Thomson Reuters disclosed on Wednesday that an unauthorized party gained access to files from C-Track, a court case management platform operated by its West Publishing Corporation division, in a breach that affected courts across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. The company said West Publishing identified the unauthorized activity on June 30, 2026, nearly four months after the intrusion began in March. A portion of court records may include individuals' names, Social Security numbers, driver's license numbers, dates of birth, medical information, and health insurance details, according to the firm.
The unauthorized access continued from March 1 through June 29, 2026, according to Montana Supreme Court's account of the vendor's notification. The compromised data consisted of backup material housed on Thomson Reuters servers, pulled from database copies that had been provided to the company for troubleshooting purposes, Montana's court said. Alabama Appellate Courts reported that West Publishing later informed them a duplicate of some Alabama appellate court data was maintained in a backup file within the company's cloud infrastructure—a backup the courts said they had neither requested nor been aware of. The Supreme Court of Ohio, however, stated in its own announcement that Thomson Reuters Court Management Solutions notified it on August 31 that the unauthorized access occurred on the Court's production platform, which hosts filing system data for the 10 Ohio appellate districts using C-Track. The affected jurisdictions span Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, and Wyoming, plus the U.S. Virgin Islands and Ontario. Minnesota's Judicial Branch said on September 2 that data from its appellate courts was exposed in the incident, though Minnesota doesn't appear on the West Publishing notice reviewed by The Hacker News on September 3.
West Publishing said in its September 2 notice that "certain confidential, redacted or sealed information may have been impacted for certain affected courts," though the company added there's no evidence to date of fraud or misuse of the information. Minnesota Supreme Court Chief Justice Natalie Hudson said she is "deeply troubled that our court users' data has been compromised." The firm is providing potentially affected individuals 12 months of Experian IdentityWorks credit monitoring, with enrollment available until December 31, 2026, using a multi-use code published in the notice. A Thomson Reuters spokesperson told Reuters that "there has been no operational disruption to C-Track as a result of this incident," adding that the company considers the platform safe to continue using. North Dakota's Court System said "there is an active criminal investigation into this incident."
The vendor notified the courts and Ontario's Ministry of the Attorney General between July 23 and July 27, but public disclosure didn't follow until September 2—a date Montana said was selected so the vendor and other affected states could issue simultaneous announcements. As of September 3, no party had released a tally of affected individuals, the method through which the files were obtained, or the identity of whoever was responsible, according to the report. Wyoming said the material taken was historical data from the Wyoming Supreme Court and district courts, chiefly involving people who interacted with those courts between 2015 and 2025, with preliminary review indicating that "limited personal information, including names, addresses and dates of birth, was compromised." Ontario's three chief justices stated that "it is still unclear what information may have been compromised," and that anyone involved in court proceedings or mentioned in court documents could have had personal information involved. Minnesota has terminated Thomson Reuters' access to the courts' electronic environments and mandated that users of the appellate case management system change their passwords. The Supreme Court of Ohio said it has yet to receive comprehensive details of the enhanced security measures Thomson Reuters Court Management Solutions told it have been deployed. Courts that depend on third-party vendors for sensitive case management now face heightened scrutiny over backup practices they may not have authorized or known existed. The decision to house production data and backup copies in cloud environments without explicit court knowledge raises questions about vendor oversight in judicial technology contracts.

