Thomson Reuters C-Track Breach Exposes Court Data Across 12 US States
Thomson Reuters disclosed a significant data breach on Wednesday affecting its C-Track court case management platform, compromising court records and sensitive personal data across at least 12 U.S. states, the U.S. Virgin Islands, and Canada. The company revealed that an unauthorized party accessed C-Track files in March, though the intrusion was not discovered until June 30, when Thomson Reuters launched an investigation with external cybersecurity experts and law enforcement. In some cases—such as Montana—attackers reportedly maintained access to the system until June. Thomson Reuters has not disclosed the attack vector, the threat actor responsible, the total number of affected individuals, or the full scope of data exfiltration.
The exposed data may include highly sensitive personally identifiable information (PII) such as names, Social Security numbers, driver's license numbers, dates of birth, medical records, and health insurance information. Confidential, redacted, and sealed court records may also have been compromised, raising serious concerns about judicial privacy. Affected jurisdictions include appellate courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, South Carolina, Tennessee, Wyoming, Pennsylvania, and Ohio, along with 10 Ohio district courts of appeals, the Oregon Judicial Department, and courts in the U.S. Virgin Islands. The Canadian breach impacted Ontario's Ministry of the Attorney General, among other systems.
Notably, this represents a classic third-party supply chain attack, where a trusted vendor's platform became the vector for compromising multiple downstream government entities. Thomson Reuters emphasized that the breach occurred entirely within its own environment and did not stem from vulnerabilities in the affected courts' networks—meaning the courts themselves had no ability to prevent the intrusion. Court administrators in some jurisdictions, including Montana and Ontario, were not notified until July 23, nearly a month after the breach was discovered. The company has since deployed new security measures, reviewed and approved by unnamed external experts, though C-Track remained operational throughout the incident.
Individuals potentially affected by this breach should immediately take steps to protect their identities. Running an email breach checker can help determine whether personal information has appeared in known leaks, while using a password checker ensures that any reused credentials are updated. Additionally, affected parties should monitor their financial accounts, consider placing fraud alerts with credit bureaus, and verify their network privacy with a DNS leak test to ensure their connections remain secure in the wake of this incident.