Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

6 hours ago 3

Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada.

West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names, Social Security numbers, driver's license numbers, dates of birth, medical information, and health insurance information, the company said.

The firm is offering potentially affected individuals 12 months of Experian IdentityWorks credit monitoring, with enrollment open until December 31, 2026, using a multi-use code published in the notice, and a hotline at 1-833-918-5294 that requires the engagement number B171847.

In Canada, Thomson Reuters Canada Limited is offering 12 months of TransUnion myTrueIdentity monitoring with a call center scheduled to open on September 4.

"Certain confidential, redacted or sealed information may have been impacted for certain affected courts," West Publishing said in its September 2 notice, adding that there is no evidence to date of fraud or misuse of the information.

Cybersecurity

The West Publishing notice and the Canadian notice from Thomson Reuters Canada Limited name the following court systems -

  • Alabama - Alabama Appellate Courts
  • Kentucky - Kentucky Appellate Courts
  • Montana - Montana Supreme Court
  • Nevada - Nevada Appellate Courts
  • New Hampshire - The New Hampshire Supreme Court
  • North Dakota - North Dakota Supreme Court
  • Ohio - First, Second, Third, Fourth, Fifth, Sixth, Seventh, Ninth, Eleventh, and Twelfth District Courts of Appeals
  • Pennsylvania - Commonwealth of Pennsylvania Environmental Hearing Board (former client), Court of Common Pleas of Washington County, Fifth Judicial District of Pennsylvania, and the Court of Common Pleas of Monroe County, which the notice lists by county name only
  • South Carolina - Supreme Court of South Carolina and the South Carolina Court of Appeals
  • Tennessee - Tennessee Appellate Court Clerk's Office
  • Wyoming - Wyoming Judicial Branch
  • U.S. Virgin Islands - Supreme and Superior Courts
  • Ontario - Court of Appeal for Ontario, Ontario Superior Court of Justice, and Ontario Court of Justice

The Hacker News reviewed the West Publishing notice on September 3, 2026; it lists 24 court bodies in 11 states and the U.S. Virgin Islands, with Minnesota absent from the list.

The Minnesota Judicial Branch said on September 2 that data from its appellate courts was exposed in the incident, that it has terminated Thomson Reuters' access to the courts' electronic environments, and that users of the appellate case management system must change their passwords. Minnesota Supreme Court Chief Justice Natalie Hudson said she is "deeply troubled that our court users' data has been compromised."

In Montana Supreme Court's release, the court said the material taken was backup data stored on Thomson Reuters servers, drawn from database copies that had been "supplied to TR for the purpose of troubleshooting the applications."

Those databases may hold case numbers, party names and addresses, phone numbers, the charge and docket entry descriptions, and, for some individuals charged with a crime, driver's license numbers and dates of birth, the release said.

Unauthorized access to that storage location ran from March 1 through June 29, 2026, per the court's account of the vendor's notice.

The Alabama Appellate Courts said West Publishing later told them that a copy of some Alabama appellate court data was kept in a backup file within the company's cloud environment, a backup the courts said they had neither requested nor known about.

"This incident occurred within our vendor's systems, not our own," Alabama Chief Justice Sarah Stewart said.

The Supreme Court of Ohio, however, said in its own statement that Thomson Reuters Court Management Solutions (TRCMS) informed it on August 31 that "the unauthorized access took place on the Court's production platform." That platform hosts the filing system data of the 10 Ohio appellate districts that use C-Track, with the Eighth and Tenth districts unaffected.

The Hacker News has reached out to Thomson Reuters for clarification on which environment was accessed and whether Minnesota courts are affected, and will update this story with any response.

"There has been no operational disruption to C-Track as a result of this incident," a Thomson Reuters spokesperson told Reuters, adding that the company considers the platform safe to keep using.

The Supreme Court of Ohio said it has yet to receive comprehensive details of the enhanced security measures TRCMS told it have been deployed.

Ontario's Court of Appeal, Superior Court of Justice, and Court of Justice said in the three chief justices' statement that Thomson Reuters detected the activity within one of its cloud environments. The chief justices said "it is still unclear what information may have been compromised," and that anyone involved in court proceedings or mentioned in court documents could have had personal information involved.

In Wyoming, the material taken was historical data from the Wyoming Supreme Court and district courts, primarily involving people who dealt with those courts between 2015 and 2025, the state's Judicial Branch said in its release.

The preliminary review indicates that "limited personal information, including names, addresses and dates of birth, was compromised," the branch added. Wyoming gives the hotline's hours as 7 a.m. to 7 p.m. Mountain Time.

Cybersecurity

The Virgin Islands courts said they received notice on July 27 and can so far confirm only that the accessed data "related to its 2018 system implementation project."

Trial court e-filing in Kentucky is untouched because the state does not use third-party vendors for it, Kentucky's court administrators said, adding that there is "no indication at this point that the unauthorized third party distributed the Kentucky data."

Montana and Minnesota each said that court documents were not part of the accessed data, although the vendor's notice states that sealed material may have been affected for certain courts.

The vendor notified the courts and Ontario's Ministry of the Attorney General between July 23 and July 27. Public disclosure followed on September 2, a date Montana said was chosen so that the vendor and the other states involved could issue simultaneous announcements.

As of September 3, no party had published a count of affected individuals, the method by which the files were obtained, or the identity of whoever was responsible.

North Dakota's statement said the incident involved only North Dakota Supreme Court data, with the state's district courts and its Odyssey system unaffected. It added that there is no evidence nCourt, the system used to process financial transactions, was impacted.

"There is an active criminal investigation into this incident," the North Dakota Court System said.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Read Entire Article