C-Track breach hits court systems in 11 U.S. states, USVI
The C-Track breach affected court systems in 11 U.S. states, the U.S. Virgin Islands and Canada, with some records containing personal information.
Lauren Collins ·

The C-Track breach affected court systems in 11 U.S. states, the U.S. Virgin Islands and Canada, Thomson Reuters said.
Thomson Reuters detected the cybersecurity incident on June 30 in a cloud environment tied to C-Track, its case management platform for courts. A later company review found that an unauthorized party obtained certain C-Track files in March, according to a website the company created for information about the incident.
The West Publishing unit of Thomson Reuters said the incident involved court systems in Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire and Wyoming, alongside the U.S. Virgin Islands. In Canada, three Ontario courts that use C-Track for digital court record management issued a joint statement on the matter.
March files surface
The company said its investigation found that some court records were affected and that those files included names and personal information. Thomson Reuters has not publicly identified the number of people whose data was involved, and the available notices do not describe the full range of information in the files.
C-Track is used by courts to manage case records, a category of software that can hold information on litigants, lawyers, witnesses and people mentioned in filings. That makes the scope of the files central to assessing the privacy risk, even where court operations continue as normal.
Ontario courts disclose exposure
The chief justices of the Court of Appeal for Ontario, the Ontario Superior Court of Justice and the Ontario Court of Justice said Thomson Reuters detected unauthorized activity in one of its cloud environments. They said the company worked with Ontario's Ministry of the Attorney General and the courts after the activity was found.
The Ontario statement said it was unclear what information may have been compromised. It said people involved in court proceedings, or named in court documents, could have had personal information relating to them involved in the incident.
Thomson Reuters said affected customers have been notified and that it took containment and security measures after detecting the activity. A company spokesperson said, "There has been no operational disruption to C-Track as a result of this incident," adding that its products and services remain operational and safe to use.
Security work continues
The company said independent cybersecurity experts assisted in the investigation and validated remediation measures it implemented. It also said law enforcement was notified, according to the Ontario courts' statement.
The absence of a reported service outage narrows the immediate operational issue for courts that depend on C-Track. The harder question is data exposure: which records were accessed, whether the files contained sensitive identifiers, and how many people need notice or assistance.
Thomson Reuters Canada will respond to inquiries and set up a call center that is scheduled to be active on September 4, the Ontario chief justices said. The company spokesperson confirmed Thomson Reuters is handling inquiries in both the U.S. and Canada and will have a contact center.
Court vendors face scrutiny
If the exposed files are limited in volume and sensitivity, the main effect for Thomson Reuters is likely to remain customer notification, remediation and support costs tied to affected jurisdictions. If the files contain broader personal information, court administrators may face longer reviews of vendor controls, retention policies and cloud-access procedures.
For the wider legal technology sector, the mechanism is procurement pressure rather than a single product outage. Courts using cloud-based record systems may demand clearer audit trails, tighter access controls and faster incident reporting from vendors that store or process judicial records.
The global macro effect from this incident is likely to be limited unless similar breaches begin to impair public-sector digital services at scale. If confidence in court technology weakens, the more direct consequence would be slower adoption of cloud case systems and higher compliance costs for companies selling them.