24
court organizations across the US and Canada with case records accessed
92 days
unauthorized access to C-Track files went undetected from March to June 30, 2026
11 states
US states with confirmed exposed court case records, plus US Virgin Islands and Ontario
Dec 31, 2026
enrollment deadline for Experian IdentityWorks credit monitoring via Thomson Reuters

SponsoredHorizon3.ai

Proactive Security for the AI Era

NodeZero continuously and autonomously pentests infrastructure, identity, cloud, and now web applications, chaining weaknesses across every domain the way real attackers do. Every finding ships with replayable proof showing exploitable business impact, not theoretical risk.

See NodeZero WebApp in action

An unauthorized party accessed Thomson Reuters C-Track court case management files for 92 days before detection, compromising Social Security numbers, medical information, and sealed court records across 24 court organizations in 11 US states, the US Virgin Islands, and Ontario, Canada. Thomson Reuters disclosed the breach on September 3, 2026, after detecting unauthorized activity on June 30.

C-Track is a digital court case management platform operated by West Publishing Corporation, a Thomson Reuters subsidiary. The system handles case docketing, scheduling, document management, and records access for appellate and trial courts across North America. Confirmed affected jurisdictions include Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, and Wyoming, along with courts in the US Virgin Islands and several Ontario appellate courts.

The attacker accessed files containing individuals' names, Social Security numbers, driver's license numbers, dates of birth, medical information, and health insurance information. For some courts, sealed records may also have been exposed, including juvenile criminal proceedings, family law cases involving minor children, expunged criminal records, and mental health commitment proceedings. Thomson Reuters has not disclosed the attacker's identity, the initial access vector, or the total number of individuals whose data was accessed.

Courts using C-Track must act immediately: verify whether your jurisdiction appears in Thomson Reuters' confirmed affected list, request access logs for the March through June 2026 window, and initiate breach notification to affected individuals under applicable state laws. Individuals who appeared in court cases in affected jurisdictions should enroll in Experian IdentityWorks credit monitoring before the December 31, 2026 deadline and place a credit freeze with all three bureaus.

How Did the Thomson Reuters C-Track Breach Happen?

Thomson Reuters has not publicly disclosed the technical access vector for the C-Track breach. The company confirmed that an unauthorized party obtained certain C-Track files in March 2026 and that the activity went undetected until June 30, 2026, when Thomson Reuters launched an investigation with outside cybersecurity experts and law enforcement.

C-Track is a web-based case management platform delivered as a hosted service to court clients. The system centralizes sensitive case data including party information, filing documents, case history, and in some jurisdictions, sealed or expunged records. As a hosted platform, courts using C-Track have no direct visibility into, and no independent control over, the security of Thomson Reuters' underlying infrastructure, application layer, or data storage.

The 92-day detection gap is a defining characteristic of this breach. Modern threat intelligence firms consistently find that well-resourced attackers operating in third-party environments go undetected for 24 to 48 days on average. Ninety-two days gives an attacker substantial time to exfiltrate structured case data, identify sealed records by type, enumerate individuals by Social Security number or case number, and establish persistent access for future operations.

The supply chain structure of the breach means affected courts bear notification and legal obligations without having been the entry point. Courts that outsourced case management to Thomson Reuters now face state-law breach notification deadlines, potential liability from affected individuals, and the reputational consequence of a breach they could not have independently detected or prevented.

An unauthorized party obtained certain C-Track files in March 2026. Thomson Reuters detected the activity on June 30, 2026, and immediately launched an investigation with outside cybersecurity experts and law enforcement.

Thomson Reuters via The Record from Recorded Future News, September 3, 2026

Which Courts and States Were Affected by the C-Track Breach?

The C-Track breach affected 24 court organizations across 11 US states, the US Virgin Islands, and Ontario, Canada. Thomson Reuters confirmed affected jurisdictions include appellate and trial courts in Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio (multiple appellate courts), New Hampshire, and Wyoming. Minnesota appellate courts and US Virgin Islands courts are also confirmed. Several Ontario appellate and superior courts are among the affected Canadian jurisdictions.

The affected courts are predominantly appellate-level institutions. Appellate courts handle case records on appeal from lower courts and typically maintain the most comprehensive case records, including full transcripts, evidence summaries, party information from all proceedings, and in some cases, sealed documents carried forward from lower court proceedings.

For legal sector security teams, the key classification is supply chain breach. None of the 24 affected organizations suffered a compromise of their own infrastructure. The Thomson Reuters C-Track platform, which they contracted to manage their case data, was the entry point. Courts that entrusted their most sensitive records to a single commercial vendor had no independent mechanism to detect the breach.

Verizon's 2026 Data Breach Investigations Report documented a 60% year-over-year increase in third-party breach involvement, with 48% of confirmed data breach incidents now involving a third-party component. The C-Track incident follows this trend and reinforces that vendor access to sensitive data requires equivalent security scrutiny to direct network access.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

What Data Was Exposed in the Thomson Reuters C-Track Breach?

The exposed data spans five categories of sensitive personal information: Social Security numbers, driver's license numbers, dates of birth, medical information, and health insurance information. This data was embedded in case records for individuals who appeared as parties, witnesses, or subjects in court cases at affected jurisdictions.

Sealed court records represent a specific layer of elevated harm. Courts seal records to protect sensitive case types, including juvenile criminal proceedings, victims of domestic violence and sexual assault, expunged criminal records, involuntary mental health commitments, and family law matters involving minor children. Individuals who had records sealed precisely to protect their privacy now face the possibility that protection has been breached. In some jurisdictions, the existence of a sealed record is itself confidential, meaning even confirming exposure creates a secondary disclosure problem.

Medical information in court records typically appears in workers' compensation cases, personal injury litigation, criminal sentencing where medical conditions are a mitigating or aggravating factor, and mental health commitment proceedings. Exposure of this information implicates HIPAA for health system parties, state health privacy laws, and the state breach notification statutes governing each affected jurisdiction.

The combination of SSN, DOB, and driver's license number creates a complete synthetic identity fraud package. Attackers with this data can open credit accounts, file fraudulent tax returns, make medical insurance claims, and conduct targeted social engineering against attorneys, judges, or corporate litigants whose case data now resides with a third party of unknown identity and intent.

Why Court Case Records Are a High-Value Target

Court case management data is among the most valuable structured personal data available to attackers for three reasons. First, it is comprehensive and verified. Parties to litigation are required to provide accurate identifying information under penalty of perjury. Court records contain confirmed SSNs, verified addresses, and real medical histories that have been validated through the judicial process. Attackers who acquire court data bypass the normal information-quality problem they face with purchased credential dumps.

Second, court data spans every sector. A single appellate court database contains records for individuals from every industry, income bracket, and sector. A breach of a court case management system reaches targets that would be inaccessible through any single private sector data breach.

Third, sealed records create unique leverage. An attacker with access to sealed criminal records, expunged convictions, or sealed family court proceedings possesses information that the judicial system explicitly determined should remain private. This creates conditions for targeted extortion, blackmail, or reputational attacks against individuals who believed their records were legally protected.

The legal sector has historically underinvested in third-party cybersecurity governance. Law firms and courts that handle sensitive client and case data frequently delegate infrastructure security to vendors without contractual security requirements, audit rights, or breach notification timelines. A third-party vendor risk questionnaire process that covers data classification, minimum encryption standards, incident notification requirements, and right-to-audit provisions is the foundational control that the C-Track incident makes visible.

Court records are a breach category where the harm compounds long after the initial incident. Sealed records expose not just personal information, but the judicial protections individuals relied on to keep it private.

Kiteworks Third-Party Vendor Breach Legal Liability Report, 2026

Indicators of Compromise for Court Case Management System Breaches

Thomson Reuters has not published specific network indicators for the C-Track breach. No attacker infrastructure, command-and-control IPs, domains, or malware hashes have been publicly confirmed as of September 4, 2026.

The following behavioral indicators are derived from known bulk data access and credential abuse patterns associated with this threat class. These are structural detection indicators, not confirmed attacker infrastructure. They are intended for detection engineering teams to identify similar unauthorized access against their own hosted case management or legal records platforms. Validate against your environment before deploying as production alert rules.

For organizations that use SonicWall SMA1000 appliances as VPN gateways connecting to court networks: those appliances were confirmed under active exploitation via CVE-2026-83548 and CVE-2026-83549 as of September 1, 2026 (CISA KEV deadline September 5). While there is no confirmed link between the SonicWall campaign and the C-Track breach, organizations with unpatched SMA1000 appliances providing network access to court systems should treat those systems as potentially compromised and investigate access logs immediately.

Subscribe to unlock Indicators of Compromise

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Sigma Detection Rules for Case Management System Compromise

No CVE-specific community Sigma rules exist for the C-Track breach since this is a vendor infrastructure incident rather than a disclosed software vulnerability. These two rules were generated by Decryption Digest from the threat's known access patterns: bulk unauthorized record harvesting via a web-based case management interface and anomalous after-hours credential use. Both carry status: experimental. Validate against your environment before production deployment.

Deploy these rules against web application access logs from any hosted legal, court, or case management platform. For the retrospective hunt, request log exports from Thomson Reuters or your case management vendor for the full March 1 to June 30, 2026 window and feed them into your SIEM.

Subscribe to unlock Sigma Detection Rules

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Subscribe to unlock Sigma Hunt Queries

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Subscribe to unlock WAF Detection Rules

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

How to Verify Your C-Track Exposure and Secure Legal Data

Courts and legal organizations using C-Track should take immediate steps to assess exposure and initiate breach notification. Individuals with court cases in affected jurisdictions should protect themselves against identity fraud now. A data breach response and notification guide covers mandatory breach notification obligations by state, including timelines that apply to some of the affected jurisdictions.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Why the Thomson Reuters C-Track Breach Matters for Your Organization

The C-Track breach illustrates a structural risk that applies to every organization that outsources sensitive data management to a commercial vendor: you carry the legal obligations and reputational consequences of a breach you cannot independently detect, prevent, or contain.

Court case management systems occupy a uniquely sensitive position. They hold verified, court-mandated personal data from every sector, including sealed records that courts determined required special legal protection. A 92-day dwell time means an attacker had sufficient access to perform systematic data exfiltration, index sealed records by type, and build structured profiles on every individual in the database.

For legal sector organizations, the C-Track breach is a forcing function for supply chain security governance. Every piece of case data delegated to a SaaS or hosted vendor is data your organization can no longer guarantee the security of independently. Vendor security reviews, contractual audit rights, 48-hour notification requirements, and data minimization policies are not optional when the data involved includes Social Security numbers, medical records, and sealed judicial proceedings.

For security teams across sectors, the December 31, 2026 enrollment deadline for credit monitoring is your operational clock. Courts responsible for notifying affected parties need to complete that outreach well before December 31, not arrive at that date still initiating it.

The bottom line

Thomson Reuters C-Track breach exposed Social Security numbers, medical records, and sealed court documents from 24 courts in 11 US states and Canada. The attacker had 92 days of undetected access before Thomson Reuters discovered the incident on June 30, 2026. Courts using C-Track must pull access logs, assess the breach window, and initiate state-law breach notifications now. Affected individuals should freeze credit at all three bureaus immediately and enroll in Experian IdentityWorks before December 31, 2026.

This analysis is generic. create a free account to score threats like this against your own stack.

Frequently asked questions

What is the Thomson Reuters C-Track data breach?

The Thomson Reuters C-Track breach is a 2026 unauthorized access incident in which an attacker obtained files from C-Track, a court case management platform operated by Thomson Reuters subsidiary West Publishing Corporation. The attacker accessed files between March and June 30, 2026, affecting 24 court organizations in 11 US states, the US Virgin Islands, and Ontario, Canada. The exposed data includes Social Security numbers, driver's license numbers, dates of birth, medical information, and health insurance information from court case records.

How did attackers access Thomson Reuters C-Track?

Thomson Reuters has not publicly disclosed the technical access vector for the C-Track breach. The company confirmed that an unauthorized party obtained certain C-Track files beginning in March 2026, and the intrusion was not detected until June 30, 2026. The breach was identified after Thomson Reuters engaged outside cybersecurity experts and law enforcement. No malware, specific vulnerability, or attacker attribution has been confirmed publicly as of September 4, 2026.

Which courts and states were affected by the C-Track breach?

Thomson Reuters confirmed 24 court organizations were affected across 11 US states and Canada. Confirmed affected states include Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, and Wyoming, plus the US Virgin Islands and several Ontario courts. Most affected courts are appellate-level jurisdictions that hold comprehensive case records including transcripts, evidence summaries, and sealed documents from lower court proceedings.

What personal information was exposed in the C-Track breach?

Exposed data includes Social Security numbers, driver's license numbers, dates of birth, medical information, and health insurance information embedded in case records. Sealed records were also potentially exposed for some courts, including juvenile criminal proceedings, domestic violence cases, expunged criminal records, and family law cases involving minor children. The combination of SSN, DOB, and driver's license number is sufficient for synthetic identity fraud, tax refund fraud, and targeted social engineering.

How do I know if my data was exposed in the C-Track breach?

Your data may have been exposed if you were a party, witness, or subject in any court case processed by one of the 24 affected court organizations. Thomson Reuters is notifying potentially affected individuals and offering Experian IdentityWorks enrollment. If you had court proceedings in any of the affected states or Ontario and have not received a notification, contact the relevant court clerk directly. Do not wait for a notification to place a credit freeze: acting proactively is the most protective step.

Is Thomson Reuters offering credit monitoring for the C-Track breach?

Yes. Thomson Reuters is offering 12 months of Experian IdentityWorks credit monitoring to potentially affected individuals. Enrollment is available through December 31, 2026. If you have not received enrollment instructions but believe your data was in an affected court's records, contact the court clerk for the affected jurisdiction or Thomson Reuters directly. Credit monitoring alone is insufficient: a credit freeze at all three bureaus (Equifax, Experian, TransUnion) provides stronger protection against new account fraud.

Why are court records a high-value target for attackers?

Court records are verified, comprehensive, and cross-sector. Parties to litigation provide accurate personal information under penalty of perjury, making court data more reliable than most purchased credential dumps. A single appellate court database contains SSNs, medical histories, and financial information from individuals across every industry and income level. Sealed records add leverage: attackers with access to expunged criminal records or sealed family court proceedings can use that information for extortion against individuals who believed those records were legally protected.

What should legal organizations do immediately after the C-Track breach?

Legal organizations and courts using C-Track should verify if their jurisdiction appears in the confirmed affected list, then contact Thomson Reuters to request access logs for March 1 to June 30, 2026. Review those logs for bulk access patterns and off-hours authentication. Initiate breach notification under your applicable state breach notification law immediately, since detection occurred on June 30 and some state timelines may be approaching or past. Audit all vendor contracts for case management platforms to add security requirements at next renewal.

Sources & references

  1. The Record from Recorded Future News: US and Canadian court data exposed in Thomson Reuters breach
  2. The Hacker News: Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
  3. Help Net Security: Thomson Reuters reveals breach that exposed U.S. and Canadian court records
  4. Verizon 2026 Data Breach Investigations Report: Third-Party Breach Trends

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Giveaway: InfoSec World 2026 All Access Pass ($3,895 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $3,895 InfoSec World 2026 pass.