>samit_hota
Back to security news

Security News · SN-2026-437

HIGHOPEN

Thomson Reuters Discloses C-Track Breach Exposing US and Canadian Court Data

Affected: Thomson Reuters C-Track · West Publishing Corporation · US and Canadian state/provincial court systems

Samit Hota·
#news#data-breach#thomson

Courts across at least 12 US states, the US Virgin Islands, and Ontario, Canada are assessing the damage following a widespread Thomson Reuters C-Track breach that exposed sensitive personal information, criminal docket details, and confidential court records. The incident, disclosed publicly on September 2, 2026 by Thomson Reuters’ subsidiary West Publishing Corporation, involved unauthorized access to C-Track court case management files stored within the vendor’s cloud environment.

The breach highlights the persistent risks surrounding vendor cloud hosting and unmanaged data retention. Attackers maintained undetected access to Thomson Reuters’ systems for nearly four months, gaining access to production platforms as well as forgotten, unencrypted, or loosely controlled backup copies of state court databases.

How the Compromise Occurred

Between March 1 and June 29, 2026, an unauthorized third party obtained access to files associated with C-Track, the proprietary court software used by judicial systems for electronic filing and case administration. Thomson Reuters discovered the unauthorized activity on June 30, 2026, and initiated an investigation alongside external cybersecurity specialists and law enforcement.

While Thomson Reuters emphasized that the intrusion occurred within its own cloud environment rather than on judicial networks, local disclosures by affected state supreme courts reveal multiple attack vectors and storage exposures:

  • Production Filing Platforms: The Supreme Court of Ohio stated that Thomson Reuters Court Management Solutions (TRCMS) notified them on August 31 that unauthorized access occurred directly on the court’s production platform hosting C-Track e-filing data for 10 district courts of appeals.
  • Unsanctioned Cloud Backups: The Alabama Appellate Courts revealed that vendor representatives admitted to retaining a copy of state appellate court data in a cloud backup file—a backup the judicial branch had neither requested nor authorized.
  • Troubleshooting Staging Copies: In Montana, the compromised data originated from database copies provided to Thomson Reuters specifically for application troubleshooting and stored on the vendor’s internal servers.
  • Legacy and Implementation Datasets: The Wyoming Judicial Branch confirmed compromised data spanned historical records from 2015 to 2025, while the US Virgin Islands reported that accessed files pertained to its 2018 system deployment project.

This pattern points to systematic data sprawl and weak access boundaries within the vendor’s cloud tenant. Threat actors frequently target software-as-a-service (SaaS) and legaltech providers specifically because a single compromised administrative credential, misconfigured storage bucket, or exposed staging environment grants flat access to high-value data from dozens of enterprise clients.

Scope of Exposed Data

The material exposed varies significantly by jurisdiction, but overall includes deep, unredacted personal identifiable information (PII) and protected legal records. According to vendor notifications and court statements, compromised data elements include:

  • Full names, physical addresses, telephone numbers, and dates of birth
  • Social Security numbers (SSNs) and driver’s license numbers
  • Medical records, health insurance information, and charge/docket descriptions
  • Sealed, confidential, or legally redacted court filings

Because C-Track manages appellate and trial dockets, sensitive documents exposed in the intrusion potentially include sealed criminal filings, grand jury materials, juvenile proceedings, and protected witness declarations.

Affected jurisdictions confirmed so far include appellate courts in South Carolina, Oregon, Minnesota, Montana, Alabama, and North Dakota; 10 district court of appeals in Ohio; trial and appellate courts in Wyoming, Pennsylvania, and the US Virgin Islands; and three court tiers in Ontario, Canada (the Court of Appeal, Superior Court of Justice, and Ontario Court of Justice).

Operational Impact and Isolation Measures

Thomson Reuters maintains that C-Track remains fully operational and safe to use, asserting that additional security controls have been added and verified by external advisors. However, individual judicial bodies are taking aggressive containment measures:

The Minnesota Judicial Branch terminated Thomson Reuters’ access to state court electronic environments, forced mandatory password resets for all users of its appellate case management system, and noted that state court users’ data had been compromised. In contrast, Kentucky confirmed its trial court e-filing was completely untouched because the state runs its systems in-house without third-party vendor platforms.

Thomson Reuters notified affected courts between July 23 and July 27, 2026, but delayed public disclosure until September 2 to coordinate unified victim announcements. The vendor is providing 12 months of free identity protection and credit monitoring (via Experian in the US under engagement B171847 and TransUnion in Canada).

What Security Teams Must Do

Organizations relying on third-party SaaS platforms or managed court management systems should immediately audit how vendors store and retain operational and historical data.

  1. Audit Vendor Data Retention and Staging Environments: Demand confirmation from vendors regarding where troubleshooting database exports and historical backups are stored, who holds decryption keys, and how quickly staging copies are destroyed after maintenance tickets close.
  2. Revoke Stale Vendor System Integrations: Follow Minnesota’s posture by temporarily isolating vendor integration tunnels and forcing credential resets across all accounts tied to vendor-managed e-filing and case management software until independent attestation of containment is provided.
  3. Scan for Exposed Court Data: Security operations teams within municipal, state, and legal entities should monitor threat actor leak sites and breach forums for references to C-Track database dumps or exposed sealed court filings.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call