Thomson Reuters has disclosed a cybersecurity incident involving C-Track, a court case management platform operated by its West Publishing unit, after an unauthorized party obtained files from the system in March 2026.
The incident affects courts across 11 U.S. states, the U.S. Virgin Islands and Ontario, Canada. West Publishing said it discovered the unauthorized activity on June 30. Some of the affected court records may contain sensitive information, including names, Social Security numbers, driver’s license numbers, dates of birth, medical information and health insurance details.
Thomson Reuters said it is offering potentially affected people in the United States 12 months of Experian IdentityWorks credit monitoring. In Canada, affected individuals will be offered 12 months of TransUnion myTrueIdentity monitoring.
The company has not disclosed how many individuals were affected or explained exactly how the files were obtained. It also said there is currently no evidence that the exposed information has been used for fraud or other misuse.
The affected court systems include appellate and supreme courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee and Wyoming, as well as courts in the U.S. Virgin Islands and Ontario.
Several courts have provided additional details about the incident. Minnesota’s Judicial Branch said its appellate court data was exposed and that it had terminated Thomson Reuters’ access to its electronic environments. Minnesota also instructed users of its appellate case management system to change their passwords.
Montana’s Supreme Court said the accessed material consisted of backup data stored on Thomson Reuters servers. The databases could contain case numbers, names, addresses, phone numbers, docket information and, in some criminal cases, driver’s license numbers and dates of birth.
Alabama Appellate Courts said West Publishing later informed them that some court data had been stored in a backup file in the company’s cloud environment. The courts said they had not requested or known about the backup.
Ohio’s Supreme Court said Thomson Reuters informed it that the unauthorized access occurred on the production platform hosting filing-system data for 10 appellate districts. The Eighth and Tenth districts were not affected.
Ontario’s courts said Thomson Reuters detected the activity in one of its cloud environments and that it remains unclear what information may have been compromised. They warned that people involved in court proceedings or mentioned in court documents could potentially have had personal information exposed.
Wyoming’s Judicial Branch said the stolen material consisted of historical data from the state’s Supreme Court and district courts, primarily involving people who interacted with those courts between 2015 and 2025. Its preliminary review found that limited personal information, including names, addresses and dates of birth, had been compromised.
Thomson Reuters said there has been no operational disruption to C-Track and considers the platform safe to continue using. However, some courts said they were still waiting for comprehensive information about the security measures implemented following the incident.
The vendor notified affected courts and Ontario’s Ministry of the Attorney General between July 23 and July 27, with the public disclosures made on September 2. As of September 3, authorities and affected courts had not published a total number of impacted individuals, details about how the files were accessed or the identity of the person responsible.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
North Dakota’s court system said the incident was limited to Supreme Court data, while its district courts and Odyssey system were not affected. The state also said there was no evidence that its nCourt financial transaction system had been compromised and confirmed that an active criminal investigation is underway.





