AIO APEX

Thomson Reuters court software breach exposes sealed records across 12 US states

The Hacker News
Share:
Thomson Reuters court software breach exposes sealed records across 12 US states

Thomson Reuters disclosed on September 2 that attackers had accessed C-Track, its court case management platform, between March 1 and June 29, 2026 — a four-month window that exposed sensitive personal and judicial records across courts in 11 US states, the US Virgin Islands, and Ontario, Canada.

The affected states are Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, and Wyoming. Montana's Supreme Court confirmed its system was among those compromised. The breach was discovered June 30, courts and provincial authorities were notified by late July, and public disclosure came September 2 — more than two months after Thomson Reuters found the intrusion.

The exposed data is unusually sensitive for a vendor breach. Beyond standard identifiers like names, Social Security numbers, driver's license numbers, and dates of birth, C-Track also stores medical information, health insurance details, and — critically — sealed court records. Sealed documents can include protected witness information, juvenile records, mental health filings, and details of ongoing investigations that courts have ordered kept from public view.

Thomson Reuters operates the platform through its West Publishing Corporation unit. The company has not disclosed how many individuals are affected, what specific vulnerability was exploited, or whether the attackers were financially motivated or state-sponsored.

Affected individuals are being offered 12 months of free credit monitoring through Experian IdentityWorks in the US and TransUnion myTrueIdentity in Canada, with enrollment available through December 31, 2026. The breach underscores the systemic risk of centralizing sensitive judicial data with third-party SaaS vendors — particularly when the scope spans sealed records whose exposure cannot be undone, as reported by The Hacker News.

Originally reported by The Hacker News. Read the original article for additional details.

View original source
Share: