Thomson Reuters Court Software Breach Exposes Sensitive Legal Data
A breach in Thomson Reuters' C-Track court software may have exposed Social Security numbers and sealed legal documents. The incident affects courts across 11 U.S. states, the Virgin Islands, and Ontario.
TL;DR
- Unauthorized access to C-Track occurred in March 2026, discovered in late June.
- Exposed data may include SSNs and sealed court records from 11 U.S. states and Ontario.
- Thomson Reuters’ West Publishing unit manages the affected case management platform.
- The breach impacts sensitive legal data used in judicial proceedings.
- Organizations using C-Track should review access logs and audit data exposure.
Thomson Reuters has confirmed a security incident involving its C-Track court case management system, which may have led to the exposure of highly sensitive personal and legal information. The breach, first detected in June 2026, stems from unauthorized access to the platform as early as March 2026.
C-Track, developed by West Publishing Corporation, a subsidiary of Thomson Reuters, supports court operations across multiple jurisdictions. The breach reportedly impacted systems in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada, raising concerns over potential misuse of confidential legal data and personally identifiable information (PII).
What Was Affected
- Unauthorized party accessed files from C-Track, a court case management platform.
- Affected jurisdictions include 11 U.S. states, U.S. Virgin Islands, and Ontario, Canada.
- Potentially compromised data includes names, Social Security numbers, and sealed court documents.
- The breach was discovered on June 30, 2026, though initial access may date back to March 2026.
Implications for Legal Institutions
- Sealed and confidential court records may have been exposed, risking privacy violations.
- Judicial systems relying on third-party platforms face increased scrutiny over data safeguards.
- Organizations using C-Track should conduct thorough forensic audits and monitor for misuse.
- Incident highlights risks of centralized legal data systems and dependency on vendor security.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.