Thomson Reuters has confirmed that an unauthorized third party obtained files from C-Track, the court case management platform its West Publishing unit sells to judiciaries across North America. The company says it discovered the unauthorized activity on June 30, 2026, and that its investigation traced the file theft back to March 2026, roughly three months before detection. Public disclosure landed on September 2 and 3, more than five months after initial access. Affected jurisdictions include appellate and trial courts in at least a dozen U.S. states, the U.S. Virgin Islands, and three Ontario courts. Thomson Reuters has not identified the attacker, has not explained how access was gained, and has not published a count of affected individuals. No source in this set provides a record or victim figure; the Kentucky Administrative Office of the Courts stated plainly that as of Wednesday the number of affected individuals and organizations is not known.
What Happened
The timeline is consistent across sources on the two anchor dates. C-Track discovered unauthorized activity involving certain files on June 30, 2026. A subsequent investigation with outside cybersecurity experts and law enforcement determined that in March 2026 an unauthorized party obtained C-Track files.
The dwell time is where accounts sharpen. Montana Supreme Court Chief Justice Cory Swanson said West Publishing informed the Montana Office of Court Administrator on July 23 that unauthorized access ran from March through June 2026. TechNadu describes the window more precisely as March 1 to June 29. The Record notes that Montana's separate disclosure suggests the attacker was present in the records environment continuously until discovery, rather than executing a single March smash-and-grab. Thomson Reuters' own public framing emphasizes the March file acquisition and is less explicit about the intervening months.
Scope counts differ, and the difference is not cosmetic. CNA and TechNadu report 11 U.S. states plus the U.S. Virgin Islands and Canada. Help Net Security, The Record, and The Next Web put it at 12 U.S. states or jurisdictions. The likely cause is that Pennsylvania appears in some vendor lists and not others, and the roster has kept growing after publication. Help Net Security reports the Oregon Judicial Department separately confirmed its appellate courts were affected. The Next Web reports Minnesota's judicial branch disclosed an exposure the same week, which pushes the real count above the wire-copy figure. Treat any single number as a floor, not a total.
The jurisdictions named in Thomson Reuters' U.S. notice, per Help Net Security's detailed enumeration, include the Alabama, Kentucky, Nevada, and Tennessee appellate courts; the Montana Supreme Court; the North Dakota Supreme Court; the New Hampshire Supreme Court; the South Carolina Supreme Court and Court of Appeals; ten Ohio District Courts of Appeals plus two Ohio and Pennsylvania courts of common pleas; the Fifth Judicial District of Pennsylvania; the U.S. Virgin Islands Supreme and Superior Courts; the entire Wyoming Judicial Branch; and the Pennsylvania Environmental Hearing Board, a former client. In Canada, the Court of Appeal for Ontario, the Ontario Superior Court of Justice, and the Ontario Court of Justice were hit, with the three chief justices issuing a joint statement.
Thomson Reuters has been emphatic on one point: the breach occurred inside its own environment and was not caused by the networks, systems, or data security of the affected courts. Montana's release echoes that the data was stored entirely in a Thomson Reuters system.
What Was Taken
There is a real spread in how the exposure is characterized, and it appears to track who is describing it.
The broad version, carried in Thomson Reuters' notification pages and repeated by The Record, Fox 9, The Next Web, and the Kentucky AOC, is that affected records may contain names alongside Social Security numbers, driver's license numbers, medical information, dates of birth, and health insurance information. The company also states that confidential, redacted, or sealed information may have been affected at some courts.
The narrower version comes from Montana and from TechNadu's read of the West Publishing notice. Chief Justice Swanson's release says most of the information appears to be already publicly available court data, with some driver's license numbers and dates of birth found among it. TechNadu similarly describes a significant portion of the compromised files as public docket data, with PII limited to names, dates of birth, and driver's license numbers. TechNadu also reports that the stolen material was C-Track and e-filing backup data held on Thomson Reuters servers.
Minnesota adds a further wrinkle. Fox 9 reports state officials said case documents such as orders and briefs were not included in the breach, while The Next Web reports Minnesota warned some confidential or sealed documents may have been caught. These are not obviously reconcilable, and the honest reading is that per-jurisdiction impact varies and the assessments are still moving.
Thomson Reuters says there is no evidence to date that the incident has resulted in fraud or misuse. Kentucky's AOC says it has no indication the data was distributed onward. Neither is the same as evidence of non-exfiltration to a third party.
Why It Matters
Court records are a uniquely bad thing to lose. A docket may be public, but the underlying file can hold a sealed juvenile matter, a domestic violence protective order with an address in it, a medical filing, a witness identity, or a settlement under seal. The public-record framing that Montana and TechNadu lean on is accurate for the bulk of the volume and misleading for the risk, because the harm concentrates entirely in the small sealed and confidential fraction.
Second, this is a single-vendor compromise that reached the appellate tier of a dozen-plus separate sovereign judiciaries at once, including two national-level bodies in the Ontario court hierarchy. No court was individually attacked. The concentration risk sat in the shared case management vendor, and the courts inherited it. That is the same structural pattern that has driven the last several years of large public-sector breaches, applied here to a branch of government with limited independent security capability.
Third, the detection gap. Files taken in March, activity found June 30, public notice September 2. Even taking the company's own timeline at face value, that is roughly 120 days to detection and another 64 to disclosure. Montana officials were told on July 23, more than five weeks before the public was.
The Attack Technique
Unknown, and the sources are unanimous in saying so. The Record states directly that Thomson Reuters has not disclosed how the attacker gained access, who was responsible, or how much data was taken. No ransomware group has claimed the incident in any source here, no CVE or exploited product has been named, and no extortion demand has been reported.
What can be said with reasonable confidence: the target was backup data rather than the live production platform. TechNadu reports third parties gained unauthorized access to C-Track and e-filing backup data stored on Thomson Reuters servers, and Montana's release describes unauthorized access to court backup data files. The Next Web, citing Reuters, reports the activity was detected in the company's cloud environment. Thomson Reuters says C-Track was never disrupted and remains fully operational, which is consistent with a data-access event against stored backups rather than an intrusion into the running application.
That combination, cloud-hosted backup repositories, months of undetected access, and no service impact, is the signature of a data-theft operation against secondary storage. It is worth flagging that backup stores are routinely excluded from the monitoring and access controls applied to production, which is precisely why they are attractive. Absent a company statement, this remains inference rather than confirmed fact.
Thomson Reuters says it has implemented new security measures reviewed and approved by outside experts, though The Record notes the company declined to name those experts. It is offering 12 months of free credit monitoring and identity theft protection to affected individuals, via ctracknotification.com and a dedicated call line.
What Organizations Should Do
-
Inventory your backup and secondary storage the way you inventory production. If your cloud backup repositories, e-filing archives, and snapshot buckets are not covered by the same logging, alerting, and access review as the live system, that gap is the exposure. Ask specifically who can read backups and whether those reads are logged.
-
Push detection coverage to bulk-read patterns, not just intrusion. A four-month gap between access and discovery means nothing alerted on large-scale file retrieval. Baseline normal read volume per service account and alert on deviation, particularly for archive tiers where legitimate reads are rare.
-
If you are a C-Track jurisdiction, do what Minnesota did. The Minnesota Judicial Branch terminated Thomson Reuters' access to court electronic environments, audited accounts, and brought in independent technical review plus state authorities. Vendor access revocation and a full account audit is the correct immediate posture even where the vendor asserts the breach was contained on its side.
-
Separately track sealed and confidential material. The single hardest question in this incident is which sealed filings were in the taken files, and the answer varies by jurisdiction. If your case management vendor cannot tell you which sealed records were in a given backup set, that is a contract and architecture problem to fix now, not during the next incident.
-
Rewrite vendor notification terms. Montana learned on July 23; the public learned on September 2. Contracts with judicial and public-sector clients should specify notification clocks measured in days from vendor discovery, with a scope-update obligation as the investigation expands, because in this case it kept expanding after the initial disclosure.
-
For affected individuals, assume the broad data set applies. Enroll in the offered monitoring, place credit freezes rather than relying on alerts alone, and treat identity-theft risk as live even though the company reports no confirmed misuse. Parties to sealed or protective-order cases should raise exposure directly with the clerk of the relevant court.
Expect the jurisdiction list to grow further. Two states, Oregon and Minnesota, surfaced after the initial notice, and neither appears in the wire-service count.
Sources: Thomson Reuters reveals breach that exposed U.S. and Canadian court... | US and Canadian court data exposed in Thomson Reuters breach | Thomson Reuters detects cybersecurity incident, says unauthorized p... | A breach at Thomson Reuters reached appellate courts in twelve US j... | MN court data breach: Private user data exposed after third-party v... | Thomson Reuters C-Track Breach Hits U.S. and Ontario Courts - TechNadu | Data breach hit Montana state courts from March to June, chief just... | Ky. courts filing system part of ‘cybersecurity incident,’ official...