Thomson Reuters C-Track Breach Exposes Sensitive U.S. Court Records

Thomson Reuters confirmed hackers stole C-Track files associated with courts across multiple jurisdictions, potentially exposing SSNs, medical data and sealed records.
Thomson Reuters logo displayed over a digital background featuring court documents and a breached file folder.

Thomson Reuters has confirmed a data breach involving its C-Track court management platform after an unauthorized third party obtained files associated with court systems across multiple U.S. states and jurisdictions.

The stolen files may contain highly sensitive information buried within court records, including names, Social Security numbers, driver’s license numbers, dates of birth, medical information and health insurance information. Thomson Reuters also warned that confidential, redacted or sealed information may have been impacted for certain courts.

The breach occurred within C-Track, which is owned by Thomson Reuters subsidiary West Publishing Corporation and provides case management technology to courts.

According to an incident notification published by C-Track, the company discovered unauthorized third-party activity on June 30, 2026 and launched an investigation with outside cybersecurity experts and law enforcement.

The investigation determined that an unauthorized party had obtained certain C-Track files in March, meaning the data theft occurred approximately 3 months before the suspicious activity was discovered.

Court records taken across multiple jurisdictions

The affected C-Track files were associated with a broad collection of state and territorial court systems.

C-Track’s notification identifies records connected to appellate courts in Alabama and Kentucky, the Montana Supreme Court, Nevada Appellate Courts, North Dakota Supreme Court, South Carolina’s Supreme Court and Court of Appeals, the Tennessee Appellate Court Clerk’s Office, New Hampshire Supreme Court and Wyoming Judicial Branch.

The incident also affected multiple Pennsylvania courts and judicial bodies, 10 Ohio Courts of Appeals and the U.S. Virgin Islands Supreme and Superior Courts.

Oregon has separately confirmed that data associated with its Court of Appeals and Supreme Court was involved in the vendor breach.

The Oregon Judicial Department said the compromised system was hosted by Thomson Reuters and stressed that Oregon’s own systems, including its circuit courts and Tax Court, were not breached.

C-Track’s Canadian operation has also disclosed unauthorized access involving court information in Ontario, extending the incident beyond the United States.

SSNs, medical information and sealed records may be involved

The sensitivity of the potentially compromised information makes the incident particularly significant.

Thomson Reuters said a subset of affected court records could potentially contain:

  • Names
  • Social Security numbers
  • Driver’s license numbers
  • Dates of birth
  • Medical information
  • Health insurance information

Certain confidential, redacted or sealed information may also have been affected depending on the court involved.

That distinction matters because court management platforms can contain information that is not intended to appear in publicly accessible court records. The exposure of identifiers such as Social Security and driver’s license numbers could create identity theft and impersonation risks if the information is misused.

C-Track said it has found no evidence that the stolen information has resulted in fraud or misuse so far.

Breach originated with C-Track, not state court networks

Multiple affected court systems have emphasized that the compromise occurred within the vendor’s environment rather than their own networks.

The North Dakota Court System said C-Track confirmed that data associated with the North Dakota Supreme Court was affected, while its district court data and Odyssey system were not.

Similarly, the Oregon Judicial Department said Thomson Reuters notified it that hackers breached the C-Track system and that Oregon’s own systems were not involved.

The Supreme Court of Ohio said it was notified by West Publishing on July 24 about an incident that occurred in March. C-Track is used by 10 of Ohio’s 12 Courts of Appeals to upload filings and related documents.

Thomson Reuters said there is no evidence that systems used to process financial transactions were affected. The incident also did not disrupt C-Track operations.

The company says it contained the unauthorized activity, secured the affected environment and implemented additional security measures following the investigation.

Affected individuals offered identity monitoring

C-Track is offering 12 months of complimentary credit monitoring and identity theft protection to potentially affected individuals.

The company is encouraging those potentially impacted to remain alert for fraud and identity theft and to monitor financial accounts and credit reports for suspicious activity.

The incident demonstrates the concentration of sensitive information created when numerous government organizations depend on the same third-party technology provider. In this case, unauthorized access to a single vendor environment potentially exposed information associated with courts across numerous jurisdictions.

No threat actor has been publicly identified as responsible for the C-Track breach at time of publication.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site