform remain intact. North Dakota officials noted that their district courts and the financial transaction system were not affected. The event is currently under criminal investigation.

Notifications began rolling out between late July and early September 2026, with public announcements coordinated to follow. As of September 3, the full scope is still being clarified, including the total number of individuals impacted, how the breach occurred, and who is responsible.

This breach underscores critical vulnerabilities in how court case data—including sealed and confidential filings—is managed in cloud environments and via vendor relationships. The incident raises urgent questions about data access governance, vendor oversight, and the protections around backup and archival systems. Courts and government entities relying on third-party platforms must now assess the trade‐offs between operational convenience and safeguarding sensitive personal information. Going forward, expect calls for stronger transparency on breach timelines, more rigorous audits of vendor infrastructures, and possibly, new legal standards governing accountability when court systems outsource key data workflows.