Thomson Reuters Says Court Records Software Breached, 11 States Affected

West Publishing's C-Track platform, used by courts across the U.S. and beyond, had files taken by an unauthorized party in March. Thomson Reuters only spotted the activity three months later.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial 16:9 image of a large Japanese urban data centre at dusk, exterior shot, rows of cooling units and server ventilation grilles lit by am
Share

Key points

  • Thomson Reuters disclosed on Wednesday that an unauthorized party took files from C-Track, a court case management platform sold by its West Publishing Corporation unit.
  • The intrusion happened in March 2026 and was discovered by West Publishing on June 30, 2026, a gap of roughly three months.
  • Courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada relied on the affected software.
  • A subset of the court records taken may contain the names of individuals.
  • The disclosure will draw scrutiny under state breach notification laws and, for any listed-company reporting, the SEC's cybersecurity disclosure rule at 17 CFR 229.106.

Thomson Reuters has told regulators and customers that hackers broke into C-Track, a piece of software courts use to manage case files, and copied documents out. The company's West Publishing Corporation unit sells the platform.

The intrusion took place in March 2026. West Publishing says it only detected the activity on June 30, 2026. That is a detection gap of roughly three months, a point that state attorneys general and privacy regulators tend to focus on when they review a breach.

Courts in 11 U.S. states, the U.S. Virgin Islands, and the Canadian province of Ontario used the affected system. Thomson Reuters says a subset of the files taken may include the names of individuals. The company has not, in its public statement, said whether Social Security numbers or sealed records were among the exposed documents, though the possibility was raised in earlier reporting by The Hacker News.

What actually happened?

Someone got into the C-Track platform without permission and pulled files out. C-Track is the tool clerks and judges use to track case dockets, filings, and hearing schedules. If you have ever been to court, some record of you likely sits in a system like this.

Thomson Reuters has not named a group, a method of entry, or a ransom demand. The company describes the event as unauthorized access to files, not as ransomware, which is malicious software that locks a victim's data until they pay.

Which courts were affected?

Courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. Thomson Reuters has not published the full list of jurisdictions in the statement reviewed for this piece. Notifications to individual court administrators are expected to identify specific courts.

Fact Detail
Platform C-Track case management software
Operator West Publishing Corporation (Thomson Reuters unit)
Intrusion date March 2026
Discovery date June 30, 2026
Jurisdictions 11 U.S. states, U.S. Virgin Islands, Ontario
Data at risk Court records, may include names

What are the regulatory stakes?

Several. Each U.S. state has its own breach notification statute with its own clock, typically 30 to 60 days from discovery, and Ontario's Personal Information Protection and Electronic Documents Act (PIPEDA) requires notice of breaches posing a real risk of significant harm.

For Thomson Reuters itself, a Toronto- and New York-listed company, the U.S. Securities and Exchange Commission's cybersecurity disclosure rule at 17 CFR 229.106, finalised in July 2023, requires registrants to describe material cybersecurity incidents on Form 8-K within four business days of a materiality determination. Whether the C-Track incident meets that materiality bar is a judgment the company has to make and, if challenged, defend.

Courts and their clerks are themselves subject to state records laws, and any sealed material caught up in the files raises a separate set of duties owed to litigants.

What should ordinary people do?

If you have had a case in one of the affected courts, watch for a written notice from the court or from Thomson Reuters. Do not rely on email alone: notification laws generally require postal mail for sensitive data.

Be wary of phone calls or emails claiming to be from a court and asking you to confirm personal details. Real court staff will not ask for a Social Security number by email. If in doubt, call the clerk's office using a number from the court's own website.

© 2026 Threat Vectr