Thomson Reuters Cyberattack Exposed Court Records Across Multiple Jurisdictions

A cyber breach of Thomson Reuters’ C-Track system compromised court documents in 11 US states, Ontario, and the US Virgin Islands. Investigation continues with no operational impact reported.

Thomson Reuters Cyberattack Exposed Court Records Across Multiple Jurisdictions
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

What happened in the Thomson Reuters cyberattack?

In March 2026, an unauthorized party gained access to Thomson Reuters' C-Track court case-management system via a breach in its cloud environment. C-Track is a software tool used by courts to manage case files, hearings, filings, and schedules. The breach exposed sensitive court records and personal data from courts in 11 US states, the US Virgin Islands, and Ontario, Canada.

The intrusion was only detected months later in late June 2026, triggering an investigation and notifications to relevant authorities. As of now, no threat actor has claimed responsibility or demanded ransom, and no evidence exists that stolen data has been misused or leaked publicly.

Which jurisdictions and data were impacted?

Thomson Reuters detects cybersecurity incident, says unauthorized party  accessed files | Reuters
Thomson Reuters detects cybersecurity incident, says unauthorized party accessed files | Reuters

The affected US states include Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, and Wyoming. Courts in Ontario and the US Virgin Islands also had files exposed. The exact type and volume of data accessed are still being determined, but the breach involved court records containing personal information.

Importantly, there is no indication that systems managing court-related financial transactions were compromised. No operational disruptions to the C-Track platform have been reported, and it remains safe to use.

What are the implications and recommended actions for affected users?

Individuals whose court records may have been exposed should monitor for signs of identity theft or fraud, even though no such cases have been reported so far. Organizations using similar case management systems should review their cloud security monitoring and incident detection capabilities to minimize delayed breach discovery.

Courts and legal institutions relying on third-party platforms should demand transparency on incident investigations, remediation steps, and long-term security enhancements to protect sensitive judicial data.

What practical lessons can be drawn from this incident?

Thomson Reuters detects cybersecurity incident, says unauthorized party  accessed files | ZAWYA
Thomson Reuters detects cybersecurity incident, says unauthorized party accessed files | ZAWYA

This breach illustrates the challenges of securing cloud-hosted legal data and the risks introduced by delayed detection. Effective cybersecurity requires continuous monitoring, timely incident response, and regular security audits. Users of court management systems should remain vigilant for suspicious activity and work with their providers to ensure robust data protection measures are in place.

While no immediate harm has been reported, ongoing investigation is crucial to fully understand the breach's impact and prevent future incidents.

React to this story

Related Posts