Thomson Reuters has disclosed a security breach involving its C-Track case management platform, compromising court records and personal data across numerous jurisdictions in the United States and Canada.
The company publicly revealed the incident on September 3, 2026, launching dedicated notification portals for affected individuals in both countries. According to Thomson Reuters, unauthorized activity within its cloud environment was first discovered on June 30, 2026, though subsequent investigations revealed that an unauthorized third party had accessed and obtained specific C-Track files as early as March 2026.
The breach impacts court systems across at least 12 U.S. states, the U.S. Virgin Islands, and multiple Canadian provinces. Among the affected jurisdictions are the Court of Appeal for Ontario, the Ontario Superior Court of Justice, the Ontario Court of Justice, Alabama Appellate Courts, the Montana Supreme Court, Nevada Appellate Courts, North Dakota Supreme Court, the Wyoming Judicial Branch, and the U.S. Virgin Islands Supreme and Superior Courts, alongside several county and district courts in Ohio and Pennsylvania.
Exposed data varies by location but frequently includes individual names combined with sensitive personal identifiers such as Social Security numbers, driver’s license numbers, dates of birth, medical details, and health insurance information. Furthermore, U.S. disclosures warn that confidential, redacted, or sealed court documents may have been compromised in certain jurisdictions, while Canadian chief justices confirmed that the exact scope of affected records and impacted individuals remains under evaluation.
In a joint statement regarding the ongoing assessment, Canadian court officials noted: “If individuals have been involved in court proceedings or may have been mentioned in court documents, it is possible that some personal information relating to them could have been involved in the incident.”
Thomson Reuters stated that C-Track remains fully operational and that the incident stemmed entirely from its own cloud environment rather than the internal networks of the courts. In response to the breach, the company has deployed enhanced security controls reviewed by outside cybersecurity experts and is offering 12 months of free credit monitoring and identity theft protection to all affected individuals.