HomeData BreachesThomson Reuters Court Software Breach Exposes Social Security Numbers and Sealed Records...

Thomson Reuters Court Software Breach Exposes Social Security Numbers and Sealed Records Across 11 US States

Thomson Reuters has disclosed that hackers had access to a court case management system used by dozens of courts across North America for nearly four months before the intrusion was discovered. The affected product, C-Track, is sold by West Publishing Corporation, a Thomson Reuters unit, and is used by courts to manage case files, dockets, and related records.

According to Thomson Reuters’ breach notification, reported by The Hacker News, the unauthorized access began on March 1, 2026 and continued until June 29, 2026, when the company detected it. The company said it notified affected courts between July 23 and July 27, but the breach was not disclosed publicly until September 2, 2026, meaning more than two months passed between notification to the courts and public disclosure.

The breach touched 24 court bodies spread across 11 US states, plus the US Virgin Islands and three court systems in Ontario, Canada. The affected US states include Alabama, Kentucky, Minnesota, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, and Wyoming.

The data exposed varies by court but can include full names, Social Security numbers, driver’s license numbers, dates of birth, medical information, and health insurance details. Court-specific data such as case numbers, party names and addresses, phone numbers, and descriptions of charges and docket entries was also affected. Thomson Reuters said in its notification that “certain confidential, redacted or sealed information may have been impacted for certain affected courts,” which raises the possibility that records meant to be shielded from public view, such as juvenile cases or matters under a protective order, were among the data an attacker could have accessed.

Thomson Reuters has not published a specific figure for how many individuals were affected. The company said it has found “no evidence to date of fraud or misuse of the information” and that C-Track itself experienced no operational disruption during or after the incident.

Court records systems are an attractive target for attackers because they concentrate sensitive personal and legal information from many different people in one place, often including data that individuals cannot easily change, like Social Security numbers, alongside details from sealed or sensitive proceedings. When a single vendor serves many courts, as Thomson Reuters does with C-Track, a single breach can expose records that were never meant to be linked together in one dataset.

Anyone who has had a case in one of the affected courts between March and June 2026, or whose information may have appeared in a case file during that window, should watch for a formal notification letter and consider placing a fraud alert or credit freeze given the exposure of Social Security numbers.

Source: The Hacker News, Swati Khandelwal

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular