Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2655+ Articles
165+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
NEWS

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

A breach of Thomson Reuters' C-Track court case management platform may have exposed SSNs, medical data, and sealed records across 11 US states.

Dylan H.

News Desk

September 4, 2026
3 min read

Breach of C-Track Court Platform Disclosed by Thomson Reuters

Thomson Reuters disclosed on September 2, 2026, that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit. C-Track is used by appellate and trial courts across multiple US states and Canadian jurisdictions to manage case filings, dockets, and related records.

What Was Exposed

Depending on the court, the compromised files potentially contained:

  • Social Security numbers
  • Driver's license numbers
  • Dates of birth
  • Medical information and health insurance details
  • Names, addresses, and phone numbers
  • Case numbers and docket entries
  • Certain confidential, redacted, or sealed information held by some courts

Affected Jurisdictions

West Publishing's notice lists 11 US states — Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, and Wyoming — plus the U.S. Virgin Islands and Ontario, Canada. Minnesota's appellate courts were also affected, though they were initially absent from the official notice.

Timeline

DateEvent
March 1 – June 29, 2026Unauthorized access window
June 30, 2026Breach discovered
July 23–27, 2026Affected courts notified
September 2, 2026Public disclosure

The roughly two-month gap between discovery and court notification, and the further gap to public disclosure, reflects the coordination required across multiple independent court systems before individual notice letters could go out.

The Sealed-Data Problem

The exposure of "confidential, redacted or sealed information" is the most sensitive element of this incident. Sealed court records exist specifically to protect information — such as juvenile cases, victim identities, or matters under protective order — that courts have determined should not be public. A breach that potentially exposes that category of data carries legal and safety implications well beyond a typical PII leak, since the same protections that sealed the records in the first place make it harder to assess and communicate the scope of exposure.

Remediation Offered

Thomson Reuters is offering affected individuals:

  • 12 months of Experian IdentityWorks credit monitoring (US)
  • 12 months of TransUnion myTrueIdentity monitoring (Canada)
  • A dedicated support hotline: 1-833-918-5294

Thomson Reuters says it has found no evidence to date that the exposed data has been misused or that fraud has resulted from the incident.


Sources: The Hacker News, Thomson Reuters/West Publishing breach notification

#Data Breach#Thomson Reuters#West Publishing#C-Track#Court Systems#PII

Related Articles

LACMA Data Breach Exposed Social Security Numbers and Medical Data

The Los Angeles County Museum of Art disclosed a 2025 breach that exposed SSNs, medical records, and financial data of employees and visitors.

5 min read

Medtronic Breach Hits 3.8 Million: SSNs and Health Data Exposed

Medtronic, the world's largest medical device maker, has notified nearly 3.8 million people after a breach linked to ShinyHunters exposed Social Security...

3 min read

IDMerit KYC Data Breach Exposes 1 Billion Records Across 26

An unprotected MongoDB instance belonging to identity verification firm IDMerit left over 1 billion personal records — including SSNs, passport numbers,...

4 min read
Back to all News