Skip to content

Thomson Reuters Court Software Exposed Sealed Case Data

West Publishing says an unauthorized party took files from C-Track, the court case system used in 11 US states, the US Virgin Islands, and Ontario. Sealed.

By THEYDIDNTASK
Thomson Reuters Court Software Exposed Sealed Case Data
Thomson Reuters Court Software Exposed Sealed Case Data

TL;DR

  • —Court records are supposed to be boring in a specific way: docket numbers, party names, and a clerk who can tell you what is public.
  • —A vendor breach is the other version of that story.
  • —On 2 September 2026, West Publishing Corporation, a Thomson Reuters unit, said an unauthorized party obtained files from C-Track, the court case management platform it sells.
Court records are supposed to be boring in a specific way: docket numbers, party names, and a clerk who can tell you what is public. A vendor breach is the other version of that story. The filing system itself becomes the leak. On 2 September 2026, West Publishing Corporation, a Thomson Reuters unit, said an unauthorized party obtained files from C-Track, the court case management platform it sells. The company says the access happened in March 2026 and that it discovered the activity on 30 June 2026. There is no public count of affected people, no named attacker, and no confirmed method of access. That gap matters. So does the data class. What the vendor says was taken West Publishing's notice says a subset of court records could contain names, Social Security numbers, driver's license numbers, dates of birth, medical information, and health insurance information. It also says confidential, redacted, or sealed information may have been impacted for certain courts. The company says it has found no evidence of fraud or misuse so far. Credit monitoring is being offered through Experian in the US, with enrollment listed through 31 December 2026, and TransUnion in Canada. A Thomson Reuters spokesperson told Reuters there has been no operational disruption to C-Track and that the company considers the platform safe to keep using. Several courts have said they still lack a complete picture of what was copied. Which courts are in the notice The West Publishing and Canadian notices name court bodies in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, Wyoming, the US Virgin Islands, and Ontario. Minnesota is a useful extra data point. The Minnesota Judicial Branch said on 2 September that appellate court data was exposed, that it had terminated Thomson Reuters' access to its electronic environments, and that users of the appellate case management system must change passwords. Minnesota Supreme Court Chief Justice Natalie Hudson called the compromise of court-user data "deeply troubling." Ohio's Supreme Court said Thomson Reuters Court Management Solutions told it on 31 August that unauthorized access took place on the court's production platform for ten appellate districts using C-Track. Montana said the material taken was backup data stored on Thomson Reuters servers, supplied for troubleshooting. Alabama's appellate courts said a copy of some data sat in a backup file they had neither requested nor known about. Those three accounts do not describe the same environment. Production, vendor backups, and troubleshooting copies are different trust boundaries. If a court cannot say which one was hit, it also cannot say with confidence what a sealed file looks like in the stolen set. Why sealed court data is a different leak A leaked customer email list is bad. A leaked court file can include: People who were never convicted, or whose cases were sealed for a reason the public docket no longer shows. Addresses, dates of birth, and identity numbers collected because a court needed them, not because a user "signed up." Medical and family information that is in a case file because the dispute required it. Nobody opted into C-Track the way they opt into airport Wi-Fi. The data is there because the state required it. The delay is part of the story Unauthorized access in March. Discovery at the end of June. Court notifications in late July. Public disclosure on 2 September, which Montana said was coordinated so states could announce together. Coordinated disclosure can be responsible. It can also mean months where a person whose sealed case sat on a vendor disk had no reason to freeze credit, watch for impersonation, or ask a clerk what was in the file. As of 3 September 2026, no party had published a count of affected individuals. What to do if you might be in it If you had a case in one of the listed courts between roughly 2015 and 2026, treat this as a vendor identity event, not a website password reset. Freeze credit if your SSN may have been in a court file. Watch for targeted phishing that cites a case number, a court name, or a "C-Track notification." Use the vendor notice and court statements, not a random email, to enroll in monitoring. If you are a court user or attorney, change passwords on the case-management system as your court instructed. The password exposure check and data broker opt-out list are useful follow-ups. They will not unspread a sealed PDF. What this does not prove It does not prove that every sealed record in every listed court was copied. It does not prove the attacker is a known extortion group. It does not prove production systems in every jurisdiction were the source. It does prove something simpler: courts outsourced the filing cabinet, and the filing cabinet lived in someone else's cloud. When that copy is taken, the people in the file are the last to hear.