Thomson Reuters has disclosed that an intruder pulled files from C-Track, the court case management platform sold by its West Publishing unit, in an intrusion that may have exposed Social Security numbers, medical information, and even sealed court records. The company says the unauthorized access happened in March 2026 and was discovered on June 30.
Courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada use the platform and are named in the disclosure, which went public on September 2. Affected systems include appellate courts in Alabama, Kentucky, Nevada, New Hampshire, North Dakota, and Tennessee, several Ohio district courts of appeals, courts in Pennsylvania and South Carolina, the Montana Supreme Court, Wyoming’s Judicial Branch, and three Ontario courts. Minnesota has separately confirmed its appellate court data was caught up in the incident, and Ohio’s Supreme Court says the breach hit its production filing platform rather than a backup.
West Publishing warns that records may combine names with Social Security numbers, driver’s license numbers, dates of birth, medical details, and health insurance data. The vendor also acknowledges that confidential, redacted, or sealed material may have been involved for some courts, a point several state courts dispute for their own data.
No count of affected individuals has been published, and Thomson Reuters says it has seen no evidence the data has been used for fraud. It is offering 12 months of free credit monitoring through Experian in the U.S. and TransUnion in Canada. North Dakota’s court system says there is an active criminal investigation, and Wyoming notes the exposed files mostly involve people who dealt with its courts between 2015 and 2025.
Thomson Reuters stresses that C-Track never went offline and that the breach occurred inside its own cloud environment, not on court networks.
