Thomson Reuters C-Track Breach Exposes Sensitive Court Data Across US and Canada
Thomson Reuters disclosed a cybersecurity incident in its C-Track case management platform that compromised court data in Ontario and 11 US states plus the US Virgin Islands, exposing names, Social Security numbers, and other personal information.
Thomson Reuters Corp. has disclosed a cybersecurity incident affecting its C-Track case management platform, exposing sensitive court records in multiple jurisdictions across the United States and Canada. The breach threatens trust in the integrity of legal data and has weighed on the company’s stock.
Thomson Reuters detected unauthorized activity in a C-Track cloud environment on June 30, 2026, according to a statement from Ontario’s three Chief Justices reported by RTTNews. The company moved to contain the incident, engaged external cybersecurity experts, notified law enforcement, and secured the C-Track environment. The investigation later found that some Ontario court data had been accessed, with notification sent to the Ontario Ministry of the Attorney General on July 23. Thomson Reuters shares closed down 0.45% at $105.87 on Wednesday, RTTNews reported.
The breach affected three Ontario courts: the Court of Appeal for Ontario, the Ontario Superior Court of Justice, and the Ontario Court of Justice, according to statements from the Chief Justices and Thomson Reuters.
In the United States, West Publishing Corporation, a Thomson Reuters subsidiary that operates C-Track, confirmed the incident impacted appellate courts in 11 states and the U.S. Virgin Islands. The affected states include Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, and Wyoming, according to a Reuters report cited by RTTNews. Infosecurity Magazine added that South Carolina, Nevada, New Hampshire, North Dakota, Ohio, Kentucky, Pennsylvania, Alabama, Montana, Tennessee, and North Dakota were listed—with North Dakota appearing twice in that source’s text, suggesting a potential duplication.
West Publishing stated that the exposed data may contain names, Social Security numbers, driver’s license numbers, medical information, dates of birth, and health insurance information, as reported by Infosecurity Magazine. The company also warned that certain confidential, redacted, or sealed information may have been impacted for some courts. Thomson Reuters said there is no evidence to date that systems used to process financial transactions related to court proceedings were affected.
The Kentucky Administrative Office of the Courts (AOC) confirmed that Kentucky Appellate Court data was compromised, according to a report from The Cyber Express. Because Kentucky does not use third-party vendors for trial court e-filing, only data from the state Supreme Court and Court of Appeals stored in Thomson Reuters CMS/C-Track systems was exposed. The AOC said Kentucky’s appellate courts continued to function normally with no operational disruption.
Thomson Reuters emphasized that the incident was not caused by the courts’ own networks or systems, and there is no evidence that the accessed data has been misused for fraud or identity theft, according to both RTTNews and Infosecurity Magazine. Thomson Reuters Canada said it has taken steps to reduce the risk of misuse.
A dedicated website has been set up to answer questions about the hack, RTTNews reported. The Kentucky AOC noted that Thomson Reuters CMS has committed to covering all costs related to the breach and will provide affected individuals with 12 months of complimentary credit monitoring and identity theft protection.
The investigation is ongoing to determine the specific data accessed and the number of individuals affected across all jurisdictions. Thomson Reuters is coordinating with third-party cybersecurity specialists and law enforcement. The Kentucky AOC has pressed for a faster notification timeline, the outlet reported.
The breach underscores the sensitivity of court documents, which are frequently targeted by state-sponsored espionage groups, malicious actors seeking to influence cases, and financially motivated cybercriminals. In August 2025, the U.S. federal judiciary announced stronger cybersecurity protections for sensitive court documents following escalated cyberattacks on its case management system, according to Infosecurity Magazine. The compromise of Thomson Reuters’ C-Track platform threatens the confidentiality that courts and litigants depend on, potentially undermining trust in legal proceedings and the financial institutions that rely on accurate, secure court data.
Artículos relacionados
También te puede interesar




