Security2 distinct publishers3 min readPublished
Appellate courts in at least a dozen US states, the Virgin Islands and Ontario are notifying people about sealed filings taken from a platform they do not operate and cannot audit, by an intruder the vendor has still not described.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Thomson Reuters has offered no details on the intrusion's entry point, the intruder's identity, the amount of data taken, or the number of people affected [9]. The company's framing is that the activity sat inside its own environment and was not caused by court networks, systems or data security [10]. That framing is accurate, but it also describes the exposure, since no court on the list had a sensor in the path. C-Track never went down and remains fully operational, and the company says it added new controls that outside experts reviewed and approved, without naming those experts [14]. It says there is no evidence that systems processing financial transactions were touched [24].
The intervals are the firmest numbers here. First known file access to detection is at least three months [3]. Detection to the first court notifications is 23 days [1]. Detection to the public statement on 2 September is 64 days [2].
Counting affected courts depends on which notice you read. The US notice, as reported by The Record, names appellate courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, South Carolina, Tennessee and Wyoming, several Pennsylvania courts, 10 Ohio district courts of appeals, and the Virgin Islands Supreme and Superior courts [15]; Oregon's Judicial Department disclosed separately [16]. The West Publishing statement, as reported by Infosecurity Magazine, says 11 US states and lists North Dakota twice, which leaves ten distinct states, with neither Wyoming nor Oregon among them [17]. Anyone scoping from that second list is short by two states and a repeat [4]. On the Canadian side, the named exposure is C-Track Canada files tied to three Ontario courts: the Court of Appeal for Ontario, the Superior Court of Justice and the Ontario Court of Justice [18]. The investigation to establish what content was taken at each court, and how many individuals it covers, is still open [25].
The remedy on offer is 12 months of credit monitoring and identity theft protection [23]. That covers only one part of what was exposed, names, Social Security numbers, driver's license numbers, dates of birth, medical information and health insurance information [11], and leaves out the confidential, redacted or sealed material the company says may have been affected at some courts [12]. Infosecurity notes court filings are sought by nation-state groups for espionage, by actors trying to influence particular cases, and by criminals extorting named individuals [26]. Thomson Reuters says there is no evidence of fraud or misuse to date [13]; for a sealed filing already copied, that indicator would not move either way.
There is no attribution. So whether C-Track was an opportunistic hit on one vendor, or part of the same interest in case-management systems that pushed the US federal judiciary to announce stronger document protections in August 2025 after attacks on its filing system [27][28], is unresolved in what has been published.
Ranked by verification strength, evidence, and original report placement.
Thomson Reuters publicly disclosed a breach of a records platform affecting courts in at least 12 US states, the US Virgin Islands and Canada, in which sealed court information and sensitive personal data were exposed.
The breach involved C-Track, a court case management platform operated by a Thomson Reuters subsidiary; notification pages were published for affected users in the US and Canada.
West Publishing Corporation, a US-based provider of court management solutions owned by Thomson Reuters, disclosed the US-side impact in a separate statement.
Thomson Reuters said it discovered the unauthorized activity affecting C-Track information on 30 June, prompting an investigation with outside cybersecurity experts and law enforcement.
The investigation found that an unauthorized party had obtained certain C-Track files in March.
Montana's Supreme Court said the company told state officials the unauthorized access occurred from March through June, suggesting the attackers were present in the court records system until their discovery.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
C-Track breach reached at least twelve judiciaries, including Ontario1 distinct publisher
invest
Legal tech's two leaders are buying the field, and nobody has disclosed a price1 distinct publisher
security
A North Korean IT worker got hired by a federal agency. Vetting is a security control now.1 distinct publisher
build
OpenAI's top model at $4/$20 is a three-month answer to a permanent build decision1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One breached vendor, two trade outlets
Every hard datum in this story — 30 June, March, 23 July, the data categories, the 12 months of monitoring — originates in Thomson Reuters' or West Publishing's own notices. The genuinely independent voices, Ontario's chief justices and the Montana, Nevada and Oregon court authorities, confirm that they were told something, not what was taken; two of them say outright that they do not know. That the vendor's US list and its parent's notice disagree about which states are involved is the plainest evidence nobody outside the company has checked the scope.
Notification already running in two countries
The impact here is not projected; it is being processed. Appellate courts in at least a dozen states, ten Ohio appeals districts, the Virgin Islands Supreme and Superior Courts and three Ontario courts are in the notification chain, credit monitoring is on offer, and at least two judiciaries — Montana and Oregon — have gone public independently. What has not materialised is the denominator: the count of people behind those dockets is still open at every court.
Drier than the facts deserve
Neither outlet reaches for a superlative, and The Record explicitly marks what it cannot confirm. Set against three months of undetected access to sealed and redacted appellate filings across two countries, the writing sits slightly under its subject: the dwell time appears as a date rather than a finding, and Montana's 'most of it was already public' is allowed to soften a set that also included driver's licence numbers and birth dates. The one inflated note belongs to the company — unnamed experts approving unspecified new measures — and both outlets hold it at arm's length rather than adopting it.
The breached party owns the forensics
The organisation with the most to lose is the only one holding the evidence, and its framing does two favours for itself at once: fault is pushed away from court networks, and the absence of observed fraud leads — a claim that cannot be falsified this early in a data theft. The courts have the mirror-image interest. Montana's suggestion that most of the material was already public and Nevada's warning not to extrapolate both work to narrow their own institutions' exposure, and every one of those characterisations reaches readers secondhand.
Firm on scope, soft on cause
What happened, to which courts, and when it was found are solid enough to act on — two independent outlets agree and multiple judiciaries have confirmed on the record. Beyond that, confidence drops sharply: the intrusion's start date rests on a single account of what Montana was told, the number of affected states depends on which notice you read, and the cause and victim count are open by the company's own admission.