Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
Thomson Reuters disclosed that an unauthorized party accessed C-Track court case management platform files between March 1 and June 29, 2026, affecting courts across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada A subset of exposed court records may contain highly sensitive personal data including Social Security numbers, driver's license numbers, dates of birth, medical information, and health insurance information Thomson Reuters is offering 12 months of credit monitoring throug
Analysis
TL;DR
- Thomson Reuters disclosed that an unauthorized party accessed C-Track court case management platform files between March 1 and June 29, 2026, affecting courts across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada
- A subset of exposed court records may contain highly sensitive personal data including Social Security numbers, driver's license numbers, dates of birth, medical information, and health insurance information
- Thomson Reuters is offering 12 months of credit monitoring through Experian (U.S.) and TransUnion (Canada) for affected individuals, with enrollment open until December 31, 2026
- Minnesota Judicial Branch confirmed its appellate court data was exposed despite not being listed in the original notice, and has terminated Thomson Reuters' access to its electronic environments
- There is currently no evidence of fraud or misuse of the compromised information, and Thomson Reuters maintains that C-Track operations remain uninterrupted and safe to use
Why It Matters
This breach highlights the critical supply-chain risks inherent in government agencies relying on third-party vendors for sensitive court case management systems, where a single vendor compromise can cascade across multiple jurisdictions. The exposure of sealed, redacted, and confidential judicial data—including SSNs and medical information—underscores the severe privacy and security implications for individuals whose most sensitive personal records were entrusted to a commercial platform. For AI and technology practitioners, this incident serves as a stark reminder that cloud-based legal tech infrastructure requires rigorous vendor security audits, transparent data retention policies, and clear contractual boundaries around backup data storage.
Technical Details
- The breach occurred on Thomson Reuters' C-Track platform, a court case management system operated by its West Publishing Corporation unit, with unauthorized access spanning from March 1 through June 29, 2026, and discovered on June 30, 2026
- The scope of compromised data varied by jurisdiction: some courts reported exposure of backup data stored on Thomson Reuters servers (Montana, Alabama), while Ohio reported unauthorized access directly on the production platform hosting filing system data for 10 appellate districts
- Affected data types include names, Social Security numbers, driver's license numbers, dates of birth, addresses, phone numbers, case numbers, charge and docket entry descriptions, medical information, and health insurance information; certain confidential, redacted, or sealed court information was also potentially impacted
- The incident affected 24 court bodies across Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, Wyoming, the U.S. Virgin Islands, and Ontario, Canada, with Minnesota confirming exposure despite not being in the original notice
- Thomson Reuters stated there has been no operational disruption to C-Track and considers the platform safe to continue using, though Ohio's Supreme Court noted it has not yet received comprehensive details of enhanced security measures deployed by TRCMS
Industry Insight
- Government agencies and court systems must conduct thorough vendor risk assessments that go beyond production environments to include backup data, cloud storage locations, and troubleshooting database copies—since some courts discovered unauthorized data retention they never requested or authorized
- Legal technology vendors should implement transparent data governance frameworks that clearly define what data is stored, where backups reside, and who has access, as the lack of clarity across jurisdictions has eroded trust and created confusion about the true scope of the breach
- The incident reinforces the importance of contractual clauses requiring vendors to notify clients promptly of security incidents and provide detailed breach disclosures, as conflicting narratives between Thomson Reuters and individual courts about whether access occurred on production or backup systems have complicated response efforts and damaged institutional confidence
Disclaimer: The above content is generated by AI and is for reference only.