A cybersecurity breach involving C-Track, a court case-management platform owned by Thomson Reuters subsidiary West Publishing Corporation, exposed court records associated with judicial systems across at least 12 U.S. states, the U.S. Virgin Islands and Canada, including information that may have been confidential, redacted or sealed.
Thomson Reuters disclosed that it discovered unauthorized activity involving C-Track information on June 30, 2026. The company launched an investigation with outside cybersecurity specialists and law enforcement and determined that an unauthorized party had obtained certain C-Track files in March 2026.
The company has not publicly identified the attacker, disclosed the initial access method, or stated how much data was removed. The number of individuals affected also remains undetermined.
Thomson Reuters emphasized that the incident occurred within its own environment and was not caused by the networks, systems or data-security practices of the affected courts.
C-Track is used by courts to manage case information, documents and records. Because those systems can contain both public filings and restricted material, the potential impact varies significantly by court and by case.
According to Thomson Reuters, a subset of affected court records may have contained names, Social Security numbers, driver’s license numbers, medical information, dates of birth and health insurance information.
The company also acknowledged that confidential, redacted or sealed information may have been affected at certain courts.
That disclosure is particularly significant because sealed and redacted court information is specifically restricted from ordinary public access and can contain sensitive personal, medical, criminal, family or identifying information.
Thomson Reuters said it has found no evidence to date that the breach resulted in fraud or misuse of the exposed information. It also said financial-transaction systems used by the courts were not affected.
The company reported that C-Track remained operational and that the incident did not prevent courts from continuing to use the platform.
The court systems named in Thomson Reuters’ U.S. notification include the Alabama Appellate Courts, Kentucky Appellate Courts, Montana Supreme Court, Nevada Appellate Courts, North Dakota Supreme Court, South Carolina Supreme Court and Court of Appeals, Tennessee Appellate Court Clerk’s Office, New Hampshire Supreme Court, Wyoming Judicial Branch, U.S. Virgin Islands Supreme and Superior Courts, and multiple courts in Pennsylvania and Ohio.
Pennsylvania entities identified in the notification include the Environmental Hearing Board, Court of Common Pleas of Monroe County, Court of Common Pleas of Washington County and Fifth Judicial District of Pennsylvania.
In Ohio, the notice identifies the First, Second, Third, Fourth, Fifth, Sixth, Seventh, Ninth, Eleventh and Twelfth District Courts of Appeals.
Separate disclosures indicate that the breach extended beyond the systems named in that notification.
The Oregon Judicial Department also disclosed that data from the C-Track system used by the Oregon Court of Appeals and Oregon Supreme Court was involved in the vendor breach, bringing the known U.S. state total to at least 12.
The scope of the incident appears to differ substantially between jurisdictions.
In Montana, the Supreme Court disclosed that Thomson Reuters informed state court administrators of unauthorized access to court backup data files from the state’s C-Track and E-Filing systems stored on Thomson Reuters servers.
Montana officials said they were informed that the unauthorized access occurred from March through June 2026. Thomson Reuters notified Montana Court Administrator Dave McAlpin on July 23, 2026.
That timeline indicates that data exposure associated with the Montana system may have extended over several months before Thomson Reuters detected the broader unauthorized activity on June 30.
Montana officials said much of the affected information appeared to already be publicly accessible, though some records also included driver’s license numbers and dates of birth.
The distinction matters because the presence of publicly available court records in the accessed files does not eliminate the risk created by restricted personal information contained alongside them.
In Ontario, Canada, the Court of Appeal for Ontario, Ontario Superior Court of Justice and Ontario Court of Justice jointly disclosed that C-Track is used to store and manage certain court documents and records.
Ontario officials said Thomson Reuters notified the province’s Ministry of the Attorney General on July 23, 2026 that information associated with Ontario courts had been accessed.
The three Ontario chief justices said the full scope remains under investigation and that it is still unclear exactly what information was accessed or how many individuals may have been affected.
They also warned that individuals who participated in court proceedings or were mentioned in court documents could potentially have personal information involved in the incident.
Ontario officials said there is currently no indication that systems processing financial transactions connected to court proceedings were affected, and Thomson Reuters reported no evidence of identity theft linked to the incident.
The Ontario courts also said C-Track remains operational and safe to use following additional security measures implemented by Thomson Reuters.
The delayed notification timeline is another important element of the breach.
Thomson Reuters detected unauthorized activity on June 30, yet at least some court systems were not informed that their information had been accessed until July 23, several weeks later.
That period appears to have been used to determine which stored files had been affected and which courts were connected to the compromised data.
The breach also highlights a broader third-party risk facing judicial systems.
Court agencies may maintain their own secure internal networks while relying on external vendors to host, back up or manage case-management data. A compromise of that vendor can expose judicial information even when the court’s own infrastructure has not been breached.
In this incident, Thomson Reuters explicitly stated that the affected courts’ networks and systems were not responsible for the compromise.
That distinction does not reduce the sensitivity of the exposed material.
Court records can contain information concerning criminal defendants, witnesses, victims, children, litigants, medical histories, addresses, identity documents, financial details and other highly sensitive information depending on the jurisdiction and type of proceeding.
The possible exposure of sealed or redacted material creates an added concern because those protections exist specifically to prevent certain information from becoming publicly available.
Thomson Reuters said it has implemented additional safeguards and security enhancements following the incident and that outside cybersecurity experts reviewed the company’s response.
The company has not publicly identified those experts.
Thomson Reuters has offered 12 months of complimentary credit monitoring and fraud-protection services to affected users in at least some jurisdictions, including Montana, while separate notification resources have been established for potentially affected individuals in the United States and Canada.
At this stage, several major questions remain unanswered, including who carried out the intrusion, how the attacker initially entered the C-Track environment, the total volume of files obtained, the full number of courts affected, the number of individuals whose data was exposed, and whether any stolen information has been sold, published or otherwise used.
No public attribution has been made to a ransomware group, nation-state actor or other threat organization.
The absence of reported fraud or identity theft does not establish that stolen information has been destroyed or will not be used later. Personal and sealed legal information can remain valuable for identity fraud, extortion, social engineering or targeted criminal activity long after an intrusion is discovered.
The continuing investigation will determine whether the scope expands beyond the jurisdictions already identified and whether more individuals require notification.
Montana Supreme Court, “Montana Supreme Court Discloses Discovery of Unauthorized Access to Court Data — C-Track Case Management System, Owned by Thomson Reuters, Incident Affected Multiple States,” dated September 2, 2026. The statement confirms unauthorized access to Montana C-Track and E-Filing backup data, the March-to-June 2026 access period, the presence of some personally identifiable information, and Thomson Reuters’ offer of 12 months of free credit monitoring and fraud protection for affected users.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



