Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 04, 2026 · 7 min read

Thomson Reuters Breach Hit Courts in 12 States

A judge sealed those filings. A vendor breach unsealed them, and the people named in them found out five months later.

A court seal is an order. A judge weighed one person's safety against the public's right to read a file and decided the file stays shut: the informant's name, the survivor's home address, the juvenile's record. On September 2 the company running the software behind appellate courts in a dozen US states said an unauthorized party had taken files that may include exactly that material. The intrusion began in March.

Key Takeaways

  • Thomson Reuters disclosed that an unauthorized party obtained files from C-Track, the court case management platform operated by its subsidiary West Publishing Corporation, according to The Record.
  • The access started in March 2026 and ran until late June; Thomson Reuters found it on June 30, told Ontario's Ministry of the Attorney General on July 23, and went public on September 2.
  • Courts in 12 US states, the US Virgin Islands and three Ontario courts were affected, including 10 Ohio district courts of appeals and Oregon's appellate courts.
  • West Publishing said the files may contain names, Social Security numbers, driver's license numbers, dates of birth, medical information and health insurance information, and that "certain confidential, redacted or sealed information may have been impacted for certain affected courts."
  • Affected US and Virgin Islands residents get 12 months of Experian IdentityWorks credit monitoring, with enrollment closing December 31, 2026.

What Is C-Track?

C-Track is a court case management platform sold by West Publishing Corporation, a Thomson Reuters subsidiary, and used by appellate courts across the United States and Canada to docket cases, hold filings and publish decisions.

Courts do not run it on their own hardware. It lives in a Thomson Reuters cloud environment, which is where the unauthorized activity was detected, and the company has been careful about that distinction. Thomson Reuters said the incident happened inside its own environment and "was not caused by the networks, systems or data security of the affected courts," per Help Net Security.

That sentence reassures court administrators and should alarm everyone else. A chief justice could have hardened every system her judiciary owns and changed nothing here. The records left the building years ago.

Which Courts Were Affected?

Appellate and supreme courts in 12 US states, the US Virgin Islands, and three courts in Ontario. Infosecurity Magazine and other outlets have pieced the list together from individual court notices rather than from one central disclosure:

  • Appellate courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Oregon, South Carolina, Tennessee and Wyoming.
  • Ohio, where 10 district courts of appeals were caught, and Pennsylvania.
  • The US Virgin Islands Supreme and Superior Courts.
  • Ontario: the Court of Appeal for Ontario, the Ontario Superior Court of Justice and the Ontario Court of Justice.

Scope varies. North Dakota said only Supreme Court data was involved and its district courts, on a different system, were untouched. Ontario's chief justices said it remained unclear what was taken or how many people are in it.

Rows of manila court case files packed into tall metal shelving in an institutional records room, with one drawer pulled slightly open under cool daylight from a high window

What Data Was Exposed?

Ordinary identity data, and one category that is not ordinary at all. West Publishing told courts that "certain confidential, redacted or sealed information may have been impacted for certain affected courts," a line reported by The Hacker News.

The rest is the usual inventory: names, Social Security numbers, driver's license numbers, dates of birth, medical information and health insurance information. License numbers have a resale market of their own, as the Nexus marketplace listing 153 million stolen licenses showed last week.

Here is the part no press release frames properly. Sealing is a judicial act: somebody filed a motion, a judge ruled, a document became legally invisible. Undoing it normally takes another motion, a hearing and often an appeal. This breach skipped all of that. No judge weighed anything, and the people protected by those orders were not parties to the decision that reversed them.

Why Did It Take Five Months to Disclose?

Thomson Reuters has not explained the gap, and the timeline is worth laying out because each interval was somebody's decision.

  • March 2026: an unauthorized party obtains C-Track files. Access continues into late June, roughly four months undetected.
  • June 30: Thomson Reuters detects the activity, contains it, brings in outside cybersecurity experts and notifies law enforcement.
  • July 23: Ontario's Ministry of the Attorney General is told court data was accessed. US courts are notified across the following days.
  • September 2: courts start posting public notices, 64 days after discovery and 41 days after the first government was told.

Investigations take time, and working out which records sat in which files is slow. But the cost of the delay falls elsewhere. Anyone whose sealed address was in those files spent the summer under a protection they no longer had. We saw the same shape in the Liechtenstein registry hack that exposed the owners of 31,000 companies: a government promise of confidentiality, broken quietly, disclosed on the holder's schedule.

Why Sealed Records Matter More Than the Social Security Numbers

Because a Social Security number can be locked behind a credit freeze in twenty minutes, and a sealed filing cannot be resealed once it is out.

Consider who ends up in a sealed appellate file. Cooperating witnesses whose names were withheld for a reason. Petitioners under protective orders. Juveniles. People in domestic violence proceedings who used a substitute address precisely so a filing would not print where they sleep. Most states run formal programs for this: Virginia's, under Va. Code § 2.2-515.2, is typical in giving survivors a legal substitute address to use in government records.

Almost every headline led with Social Security numbers and credit monitoring, because that is the part with a standard remedy. For the person whose safety depended on a redaction, twelve months of Experian is not a remedy at all. It answers a different question. This is also the second court records system compromise in under two months, after the intrusion into PACER and CM/ECF that reached sealed federal filings. One difference matters: the federal judiciary owns PACER and approved an $800 million replacement for it. No court owns C-Track, so no court can fund a fix.

What Should You Do If You Were Notified?

Assume the notice understates it, because the investigation is still running and no individual count has been published anywhere.

  • Freeze your credit, do not just monitor it. Monitoring tells you after an account is opened; a freeze stops it being opened. The FTC's guidance on credit freezes and fraud alerts covers a process that is free, reversible and separate at each of the three bureaus.
  • Enroll before December 31, 2026. That is the cutoff for the Experian IdentityWorks offer in the US and the Virgin Islands; Canadian residents are routed to TransUnion myTrueIdentity. Use the code printed on your letter, at a number you looked up yourself.
  • Treat the breach email as a phishing pretext. Criminals read the same coverage you do, and a wave of fake notices follows every named incident. The FTC's alert on emails claiming your data is for sale on the dark web describes the pattern. Never enroll through a link in an unsolicited message.
  • Ask the clerk whether your filings were sealed or redacted. This is the question the notification letter will not answer for you, and the one that decides whether your exposure is financial or physical.
  • If you are under a protective order or an address program, tell your advocate now. Safety plans get rebuilt on the assumption that a location is still private. That assumption may be stale.

What to Watch Next

Three things are still missing: who did it, how many people are in the files, and whether anything surfaces for sale. Thomson Reuters has named no attacker, published no individual count, and reports no evidence of fraud so far. State attorney general breach notification filings will produce the first hard numbers.

The structural question outlasts this story. Courts across dozens of jurisdictions handed case management to one vendor, and one vendor's cloud environment then became the single place where a seal could fail for all of them at once. The federal judiciary is spending real money to modernize the system it controls, per the Administrative Office of the US Courts. State appellate courts bought theirs, which is cheaper and faster right up to the moment it is neither.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.