← Blog

Thomson Reuters C-Track: Court Files Stolen

Share on X

Thomson Reuters and its West Publishing subsidiary said an unauthorized party obtained certain C-Track court case-management files in March 2026, an incident detected on June 30, 2026. The company’s C-Track notification site, court notices, and Reuters reporting say the affected material may contain names, Social Security numbers, driver’s-license numbers, dates of birth, medical information, and health-insurance information. Courts in 11 US states, the US Virgin Islands, and Canada were affected, although each person’s exposed fields depend on the files held by the relevant court.

What happened to the C-Track environment

C-Track is a court case-management platform supplied by West Publishing, part of Thomson Reuters. Courts use systems of this kind to manage filings, dockets, parties, documents, workflows, and case information. That role places the platform close to records that can range from routine public filings to confidential or sealed material.

According to the notification, an unauthorized party accessed and obtained certain files during March 2026. Thomson Reuters detected the cybersecurity incident on June 30 and began an investigation with outside specialists. The public account does not identify the attacker, disclose an initial-access technique, or say whether stolen credentials, a software vulnerability, phishing, or another route caused the compromise.

The company said the event did not disrupt court operations. It also reported no evidence that financial transaction systems were affected. Those are important limits, but they do not reduce the sensitivity of court documents containing identity, health, or legal information. Confidentiality can be lost even when systems remain available and cases continue moving normally.

Which courts were identified

The North Dakota Courts notice lists a wide group of C-Track customers. They include the Alabama appellate courts; Kentucky appellate courts; the Montana Supreme Court; Nevada appellate courts; the North Dakota Supreme Court; Oregon appellate courts; the South Carolina Supreme Court and Court of Appeals; the Tennessee Appellate Court Clerk’s office; the New Hampshire Supreme Court; the Wyoming Judicial Branch; and several Ohio appellate districts.

The list also includes Pennsylvania’s former Environmental Hearing Board implementation, the Monroe County and Washington County Courts of Common Pleas, and Pennsylvania’s Fifth Judicial District. The US Virgin Islands Supreme and Superior Courts were named as well. Ontario court officials separately acknowledged impact in Canada.

A court’s appearance on the list does not mean every case, filing, attorney, employee, or resident in that jurisdiction was exposed. The incident involved a subset of files. Determining who was affected requires matching the acquired files to individual records and understanding what each court placed in C-Track.

Why court data creates unusual risks

Court systems contain information gathered under legal requirements, not just information a consumer voluntarily gives a commercial service. A person can appear as a litigant, witness, juror, victim, family member, debtor, claimant, attorney, expert, or government employee. Some may have had little practical choice about submitting sensitive information.

Legal files can also explain why a data point exists. A Social Security number in isolation is dangerous; a Social Security number tied to a family-law dispute, medical claim, guardianship, benefits appeal, or sealed proceeding can be more damaging. Context helps criminals craft convincing messages and may expose deeply private circumstances.

Public access rules normally separate open judicial records from sealed, confidential, or redacted information. A system compromise can bypass that boundary. West Publishing’s notice acknowledged that some confidential or sealed information may have been affected, making the C-Track incident more than a republication of records already available online.

What information may have been involved

The identified fields include names and, depending on the record, Social Security numbers, driver’s-license numbers, medical information, dates of birth, and health-insurance information. Not every affected person had every category exposed. Notices use broad category language because court files vary by case type and jurisdiction.

Names and dates of birth support identity matching. Social Security and driver’s-license numbers can support new-account fraud, tax fraud, account recovery abuse, and forged applications. Health-insurance and medical information can enable benefits fraud or highly tailored phishing. Court context may reveal addresses, relationships, allegations, financial hardship, or procedural deadlines even when those details are not highlighted in a summary notice.

The company stated that it found no evidence of access to financial transaction systems. That statement should not be misread as a guarantee that no financial information appeared inside individual court documents. It means the transaction systems themselves were not shown to be affected; file-level content can differ.

Timeline of the Thomson Reuters C-Track incident

  • March 2026: The unauthorized party obtained certain files associated with the C-Track environment.
  • June 30, 2026: Thomson Reuters detected the cybersecurity incident and began investigating.
  • Following detection: The company worked with forensic specialists, notified law enforcement, reviewed acquired files, and coordinated with affected court customers.
  • September 2026: Reuters, court systems, and the dedicated notification site publicized broader details about the affected jurisdictions and available assistance.
  • Notification period: Eligible individuals were offered 12 months of credit monitoring and identity-protection services.

The gap between the March acquisition and June detection matters. It shows that data can leave a managed platform without immediately causing an outage. For courts and vendors, effective detection must include unusual file access and export behavior, not only malware alerts or service disruption.

What has not been disclosed

No public technical report has explained the attack chain. It remains unknown whether the attacker first compromised Thomson Reuters, West Publishing, a court account, an administrator, or connected infrastructure. The notices also do not give a single total number of people because the review spans many jurisdictions and different record sets.

The public information does not establish that all acquired files were published, sold, or used for fraud. Data acquisition is nevertheless a breach even without proof of downstream misuse. Criminals often hold information for months, combine it with other datasets, or use it selectively in ways that are difficult to attribute.

People should avoid unsupported claims about ransomware. The available notices describe unauthorized access and file acquisition but do not identify a ransomware group, extortion demand, or encryption event. Calling it ransomware without evidence would obscure what investigators have actually confirmed.

Who may receive a notification

Potential recipients include people whose sensitive personal information appeared in the affected subset of court records. That could include parties to cases, witnesses, dependents, employees, attorneys, or others mentioned in filings. Eligibility depends on the data review, applicable notification law, and whether the vendor or court has a usable address.

A person can be affected even if they never created a Thomson Reuters account. C-Track serves institutions, so data may have entered the system through a court filing or administrative workflow. Former residents and people involved in old proceedings should not assume they are outside the scope merely because they no longer live in the jurisdiction.

Recipients should confirm a letter through official channels before supplying information. The dedicated assistance line is 1-833-918-5294, and the enrollment code reported for the incident is B171847. Navigate independently to the official notification site rather than following links in an unexpected email or text.

Credit monitoring helps, but it is not complete protection

West Publishing is offering 12 months of credit monitoring. Monitoring can alert a person after certain changes appear on a credit file. It may help identify a new account, inquiry, or identity signal, but it does not prevent every application and does not watch medical records, court impersonation, tax filings, or all government-benefit systems.

A credit freeze is stronger for preventing many forms of new-credit fraud. It restricts access to a credit report until the consumer lifts or temporarily removes the freeze. Monitoring and a freeze can be used together; enrolling in one does not normally require leaving the other disabled.

Likely phishing themes after the C-Track breach

Attackers may impersonate court clerks, attorneys, Thomson Reuters, credit-monitoring providers, insurers, or law enforcement. Messages may claim that a filing must be corrected, a sealed record is about to become public, a fine is overdue, or compensation is available. Court deadlines and legal consequences create urgency that scammers can exploit.

A legitimate court will not demand payment through gift cards, cryptocurrency, or an unsolicited remote-access session. Do not trust caller ID, because telephone numbers can be spoofed. Contact the relevant court using a number published on its official government website.

Medical or insurance details can support another theme: a caller may claim that a court-ordered examination, settlement, or insurance reimbursement requires confirmation. Never disclose a Social Security number, bank credential, verification code, or full policy number solely because the caller knows details from a real case.

What affected people should do now

  1. Verify the notice independently. Visit ctracknotification.com directly or call 1-833-918-5294. Use enrollment code B171847 only through the verified process.
  2. Enroll in the offered protection. The 12-month monitoring service can provide useful alerts. Record the enrollment deadline and retain confirmation.
  3. Freeze your credit. Place freezes with the three nationwide US credit bureaus or use the applicable Canadian process. Store the credentials needed to lift each freeze safely.
  4. Review all three credit reports. Look for unfamiliar inquiries, addresses, employers, or accounts. Dispute inaccuracies with both the bureau and the organization reporting them.
  5. Protect tax and government accounts. Create official online accounts before a criminal does, use an IRS Identity Protection PIN if eligible, and watch for unexpected benefit or tax correspondence.
  6. Monitor medical and insurance records. Review explanations of benefits for providers, services, or prescriptions you do not recognize. Ask an insurer how to flag suspected identity misuse.
  7. Expect court-themed phishing. Verify deadlines and payment requests with the clerk through an official court website. Do not open an unexpected attachment that claims to contain a sealed filing.
  8. Secure email and mobile service. Email compromise can defeat account recovery. Use a unique password, phishing-resistant multifactor authentication, and a carrier PIN that blocks unauthorized transfers.
  9. Preserve legal correspondence. Keep the notification letter, envelope, enrollment record, suspicious messages, and evidence of expenses. Those materials may matter in a fraud dispute or later proceeding.

Steps courts and legal professionals should take

Affected courts should publish jurisdiction-specific explanations stating which case types and date ranges were reviewed. A generic vendor notice cannot answer whether sealed family cases, juvenile matters, medical exhibits, or particular appellate records were included. Clear local communication will reduce confusion and phishing opportunities.

Courts should also revisit filing rules that permit unnecessary full identifiers. Redaction tools, clerk review, protected-information forms, and separate confidential attachments reduce exposure when a case-management platform is compromised. Sensitive fields should not appear in ordinary documents merely because a legacy workflow accepts them.

Attorneys must determine whether client files or confidential submissions were involved and whether professional obligations require direct communication. They should warn clients about scams without speculating about unconfirmed facts. Firms should also review downloaded C-Track material in their own systems, because the same records may exist in multiple locations.

Lessons for justice-sector vendors

Case-management vendors operate as part of critical public infrastructure. Security architecture should treat every tenant and jurisdiction as a separate trust boundary. Administrative access needs phishing-resistant authentication, short-lived credentials, least privilege, and monitoring that can identify bulk collection across cases.

File repositories require controls beyond perimeter protection. Export limits, behavioral analytics, immutable logs, data-loss prevention, and alerts for unusual search patterns can shorten the time between initial access and containment. Encryption is useful, but it cannot protect files when an authorized application or stolen account can decrypt them normally.

Contract terms should establish notification responsibilities before an incident. Courts and vendors need tested procedures for evidence preservation, forensic access, public statements, individual review, and multilingual assistance. A three-month detection gap becomes harder to manage when customers first have to determine who owns each response task.

No operational disruption does not mean low impact

Cybersecurity reporting often emphasizes whether systems went offline. Here, court operations continued. That is good for access to justice, but it can make a confidentiality breach appear less urgent than a ransomware outage. For a person whose sealed medical or identity information was acquired, the absence of downtime offers little comfort.

Risk should be measured by what the files reveal, how long the information remains useful, and whether victims can replace it. A password can be changed quickly. A Social Security number, birth date, court history, or medical condition may remain sensitive for life.

Where to follow the incident

The canonical BreachHistory entry is the Thomson Reuters C-Track 2026 incident record. It consolidates the confirmed timeline, data categories, affected jurisdictions, and support details without implying that every listed court lost every type of record.

Authoritative sources include the Reuters report, the North Dakota Courts advisory, and the official West Publishing notification site.

The bottom line

The Thomson Reuters C-Track data breach is a multi-jurisdiction court-record incident, not a consumer-account breach. An unauthorized party obtained certain files in March 2026, and the company detected the activity on June 30. The files may contain durable identifiers, medical information, insurance information, and confidential or sealed court material.

There was no reported operational disruption and no evidence that financial transaction systems were hit. Those limits should be preserved, but they do not erase the privacy risk. People who receive notice should verify it, enroll in monitoring, freeze credit, watch medical and government accounts, and treat urgent court-themed communications with suspicion.

How courts can reduce exposure in future filings

The incident should prompt every affected jurisdiction to examine how sensitive identifiers enter its case-management platform. Courts can require filers to place Social Security numbers, driver’s-license numbers, medical exhibits, and insurance details on separate confidential forms instead of embedding them in ordinary pleadings. Automated redaction can help, but clerks and attorneys still need procedures for checking that confidential data is not repeated in document titles, scanned attachments, exhibits, or searchable metadata.

Legacy records deserve the same attention as new filings. A court may have improved its current redaction rules while older documents remain accessible to administrators, vendors, or broad service accounts. A structured review can identify case categories with unusually sensitive content, apply stricter access roles, and move sealed material into repositories that do not share bulk-search or export capabilities with public records.

Courts should also test incident-response communication before another breach occurs. A person whose sealed record is involved needs a direct explanation of the affected case, the exposed data categories, and the office that can answer legal or privacy questions. A generic monitoring notice cannot explain whether publication restrictions remain intact, whether a protective order was violated, or whether the court will replace an identifier contained in its records.

Finally, procurement teams should require measurable security commitments from case-management vendors. Contracts can specify log-retention periods, maximum notification timelines, tenant isolation, independent testing, privileged-access controls, and the evidence a vendor must provide after suspicious activity. Those requirements turn security from a broad assurance into controls that courts can inspect and enforce.