Independent reporting on American politics
STATE BEACON

Thomson Reuters breach exposed sealed court records and personal data in 12 U.S. states, the U.S. Virgin Islands and Canada

A cyber‑attack on Thomson Reuters’ C‑Track court‑case‑management platform let an unauthorized party view sealed filings and sensitive personal information from March to June 2024. The breach, discovered in June 2024 and disclosed publicly on 3 September 2026, affected courts in at least 12 U.S. states, the U.S. Virgin Islands and Canada.

By State Beacon·
Thomson Reuters C‑Track server rack in a data‑centre

Thomson Reuters disclosed that an unauthorized party accessed its C‑Track court‑case‑management platform from March through June 2024, viewing sealed court records and a range of personal data for individuals in at least 12 U.S. states, the U.S. Virgin Islands and Canada.

Scope of the intrusion

The breach involved sealed court information and sensitive personal data, including names, Social Security numbers, driver’s licence numbers, medical information, dates of birth and health‑insurance details. The Record reports that the company’s own statements and the Montana Supreme Court confirm the intrusion window of March‑June 2024.

Jurisdictions affected span appellate courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, South Carolina, Tennessee, Wyoming, several Pennsylvania courts, ten Ohio district courts of appeal, the Oregon judicial department, as well as the U.S. Virgin Islands Supreme and Superior Courts. The total count reaches at least twelve U.S. states.

Courts and jurisdictions reported as affected by the C‑Track breach
Jurisdiction Court level
AlabamaAppellate
KentuckyAppellate
MontanaSupreme Court
NevadaAppellate
New HampshireAppellate
North DakotaAppellate
South CarolinaAppellate
TennesseeAppellate
WyomingAppellate
PennsylvaniaMultiple appellate courts
Ohio10 district courts of appeal
OregonJudicial department
U.S. Virgin IslandsSupreme and Superior Courts
CanadaVarious provincial courts (unspecified)
Source: The Record, "Thomson Reuters cyberattack data"

Timeline of discovery and disclosure

The unauthorized activity was first detected by Thomson Reuters on 30 June 2024. The company did not make the breach public until 3 September 2026, more than two years after discovery. The delay is documented in the packet’s timeline, which lists the three key dates: March 2024 (initial unauthorized access), 30 June 2024 (discovery), and 3 September 2026 (public disclosure).

During the period of intrusion, the attacker was able to view files stored in the C‑Track environment but, according to the company, there is no evidence that the data has been used for fraud or other malicious purposes.

Company background and filing context

Thomson Reuters Corp. (ticker TRI) is a publicly traded information services firm headquartered in Toronto, Ontario, Canada. The company’s 6‑K filings on 5 August 2026 and 6 August 2026 provide the most recent corporate disclosures, confirming Steve Hasker as chief executive and a headcount of roughly 24,000 employees. The firm operates in the media industry and is listed on the Nasdaq exchange.

While the packet does not include financial metrics for the breach, the company’s own statements stress that the intrusion occurred within its own environment and was not caused by the networks, systems or data security of the affected courts. This distinction is important for investors assessing liability risk, as the breach does not appear to stem from a failure of the courts’ own IT controls.

Implications for courts and data‑privacy stakeholders

Courts that rely on third‑party case‑management platforms now face heightened scrutiny over data‑security contracts. The breach demonstrates that even sealed court records—traditionally considered highly confidential—can be exposed when a vendor’s internal system is compromised.

For individuals whose personal data were potentially exposed, the risk profile includes identity‑theft vectors such as Social Security numbers and health‑insurance details. Thomson Reuters has not quantified the number of people affected, and the packet notes that the figure remains unclear.

Regulators in the United States and Canada may seek to examine whether existing data‑protection statutes, such as the U.S. state‑level privacy laws and Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), adequately cover third‑party providers to the judiciary. The breach could spur legislative or enforcement actions, though the packet does not contain any confirmed regulatory response at this stage.

What remains unknown

  • The exact number of individuals whose personal data were exposed.
  • How the attacker initially gained access to the C‑Track platform.
  • The identity of the attacker or any affiliated group.
  • Whether any of the exposed data have been used in fraudulent activity.

Thomson Reuters has stated that there is no evidence of misuse, but the company has not provided a timeline for any further forensic investigation or remediation steps beyond the public disclosure.

Next steps for stakeholders

Courts using C‑Track or similar platforms are likely to request detailed security audits from Thomson Reuters and may consider diversifying vendor risk. Legal‑tech providers will need to demonstrate robust segmentation and monitoring to prevent prolonged unauthorized access.

Investors should monitor any forthcoming SEC filings for potential liability disclosures, as the breach could translate into litigation costs or regulatory fines. The company’s next earnings release may include an update on remediation expenses.

Finally, individuals potentially impacted should remain vigilant for signs of identity theft and consider enrolling in credit‑monitoring services, even though the breach’s impact on personal finances has not been quantified.