Thomson Reuters disclosed a data breach affecting its C-Track court case management platform, with unauthorized access occurring in March 2026 and discovery delayed until late June. The incident exposed files from courts across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada, creating potential exposure for sensitive judicial records including Social Security numbers and sealed case documents.
West Publishing Corporation, the Thomson Reuters subsidiary that markets C-Track, confirmed that an unidentified threat actor obtained files during the March breach window. The company did not discover the unauthorized access until June 30, 2026, a lag of approximately four months between initial compromise and detection. This delay extends the window during which stolen data remained accessible to the attacker.
The breach threatens multiple categories of sensitive information. Court records routinely contain personally identifiable information, including full names and Social Security numbers used for tax administration, child support enforcement, and criminal record linkage. Sealed case data presents a separate compliance risk, as these documents receive judicial protection specifically to prevent public access. Exposure of sealed records can compromise ongoing investigations, witness protection arrangements, and confidential settlement agreements.
C-Track serves as a case management system for courts handling criminal, civil, and family law matters. Its integration into state court infrastructure means the breach potentially affects court operations across multiple jurisdictions. The geographic scope spanning 11 states plus two non-U.S. jurisdictions indicates a widespread deployment within the judicial system.
Thomson Reuters has not publicly identified the threat actor responsible for the breach or disclosed the attack method. The company also has not confirmed whether any stolen data has been offered for sale on dark web marketplaces or accessed by secondary parties. These details remain central to assessing whether exposed individuals face imminent fraud or identity theft risk.
The four-month detection lag raises questions about Thomson Reuters' security monitoring capabilities. Modern enterprise security operations should identify unauthorized file access and exfiltration far more quickly through network telemetry, log analysis, and endpoint detection tools. This detection delay suggests either inadequate monitoring in place, limited logging retention, or insufficient automated alerting on unusual data access patterns.
For affected courts, the breach requires mandatory breach notification to individuals whose records appear in exposed files. State attorneys general, federal judges, and bar associations will likely scrutinize how court records ended up in commercial software systems without adequate encryption or access controls. Courts may face pressure to audit their data handling practices and implement stricter requirements for vendor security controls.
Organizations using Thomson Reuters court software platforms should initiate incident response contacts with the company to determine whether their courts appear among affected jurisdictions. Court administrators need to work with legal counsel to understand notification obligations under state breach notification laws, which typically require disclosure when unencrypted personal information becomes accessible to unauthorized parties.
The incident underscores the security risk created when sensitive government data flows through commercial third-party platforms. Courts depend on these systems but often lack direct visibility into vendor security practices, incident response procedures, and data retention policies. This structural vulnerability affects not just Thomson Reuters customers but the entire judicial system's ability to protect confidential case information.
