Thomson Reuters has reported a significant data breach involving its C-Track case management system, affecting courts across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. The breach, which occurred in March 2026, was disclosed by the company on September 2, 2026, impacting sensitive court records and personal information.
Details of the Breach
The breach was detected by West Publishing, a Thomson Reuters unit, on June 30, 2026. It involved unauthorized access to a variety of sensitive data including names, Social Security numbers, and other personal identifiers. The affected data spanned multiple court systems, with the breach peaking from March 1 to June 29, 2026, according to the Montana Supreme Court.
In response, the company is offering credit monitoring services to those potentially impacted. In the U.S., a 12-month Experian IdentityWorks service is available, while in Canada, TransUnion’s myTrueIdentity service is being provided. The incident has prompted courts like Minnesota’s to sever access for Thomson Reuters, amid growing concerns over data security.
Impact on Court Systems
The breach affected numerous judicial bodies, including the Alabama Appellate Courts and the Supreme Court of Ohio. While some courts like those in Kentucky reported no immediate impact on their systems, others, such as Wyoming, acknowledged exposure of historical data spanning a decade. The Ohio Supreme Court, in particular, noted the breach affected its production platform, raising concerns over the extent of exposure.
Thomson Reuters maintains that the C-Track system remains operational and safe to use, despite the breach. However, the lack of detailed information on what specific data was compromised continues to cause uncertainty. The situation is further complicated by ongoing criminal investigations into the breach.
Future Outlook and Security Measures
The breach has prompted an urgent review of security protocols within affected court systems. Courts are actively working to enhance their cybersecurity measures, though details on these enhancements remain sparse. The breach underscores the growing importance of robust cybersecurity practices, especially for organizations handling sensitive legal data.
As investigations unfold, the focus remains on securing affected systems and preventing future breaches. With no confirmed cases of data misuse reported yet, the emphasis is on vigilance and rapid response to any further threats. The incident highlights the need for continuous monitoring and upgrading of cybersecurity defenses in the digital age.
