Thomson Reuters has disclosed a cybersecurity breach in its C-Track court case management platform that exposed court records across 11 US states, the US Virgin Islands, Oregon and multiple Canadian courts using the system to manage digital files.[1][2][3][7][8][10][15] The company says an unauthorized party accessed C-Track files earlier this year, potentially exposing names, personal information and some confidential court documents, although court operations and core systems remain online and functional.[1][2][10]
According to notices from Thomson Reuters and affected courts, the unauthorized access to C-Track data began in March 2026 and continued until June, when the activity was detected on June 30.[1][2][7] Thomson Reuters’ West Publishing unit, which operates the platform, said a subsequent investigation confirmed that an external actor had obtained certain C-Track files and that the company moved to contain the activity, secure the environment, notify law enforcement and bring in independent cybersecurity experts to validate its remediation steps.[1][5][7][10] The vendor maintains there has been no operational disruption to C-Track and that its products and services remain safe to use.[1][10]
A public information site operated by West Publishing lists affected US jurisdictions as Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming and the US Virgin Islands, with additional impact in Canadian courts that rely on C-Track for digital record management.[1][8][10][15] Separate statements from the Oregon Judicial Department and the Supreme Court of Ohio confirm that appellate courts in Oregon and 10 of Ohio’s 12 courts of appeals use C-Track and were swept up in the incident, while emphasizing that their own on-premises court systems were not breached.[3][5] Montana’s Supreme Court similarly reported unauthorized access to C-Track and related e-filing backup data stored on Thomson Reuters infrastructure, not on state systems, between March and June 2026.[7]
The exposed information varies by jurisdiction but is described in multiple notices as a “subset of court records” that may contain personal identification data and, in some cases, confidential, redacted or sealed filings.[1][2][6] New Hampshire’s Supreme Court, for example, said names and case information from 2002 to 2015 were accessed through C-Track but that there is no evidence Social Security numbers or similar highly sensitive identifiers were involved.[10] Thomson Reuters and several courts stress that systems used for financial transactions were not affected and that, to date, they have seen no confirmed misuse of the compromised information, though investigations and notifications are ongoing.[2][5][7][10]
As of publication, the C-Track incident has not been assigned a Common Vulnerabilities and Exposures (CVE) identifier and there is no public CVSS severity score associated with the breach, underscoring that it is being treated primarily as a data compromise rather than a disclosed software flaw.[1][2] C-Track has faced security issues before: in 2024, an independent disclosure described an insufficient permission check in the C-Track e-filing system that allowed users to manipulate registration data and grant themselves privileged roles such as clerk, a weakness that Thomson Reuters later reported fixing, though there is no public evidence linking that earlier flaw to the 2026 intrusion.[9]
Affected courts are working with Thomson Reuters to analyze which cases and individuals were exposed, with several indicating they will notify impacted parties where required and review redaction practices for sensitive filings.[1][3][5][7][10] For court systems and justice agencies that rely on third-party case management platforms, the breach highlights the importance of rigorous vendor risk assessments, contractual requirements for security monitoring and incident response, and clear data-mapping so that institutions can quickly determine whose records are at risk when a service provider’s environment is compromised.
References
- Thomson Reuters detects cybersecurity incident, says unauthorized party accessed files
- Cyberattack on Thomson Reuters Company Hits Courts in 11 States
- Newsroom – Oregon Judicial Department
- Statement on Behalf of Supreme Court of Ohio on Cybersecurity …
- C-Track and Thomson Reuters Corp.: Cyberattack on Thomson …
- Data breach hit Montana state courts from March to June, chief …
- Thomson Reuters Corp
- disclosures/README-2024-09-26-thomson-reuters-ctrack.md at main · qwell/disclosures
- State Supreme Court data exposed in cybersecurity breach
- Thomson Reuters Detected Cybersecurity Breach of US, …
