Thomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, which exposed court records and sensitive personal information across numerous jurisdictions in the United States and Canada. The company publicly announced the incident on Wednesday, September 2, 2026, alongside dedicated notification pages for individuals in both countries.
The breach was discovered on June 30, 2026, when Thomson Reuters identified unauthorized activity related to certain C-Track information. An investigation, conducted with external cybersecurity experts and law enforcement, determined that an unauthorized third party had accessed and obtained C-Track files in March 2026.
In Canada, the affected court systems include the Court of Appeal for Ontario, the Ontario Superior Court of Justice, and the Ontario Court of Justice. The chief justices of these courts noted that the precise scope of compromised information and the number of affected individuals remain under assessment. They indicated that personal information of individuals involved in or mentioned in court proceedings could have been exposed.
In the U.S., the breach impacted appellate courts in Alabama, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, and New Hampshire. Also affected were the entire state court system of Wyoming, the U.S. Virgin Islands Supreme and Superior Courts, and multiple District Courts of Appeals in Ohio (First, Second, Third, Fourth, Fifth, Sixth, Seventh, Ninth, Eleventh, and Twelfth). County-level courts in Pennsylvania (Washington County and the Fifth Judicial District) and Ohio (Monroe County) were also affected. The Oregon Judicial Department confirmed its appellate courts were impacted, and the Commonwealth of Pennsylvania Environmental Hearing Board, a former client, was also involved.
Thomson Reuters stated that the incident occurred within its own cloud environment and was not a result of vulnerabilities in the networks, systems, or data security of the affected courts. The C-Track platform remains fully operational, and the company has implemented additional security measures, reviewed and approved by outside experts.
The exposed data varied by location but may have included individuals' names along with one or more of the following: Social Security numbers, driver's license numbers, medical information, dates of birth, and health insurance information. In some U.S. courts, confidential, redacted, or sealed court information may also have been compromised.
As of the disclosure, Thomson Reuters has found no evidence that the exposed information has been used for fraud or other misuse, nor that systems handling financial transactions were affected. The company is offering 12 months of free credit monitoring and identity theft protection to all affected individuals.
Key details regarding the identity of the attacker, the full extent of data taken, and the method of initial access remain publicly undisclosed by Thomson Reuters. The company's investigation with cybersecurity experts and law enforcement is ongoing.






