Cyber & AI intelligence
Wasteland.
Briefs indexed2998
Issues30
Published Mondays07:30 CT
▣ Breach THOMSON-REUTERS-C 2026-10-04

Thomson Reuters: Unauthorized Third Party Takes C-Track Court Files Across US and Ontario

"Thomson Reuters has confirmed that an unauthorized third party obtained files from C-Track in March 2026. C-Track is the court case management and e-filing platform sold by its West Publishing Corporation unit. The…"

Thomson Reuters has confirmed that an unauthorized third party obtained files from C-Track in March 2026. C-Track is the court case management and e-filing platform sold by its West Publishing Corporation unit. The files belong to appellate and trial courts in at least 11 US states, the US Virgin Islands and three Ontario courts. They may contain Social Security numbers, driver's licence numbers, medical and health insurance information, and confidential, redacted or sealed filings. The company detected the activity on June 30, 2026 and published notices on September 2, about six months after the files were taken. How many people are affected has not been disclosed, and no threat actor has been named. Sources disagree on how many jurisdictions are involved. The vendor's own notice lists 11 states plus the USVI (Reuters, The Hacker News, Beinsure). Help Net Security says "at least 12 US states" once Oregon is counted. The Next Web and Hard2bit also say Minnesota disclosed separately, which would put the total at 13 states.

Editorial note on the Arizona Courts entry: We checked this incident against our earlier Arizona Courts coverage, and it does not appear to be the same event. Arizona is not named in the vendor notice or in any source here. Our Arizona reporting described an attack on the state court system that Chief Justice Ann Scott Timmer said in-house IT staff "found and shut down quickly". That does not match a vendor-side theft that went undetected for months. Unless Arizona confirms that C-Track was involved, treat the two as separate incidents. This brief is the vendor-level parent story for every C-Track-related court disclosure.

What Happened

All eight sources broadly agree on the timeline:

Affected court systems named in the vendor notices (Help Net Security, The Hacker News):

Disclosed separately by courts: Oregon Judicial Department appellate courts (Help Net Security, Hard2bit) and the Minnesota Judicial Branch (The Next Web, Hard2bit). Help Net Security warns that the list "is likely not complete" because individual courts keep issuing their own disclosures.

The company says C-Track stayed up the whole time: "There has been no operational disruption" (Beinsure, The Next Web). Breached.Company lists the investigation as ongoing.

What Was Taken

Volume: Not disclosed. No source gives a record count, file count or number of affected individuals. Hard2bit and Help Net Security both point out that neither the volume taken nor the method of access has been made public.

Data types, according to West Publishing's notice (via The Hacker News and The Next Web), may include:

Nature of the files: If the Montana Supreme Court's account (quoted by Hard2bit) is accurate, the files were "copies of the compromised databases, which had been supplied to TR for the purpose of troubleshooting the applications". In other words, they were full database extracts and not just individual documents. This comes from a single court's statement, and Thomson Reuters has not confirmed that it applies to every jurisdiction.

Misuse: West Publishing says there is "no evidence to date of fraud or misuse" (The Hacker News). There is no public leak-site claim and no extortion demand in any of the sources.

Remediation offered (The Hacker News): - US: 12 months of Experian IdentityWorks, enrolment open until December 31, 2026. Hotline 1-833-918-5294, engagement number B171847. - Canada: 12 months of TransUnion myTrueIdentity through Thomson Reuters Canada Limited. The call centre was due to open September 4.

Why It Matters

The people exposed never chose this vendor. Litigants, defendants, witnesses and victims end up in C-Track because a court uses it, not because they signed up with Thomson Reuters. Breached.Company cites Insurance Business on the point: the data "belongs to individuals who never consented to being" customers of the company holding it.

Sealed records carry physical-safety risk. The Next Web notes that a case file can hold a protective order, a sealed juvenile matter or a medical filing. Once an address is linked to that kind of context, it is far more dangerous than a retail breach record. Sealed filings exist so that this information stays out of reach, and this breach puts it potentially out of the courts' control.

One vendor became a single point of failure. A single cloud environment at a single vendor held data from at least 15 separate judicial bodies in two countries. A whole state's judiciary (Wyoming) sits alongside individual county courts. Each court did its own risk assessment, and the risk was concentrated at the vendor anyway.

The detection gap is long. The files were taken in March and the activity was detected June 30, a gap of about three months. Montana's account puts unauthorized access as running until June 29, which would mean the intruder was still inside when detection happened. Public notice came roughly nine weeks after detection.

Disclosure is fragmented. Because each court discloses on its own schedule, the scope keeps growing after the vendor's notice. Defenders and affected individuals cannot rely on the vendor notice alone to tell whether they are exposed.

The Attack Technique

Not disclosed. Thomson Reuters has not said how the intruder got in, who it was, or whether credentials, a vulnerability or a third-party integration were involved. Hard2bit, Help Net Security and The Record (as cited by Hard2bit) all flag this gap.

What is known:

The attacker remains unidentified, and Breached.Company lists the actor only as an "unauthorized third party". Any attribution should wait for a confirmed statement from the vendor or law enforcement.

What Organizations Should Do

  1. Inventory every data copy you have given to vendors. List each database dump, log bundle or sample dataset sent for troubleshooting, migration or testing. Record where each one sits, who can access it, and when it will be deleted. Treat these copies as production data.
  2. Require written retention and destruction terms for support copies. Contracts should set a deadline for deleting troubleshooting data, require proof of deletion, and forbid vendors from keeping copies on their own initiative. Audit compliance.
  3. Minimise data before it leaves your hands. Mask or tokenise SSNs, health data and sealed or redacted fields before sharing a dataset with a vendor. Most bugs can be reproduced with synthetic or redacted data.
  4. If you are a C-Track customer, demand scope details directly. Ask the vendor exactly which of your files, which date ranges and which sealed or confidential case types were taken. Ask whether troubleshooting copies of your data are still held anywhere. Do not rely on the public notice.
  5. Prioritise notification for safety-sensitive parties. Courts should identify protective-order petitioners, sealed juvenile matters and victim or witness records in the affected data. Contact those people directly, not just through generic credit-monitoring offers, because the main risk to them is physical and not financial.
  6. Plan for vendor-side detection delays. Write contractual breach-notification SLAs measured from the vendor's detection date. Run tabletop exercises in which a critical SaaS provider discloses months after the fact, including how you would coordinate disclosure with peer organisations that use the same platform.

Sources: Thomson Reuters C-Track Breach Hits Courts in 11 States Breached.C... | Thomson Reuters reveals breach that exposed U.S. and Canadian court... | Thomson Reuters detects cyber security incident, says unauthorised... | Thomson Reuters detects cybersecurity incident, says unauthorized p... | Thomson Reuters Court Software Breach May Have Exposed SSNs and Sea... | A breach at Thomson Reuters reached appellate courts in twelve US j... | C-Track breach at Thomson Reuters: support copies exposed | Thomson Reuters C-Track cyber incident affects US and Canadian courts