Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-04 ยท updated: 2026-09-04 ยท tags: ยท confidence: high ยท severity: high ยท affected_sectors: ยท au_impact: false

Thomson Reuters publicly disclosed a compromise of its C-Track court case-management platform that affected courts in at least 12 US states, the US Virgin Islands and Canada, including exposure of confidential, redacted or sealed case information.

Assessment

The breach occurred within Thomson Reuters' own environment rather than within the courts' systems, meaning the judicial records of every affected court inherited the commercial vendor's security posture. The exposure is significant both because of the sensitivity of the data โ€” names, Social Security numbers, driver's licence numbers, medical information, dates of birth and health insurance details โ€” and because at some courts it included confidential, redacted or sealed case information. Thomson Reuters has not disclosed the access vector, the responsible party or a victim count.

Details

  • Unauthorised activity was detected on 30 June, with the investigation finding files were first obtained in March and access persisting into June.
  • Potentially exposed data includes names, Social Security numbers, driver's licence numbers, medical information, dates of birth and health insurance information, plus confidential, redacted or sealed case information at some courts.
  • Courts in at least 12 US states, the US Virgin Islands and Canada were affected.
  • Ontario's chief justices and Montana's Supreme Court separately confirmed involvement.
  • Thomson Reuters is offering 12 months of credit monitoring to affected individuals.
  • The incident is classified as a confirmed breach.