A cybersecurity incident involving a Thomson Reuters court-management platform has raised fresh concerns over the security of sensitive digital court records after an unauthorized party accessed files connected to court systems across the United States and Canada.
Thomson Reuters said its C-Track case management platform was affected by unauthorized activity that was detected on June 30, 2026. The company’s subsequent investigation determined that an unauthorized party had obtained certain C-Track files as early as March 2026.
The incident affects court systems in 11 U.S. states, the U.S. Virgin Islands and Canada, according to information released by Thomson Reuters and statements from affected courts.
Court records containing personal information may be involved
The potential exposure is particularly significant because C-Track is used to manage digital court records and documents.
Thomson Reuters said some court records were affected and that those records included names and personal information. However, authorities have stressed that the full scope of the potentially compromised information has not yet been established.
The affected U.S. jurisdictions identified in the company’s incident information are Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire and Wyoming, along with the U.S. Virgin Islands.
The situation also extends to Ontario, where the Court of Appeal for Ontario, Ontario Superior Court of Justice and Ontario Court of Justice use C-Track for aspects of digital case and document management.
Ontario’s three chief justices said Thomson Reuters detected unauthorized activity in one of its cloud environments on June 30. During its investigation, the company determined that data from the Ontario courts had also been accessed and notified the province’s Ministry of the Attorney General on July 23.
The exact data exposed remains unclear
This is one of the most important unanswered questions surrounding the incident.
Ontario’s courts said investigators are still determining the specific content and types of information involved, as well as how many individuals could potentially be affected.
That means the incident should not currently be characterized as a confirmed mass exposure of every court record stored on C-Track. Instead, officials have confirmed that a subset of files was accessed and that some affected records may contain personal information.
Authorities have also warned that people involved in court proceedings—or individuals merely mentioned in court documents—could potentially have information included in the accessed files.
Bloomberg Law reported that the affected material could include a subset of court records and that some files may contain personal identification information. It also reported that some confidential, redacted or sealed records may have been among the potentially accessed material.
Montana confirms its court data was among the affected information
The Montana Supreme Court provided additional details about the incident, saying Thomson Reuters informed the state’s Office of Court Administrator that unauthorized access involved court backup data files stored on Thomson Reuters servers.
According to Montana court officials, the unauthorized access occurred between March and June 2026. Thomson Reuters informed Montana officials on July 23 that the state’s C-Track and electronic-filing backup data had been involved.
Kentucky officials likewise confirmed that the state’s appellate court data was among information potentially affected by the incident. The Kentucky Lantern reported that state court officials were cooperating with Thomson Reuters as investigators worked to determine precisely which Kentucky data was involved.
No evidence of disruption to court operations
Despite the seriousness of the incident, Thomson Reuters said C-Track has remained operational.
The company said there was no operational disruption resulting from the incident and that its products and services remain operational and safe to use.
Ontario’s courts similarly said the incident has not affected their ability to operate or hear cases.
Ontario officials also said there is currently no indication that systems used to process financial transactions related to court proceedings were affected. They added that there is no evidence to date that the incident has resulted in identity theft.
Thomson Reuters brought in cybersecurity experts
Following the discovery, Thomson Reuters took steps to contain the unauthorized activity, secured the C-Track environment and brought in external cybersecurity specialists to investigate.
Law enforcement was also notified.
Ontario’s chief justices said the province’s Ministry of the Attorney General and court officials are working with Thomson Reuters and government cybersecurity specialists to assess the incident and determine its potential impact.
Thomson Reuters said independent cybersecurity experts assisted with the investigation and validated the remediation measures implemented.
Who carried out the attack?
For now, there is no confirmed answer.
Reuters reported that it could not independently establish who was responsible for the incident or determine the precise details of the information compromised. No attacker has been publicly identified in the available official statements.
That distinction is important: while the incident involved unauthorized access to data, publicly available information does not establish that a particular criminal group, nation-state or ransomware operation was behind it.
Why the breach matters
The incident highlights a growing cybersecurity challenge facing courts as more legal records move into cloud-based and digitally managed environments.
Court records can contain highly sensitive information involving litigants, witnesses, lawyers, businesses and other individuals. Depending on the case, documents can contain identifying information and other details that individuals may reasonably expect to remain protected.
Ontario’s courts said they are continuing to assess the potential implications while additional security measures are being implemented.
The incident also comes as cybersecurity threats against organizations handling sensitive legal and professional information continue to increase. Reuters recently reported several data breaches involving major law firms, underscoring the broader security pressures facing the legal sector.
What happens next?
Thomson Reuters and affected courts are continuing their investigations to determine exactly what information was accessed and how many people may be affected.
For people who may have information contained in affected Ontario court records, Thomson Reuters is establishing a dedicated information channel. Ontario’s courts said a Canadian toll-free call centre is scheduled to become active on September 4, 2026.
For now, officials are urging caution while investigators determine the full scope of the incident.
The biggest unanswered questions remain what information was accessed, how many individuals are affected, and who was responsible.
Until investigators complete that work, the incident’s ultimate impact remains unclear.
WWC ONE MEDIA MJE

Leave a Reply