The disclosure that an unauthorized party obtained files from Thomson Reuters’ C-Track court case-management environment highlights the unusually sensitive risks created when judicial systems depend on centralized third-party technology providers. The incident affected court systems across at least 11 U.S. states, the U.S. Virgin Islands and Ontario, Canada, with Minnesota also separately confirming exposure involving its appellate courts. Thomson Reuters discovered the unauthorized activity on June 30, 2026, and its investigation determined that certain C-Track files had been obtained in March. Depending on the affected court and dataset, the information may have included names, Social Security numbers, driver’s license numbers, dates of birth, medical information, health-insurance information and, in some cases, confidential, redacted or sealed material. At the time of disclosure, the total number of individuals affected had not been published, and the method used by the attacker to gain access had also not been disclosed.
The nature of the compromised information makes this incident materially different from an ordinary commercial database breach. Court systems contain information collected because of litigation, criminal proceedings, family disputes, medical claims and other highly sensitive matters. Some individuals whose data appears within court files may never have voluntarily created an account with the technology provider at all. They may be defendants, witnesses, victims, family members, attorneys or other parties mentioned in documents created during judicial proceedings. This means the affected population can extend far beyond conventional customers, making notification, data mapping and risk assessment substantially more complicated. Ontario’s courts acknowledged this problem directly, noting that anyone involved in court proceedings or mentioned in court documents could potentially have had personal information involved.
The possibility that sealed or confidential information may have been affected is particularly serious. Sealing is not merely an administrative label. Courts restrict access to certain records because public disclosure could create legal, safety or privacy consequences. Such material may relate to juveniles, protected witnesses, health information, family matters or other sensitive proceedings. If an external attacker obtains data that the judicial system itself has deliberately decided should not be publicly accessible, the consequences extend beyond ordinary identity theft. The breach can undermine the confidentiality guarantees on which individuals, lawyers and courts rely when sensitive information is submitted into the judicial process.
The incident also demonstrates the concentration risk created when many independent public institutions rely on the same technology provider. A vulnerability or security failure affecting one court’s internal system may expose one jurisdiction. A compromise affecting a widely used court-management vendor can potentially create exposure across multiple states and even national borders. This is one of the recurring risks associated with technology consolidation: centralization provides operational efficiency, but it also creates a larger blast radius when the shared provider is compromised. From a security perspective, major legal, healthcare, financial and government SaaS providers increasingly resemble critical infrastructure even when they are technically commercial software companies.
Different court statements also reveal an important issue around data residency and data copies. Montana said the compromised material involved backup data stored on Thomson Reuters systems that originated from database copies supplied for application troubleshooting. Alabama similarly said it learned that some appellate-court data had been retained in a backup file in the vendor’s cloud environment, a backup the court said it had neither requested nor known about. Ohio, however, said the unauthorized access occurred on a production platform hosting filing-system information for multiple appellate districts. These differences matter because organizations cannot adequately protect information they do not know exists. Vendor governance therefore has to address not only the primary production database but also troubleshooting copies, backups, temporary exports, development datasets and other secondary repositories where sensitive information may persist.
This is a broader lesson for enterprises as well. Data minimization does not stop when information leaves the production application. Copies generated for testing, support, troubleshooting or disaster recovery may contain exactly the same sensitive records and often receive less security scrutiny. If a vendor requests a production database to diagnose a problem, organizations should know what information is being transferred, why it is required, where it will be stored, how access will be controlled and when it will be deleted. A forgotten support copy can ultimately become as sensitive as the original production database, except that nobody remembers to include it in the threat model.
The time between initial unauthorized access and detection is another important point. The activity reportedly began in March, while Thomson Reuters detected the incident on June 30. Montana’s disclosure states that unauthorized access to the relevant storage location extended from March 1 through June 29. A persistence window approaching four months should prompt organizations to examine whether monitoring around sensitive cloud repositories and vendor-managed systems is sufficiently effective. Logging access is only useful if unusual behaviour is actually detected and investigated. Large downloads, access from unexpected locations, abnormal authentication behaviour or repeated retrieval of backup datasets should trigger scrutiny, particularly when the repository contains judicial or regulated information.
It is also worth noting that no operational disruption was reported. Thomson Reuters said C-Track remained operational and safe to continue using. This illustrates why availability alone is a poor indicator of cybersecurity health. Many serious breaches are designed specifically to avoid disruption because attackers interested in information theft benefit when applications continue operating normally. An organization can therefore have 100% service availability while simultaneously experiencing a significant confidentiality breach. Monitoring programmes must distinguish between operational availability and security integrity rather than assuming that systems functioning normally are necessarily uncompromised.
The Minnesota response is particularly notable because the Judicial Branch terminated Thomson Reuters’ access to its electronic environments and required users of the appellate case-management system to change their passwords. Even though the precise relationship between Minnesota’s exposure and the broader vendor incident was still being clarified at the time of reporting, disabling vendor access is an example of containment that organizations should consider whenever a trusted third party experiences a security incident. Vendor connectivity is frequently persistent and privileged. If the security of that connection becomes uncertain, continued access can provide a pathway into customer environments even after the original vendor compromise has been identified.
This highlights why third-party access should be designed around zero-trust principles. Vendors should not retain unrestricted permanent connectivity simply because they provide support for an application. Access should ideally be time-bound, authenticated with strong multi-factor controls, limited to specific systems and recorded in sufficient detail for forensic review. Administrative sessions should be attributable to individual users rather than shared vendor accounts, and high-risk actions such as database exports should generate alerts. Organizations should also be capable of revoking vendor access rapidly without disrupting the entire service.
Encryption deserves similar scrutiny. Encrypting data at rest is important, but it does not prevent information from being stolen when an attacker obtains legitimate application or cloud-account access that can decrypt the files normally. For highly sensitive court information, organizations need layered protections including identity controls, authorization boundaries, monitoring, segmentation and data-loss detection in addition to encryption. A backup containing millions of encrypted records remains vulnerable if the compromised account has permission to retrieve and decrypt that backup.
The incident also reinforces the importance of understanding the shared-responsibility model for SaaS and hosted applications. Courts may outsource operation of case-management software, but they cannot outsource accountability for the information entirely. Public institutions need contractual visibility into where data is hosted, how backups are maintained, what subcontractors are involved, how security incidents will be communicated and how quickly forensic information will be made available. The fact that several courts publicly stated they were still awaiting comprehensive details illustrates how dependent customers can become on the vendor’s investigation after an incident occurs.
For organizations using third-party platforms to process sensitive information, security assessments should therefore move beyond questionnaires asking whether the vendor has ISO certification, encryption or a penetration test. More practical questions matter: how quickly can the provider detect abnormal data access, who can retrieve customer backups, whether production datasets are copied for troubleshooting, how long those copies remain available, whether customers can audit administrative activity and how vendor access can be terminated during an incident.
Incident-response planning must also include vendors before an incident occurs. When a breach affects multiple jurisdictions simultaneously, coordination becomes complicated because courts, law enforcement agencies, privacy authorities and the technology provider may all have different notification responsibilities. The Thomson Reuters disclosures appear to have been coordinated for September 2, with various jurisdictions issuing statements at roughly the same time. That type of coordination is useful, but the underlying incident also shows why predefined communication procedures are necessary when one provider supports many independent organizations.
For individuals potentially affected, the long-term risk is difficult to quantify because court data can be unusually persistent. Social Security numbers and driver’s license information create conventional identity-theft risks, while medical records and sealed case information can create privacy, extortion or social-engineering opportunities. Attackers possessing detailed knowledge of a person’s legal proceedings can also construct far more convincing phishing messages than criminals working with ordinary breached email addresses. A message referencing an actual court case, attorney or filing can appear highly credible to the recipient.
Security teams should therefore recognize that the value of stolen information comes from context as much as from individual data fields. A name and date of birth may have limited value in isolation. The same information combined with a court case number, legal dispute, medical record or sealed proceeding becomes far more useful for impersonation and targeted fraud. Context-rich datasets deserve correspondingly stronger protection.
The broader lesson from the C-Track incident is that judicial digital transformation creates dependency on technology providers whose security posture becomes inseparable from the security of the courts themselves. Moving case management into centralized platforms can improve efficiency, accessibility and administration, but it also concentrates enormous quantities of sensitive information into infrastructure that becomes an attractive target.
Courts therefore need to treat their technology supply chain with the same seriousness they apply to the confidentiality of the proceedings themselves.
A sealed document does not remain confidential merely because a judge marked it sealed.
It remains confidential only if every system, backup, administrator and vendor that can access it preserves that boundary.
The Thomson Reuters incident shows what happens when that chain of trust becomes the attack surface.

Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names
Source: Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data via The Hacker News — published 03 Sep 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.