Skip to main content
Emerging ThreatsData Breaches

Thomson Reuters Breach Exposes Court Data Across US, Canada

Courthouse interior with computer terminal and disheveled paper files near tall windows.

"There has been no operational disruption to C-Track as a result of this incident," a Thomson Reuters spokesperson told Reuters.

Scope: C-Track records from 11 U.S. states, the U.S. Virgin Islands and Ontario

Thomson Reuters disclosed that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026. West Publishing said it discovered the activity on June 30, 2026, and its notice — reviewed by The Hacker News on September 3 — lists 24 court bodies across 11 states and the U.S. Virgin Islands, with Ontario courts also named.

The notices from West Publishing and Thomson Reuters Canada Limited identify affected entities that include appellate and supreme courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio (multiple appellate districts), Pennsylvania (several courts listed by county and board), South Carolina, Tennessee, Wyoming, the U.S. Virgin Islands, and Ontario's three principal courts. The Hacker News review noted Minnesota was absent from the vendor list even as the Minnesota Judicial Branch said its appellate courts' data were exposed.

Data at risk: Social Security numbers, driver's licenses, medical and sealed information

West Publishing said a subset of court records "could contain" individuals' names, Social Security numbers, driver's license numbers, dates of birth, medical information, and health insurance information. The notice also said "certain confidential, redacted or sealed information may have been impacted for certain affected courts," although multiple courts have said that court documents themselves were not part of the accessed data.

Montana's Supreme Court said the material taken was backup data stored on Thomson Reuters servers, drawn from database copies "supplied to TR for the purpose of troubleshooting the applications." Montana said those databases may include case numbers, party names and addresses, phone numbers, charge and docket descriptions, and for some criminal defendants, driver's license numbers and dates of birth.

West Publishing added there is "no evidence to date of fraud or misuse of the information."

Timeline and conflicting accounts about where files were taken

According to court statements, the unauthorized access window reported by Montana ran from March 1 through June 29, 2026, and West Publishing said it discovered the activity on June 30. The vendor notified courts and Ontario's Ministry of the Attorney General between July 23 and July 27, and public disclosure by the vendor and several courts occurred on September 2.

The vendor's description of which environment was accessed differs among notifications. Ontario's chief justices said Thomson Reuters "detected the activity within one of its cloud environments." Alabama's chief justice, Sarah Stewart, said the incident "occurred within our vendor's systems, not our own," and Montana described the records as backups kept on Thomson Reuters servers. By contrast the Supreme Court of Ohio said Thomson Reuters Court Management Solutions (TRCMS) informed it on August 31 that "the unauthorized access took place on the Court's production platform."

Thomson Reuters told Reuters that it considers C-Track safe to keep using and that there has been no operational disruption. The Supreme Court of Ohio said it has yet to receive comprehensive details of the enhanced security measures TRCMS told it had been deployed. The Hacker News has sought clarification from Thomson Reuters about which environment was accessed and whether Minnesota courts are affected.

How selected courts have responded

  • Minnesota: The Judicial Branch said appellate-court data were exposed, terminated Thomson Reuters' access to the appellate case management system, and required users to change passwords. Minnesota Supreme Court Chief Justice Natalie Hudson said she is "deeply troubled that our court users' data has been compromised."
  • Montana: Characterized the files as vendor-held backups provided for troubleshooting and emphasized the types of fields that may have been included.
  • Alabama: Said West Publishing told them a copy of some appellate court data was kept in a backup file within the company's cloud environment — a backup the courts say they neither requested nor knew about.
  • Wyoming: Reported the material taken was historical data (primarily people who dealt with the courts between 2015 and 2025) and that the preliminary review indicated "limited personal information, including names, addresses and dates of birth, was compromised." Wyoming published hotline hours (7 a.m. to 7 p.m. Mountain Time).
  • U.S. Virgin Islands: Received notice on July 27 and said the accessed data so far "related to its 2018 system implementation project."
  • North Dakota: Said the incident involved only North Dakota Supreme Court data, that district courts and the Odyssey system were unaffected, and that "There is an active criminal investigation into this incident."

What this means for technologists, court administrators, and affected individuals

  • Technologists and security teams will be watching whether the files came from vendor-held backups or court production environments, and will need the vendor's detailed forensic findings to validate claims that platform operations were unaffected.
  • Court administrators and procurement leaders face immediate operational choices already illustrated by Minnesota's actions: terminating vendor access, enforcing credential changes, and seeking details about enhanced security measures that several courts say have not yet been fully disclosed.
  • Affected individuals are being offered identity-monitoring services: West Publishing is offering 12 months of Experian IdentityWorks in the U.S. (enrollment open until December 31, 2026, via a multi-use code in the notice and a hotline at 1-833-918-5294 using engagement number B171847), and Thomson Reuters Canada Limited is offering 12 months of TransUnion myTrueIdentity with a Canadian call center scheduled to open on September 4.

As of September 3, no party had published a count of affected individuals, the method by which the files were obtained, or the identity of whoever was responsible. Montana said the September 2 public disclosures were timed so vendor and states could issue simultaneous announcements. For courts, litigants and anyone named in court records, the next steps hinge on vendor forensic details, the outcome of the active criminal investigation North Dakota disclosed, and the precise inventory of what data were stored in vendor backups versus production systems. Read the original notice at The Hacker News for the vendor statements and the full list of affected courts: https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html