Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Thomson Reuters publicly disclosed a data breach of its C-Track platform — a multi-tenant SaaS system for judicial case management — on September 2, 2026. Unauthorized third-party access began in March 2026 and was discovered on June 30. The breach affects at least 12 U.S. states, the U.S. Virgin Islands, and three Ontario courts, exposing personally identifiable information and potentially compromising sealed or confidential records. The attack vector has not been disclosed.
- Unauthorized access to C-Track files began in March 2026 and continued until discovery on June 30, 2026; Thomson Reuters notified Montana and Ontario on July 23, with public disclosure on September 2–3.
- Affected U.S. jurisdictions include Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, South Carolina, Tennessee, Wyoming, Pennsylvania, Ohio (10 district courts of appeals), and the U.S. Virgin Islands; in Canada, the Court of Appeal for Ontario, Ontario Superior Court of Justice, and Ontario Court of Justice.
- Potentially exposed data includes names, Social Security numbers, driver's license numbers, dates of birth, medical information, and health insurance information; confidential, redacted, or sealed information may have been compromised for some courts.
- The incident originated in a Thomson Reuters cloud environment, not in the networks or systems of the affected courts; C-Track remained operational without service interruption.
Timeline: March to September, 60 Days of Public Silence
The timeline is established by consistent official statements. According to Ontario's three Chief Justices — George R. Strathy, Michael J. Tulloch, Sharon L. Nicklas, and Lise Maisonneuve — "On June 30, 2026, Thomson Reuters detected unauthorized activity within one of its cloud environments." The official U.S. notification site (ctracknotification.com) states that "in March 2026, an unauthorized party obtained certain C-Track files."
More than 60 days elapsed between discovery and public disclosure. Notification to Montana and Ontario's Ministry of the Attorney General occurred on July 23, 2026. Public disclosure, with the launch of dedicated sites ctracknotification.com and ctracknotification.ca, followed on September 2–3, 2026. This interval allowed inter-jurisdictional coordination but also delayed notification to potentially affected individuals.
The official Ontario statement describes the corporate response: containment of the activity, engagement of external cybersecurity experts, notification of law enforcement, and securing of the C-Track environment. No details emerge on the specific containment techniques or the identities of the experts or agencies involved.
Geographic Scope: A Single Vendor as the Access Point for 14 Jurisdictions
The C-Track platform is managed by West Publishing Corporation, a Thomson Reuters unit. The multi-tenant model enabled horizontal access to files from multiple client organizations via a single vendor environment. This architecture lies at the heart of the issue: the courts' own networks were not compromised, but they were exposed through third-party infrastructure.
The ctracknotification.com site lists affected U.S. courts: the Supreme Court of Alabama, Kentucky Court of Justice, Montana Supreme Court, Supreme Court of Nevada, New Hampshire Judicial Branch, North Dakota Supreme Court, South Carolina Judicial Department, Tennessee Administrative Office of the Courts, Wyoming Judicial Branch, Supreme Court of Pennsylvania (multiple courts), Ohio (10 district courts of appeals), and the U.S. Virgin Islands. The Record adds Oregon appellate courts, bringing the total to at least 12 states.
In Canada, the joint statement by Ontario's Chief Justices confirms three courts: the Court of Appeal for Ontario, Ontario Superior Court of Justice, and Ontario Court of Justice. The Canadian site ctracknotification.ca mirrors this list with credit monitoring services provided by TransUnion (myTrueIdentity) rather than Experian.
Data Types: From PII to Potentially Sealed Information
The official U.S. notification explicitly lists: names, Social Security numbers, driver's license numbers, medical information, dates of birth, and health insurance information. The Record, citing Montana officials, reports that "most of the affected information appeared to already be publicly available, although some driver's license numbers and dates of birth were also involved." This distinction between public and sensitive data is relevant for impact assessment but is not quantified for other jurisdictions.
The most sensitive issue concerns legally protected information. The C-Track U.S. notification states that "certain confidential, redacted or sealed information may have been impacted for certain affected courts." Ontario's three Chief Justices use similar language: "Because there remains uncertainty about the exact content of the files that may have been accessed, it is still unclear what information may have been compromised." This uncertainty, stated explicitly by the source, constitutes a structural limit of the dossier: it is not determined whether sealed files were actually accessible or only potentially involved.
The Federal Precedent and a Pattern of Systematic Targeting
Infosecurity Magazine contextualizes the incident with a precedent: an attack on U.S. federal court systems in August 2025. This chronological placement suggests a pattern of systematic targeting of judicial infrastructure, but the dossier contains no attribution or technical-infrastructure link between the two events. No overlapping indicators of compromise connect the C-Track actor to the August 2025 incident.
The C-Track breach structure mirrors a classic supply-chain cloud compromise: the vendor manages sovereign data for multiple jurisdictions, becoming a single point of failure. The absence of details on the attack vector — whether a software vulnerability, compromised credentials, or another mechanism — prevents assessment of whether the compromise was predictable or mitigable with specific controls.
"We are advised that Thomson Reuters responded by taking steps to contain the activity, engaging external cybersecurity experts to advise and investigate, notifying law enforcement, and securing the C-Track environment" — Ontario's three Chief Justices, Public Statement, September 2, 2026
Why It Matters
The dossier does not specify the attack vector, the exact volume of data exfiltrated, or the precise number of affected individuals. The source does not document whether access was continuous from March to June or limited to specific intervals. It does not emerge which file types — operational databases, backups, or individual documents — were accessible. Rankiteo mentions "backup files" for Montana, but this detail is not confirmed globally by official sources.
The attacker's identity and motive remain undetermined. No evidence of fraud or data misuse exists to date, according to official U.S. and Canadian notifications. However, the exposure of sealed information — if confirmed — raises questions of procedural integrity and strategic security for ongoing cases.
The C-Track service structure, with its centralized multi-tenant architecture, makes Thomson Reuters a critical node for the digital sovereignty of the justice system. The source does not specify whether the platform implements rigorous tenant segregation or whether the incident exploited limits of such segregation. The Ontario call center has been active since September 4, 2026; the enrollment deadline for Experian credit monitoring is set for December 31, 2026.
Frequently Asked Questions
Did the incident compromise the courts' internal systems?
No. Official U.S. and Canadian notifications explicitly state that "the incident was not caused by the courts' networks, systems or data security." The compromise occurred in Thomson Reuters' cloud environment.
Were sealed documents definitely exposed?
Official sources use cautionary language: "may have been impacted," "uncertainty about the exact content." It is not determined whether sealed information was actually accessed or only potentially involved.
What is Thomson Reuters offering affected individuals?
12 months of free credit monitoring: Experian IdentityWorks in the U.S., myTrueIdentity via TransUnion in Canada. The Ontario call center has been active since September 4, 2026.
The silence on the attack vector, in infrastructure managing judicial data for 14 jurisdictions, is not a journalistic gap but a corporate disclosure choice. When a cloud vendor becomes the sole custodian of sovereign data, the lack of transparency on the compromise mechanism turns the supply chain into a black box whose resilience client jurisdictions cannot assess. The 2025 federal precedent and C-Track's structure suggest this pattern is not episodic: the centralization of digital justice in a few private operators has become a systemic attack surface, and the relevant metric is no longer whether it will be hit, but when it will be disclosed.
Sources
- https://therecord.media/thomson-reuters-cyberattack-data
- https://www.infosecurity-magazine.com/news/us-canada-court-breach-thomson/
- http://www.econotimes.com/Thomson-Reuters-C-Track-Cyberattack-Hits-Courts-Across-US-and-Canada-1751155
- https://blog.rankiteo.com/statho1788405811-thomson-reuters-montana-supreme-court-breach-september-2026/
- https://www.straitstimes.com/world/united-states/thomson-reuters-detects-cyber-security-incident-says-unauthorised-party-accessed-files
- https://www.ontariocourts.ca/en/public-statement-cybersecurity.htm
- https://www.ctracknotification.com/
- https://www.ctracknotification.ca/
Information is based on cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.