Breach of C-Track Court Platform Disclosed by Thomson Reuters
Thomson Reuters disclosed on September 2, 2026, that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit. C-Track is used by appellate and trial courts across multiple US states and Canadian jurisdictions to manage case filings, dockets, and related records.
What Was Exposed
Depending on the court, the compromised files potentially contained:
- Social Security numbers
- Driver's license numbers
- Dates of birth
- Medical information and health insurance details
- Names, addresses, and phone numbers
- Case numbers and docket entries
- Certain confidential, redacted, or sealed information held by some courts
Affected Jurisdictions
West Publishing's notice lists 11 US states — Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, and Wyoming — plus the U.S. Virgin Islands and Ontario, Canada. Minnesota's appellate courts were also affected, though they were initially absent from the official notice.
Timeline
| Date | Event |
|---|---|
| March 1 – June 29, 2026 | Unauthorized access window |
| June 30, 2026 | Breach discovered |
| July 23–27, 2026 | Affected courts notified |
| September 2, 2026 | Public disclosure |
The roughly two-month gap between discovery and court notification, and the further gap to public disclosure, reflects the coordination required across multiple independent court systems before individual notice letters could go out.
The Sealed-Data Problem
The exposure of "confidential, redacted or sealed information" is the most sensitive element of this incident. Sealed court records exist specifically to protect information — such as juvenile cases, victim identities, or matters under protective order — that courts have determined should not be public. A breach that potentially exposes that category of data carries legal and safety implications well beyond a typical PII leak, since the same protections that sealed the records in the first place make it harder to assess and communicate the scope of exposure.
Remediation Offered
Thomson Reuters is offering affected individuals:
- 12 months of Experian IdentityWorks credit monitoring (US)
- 12 months of TransUnion myTrueIdentity monitoring (Canada)
- A dedicated support hotline: 1-833-918-5294
Thomson Reuters says it has found no evidence to date that the exposed data has been misused or that fraud has resulted from the incident.
Sources: The Hacker News, Thomson Reuters/West Publishing breach notification