Thomson Reuters Says Unauthorized Access to Court Management System May Have Exposed Sensitive Personal Data
Thomson Reuters announced on Wednesday that an unauthorized individual accessed files from C-Track, the court case‑management platform marketed by its West Publishing Corporation division, in March 2026. The breach potentially exposed Social Security numbers and information from sealed court records across a range of jurisdictions.
The company said the intrusion was detected during an internal review and that the compromised data originated from courts that rely on C-Track to file pleadings, track case progress, and store confidential documents. The affected courts span eleven U.S. states, the U.S. Virgin Islands and the province of Ontario, Canada, indicating a broad geographic footprint for the platform.
C-Track is a widely used software solution that consolidates docket entries, evidentiary filings and participant details in a single digital repository. Because the system handles both public docket information and highly protected material—such as sealed filings, juvenile case data and personal identifiers—any unauthorized access raises serious privacy concerns for litigants, attorneys and court personnel.
While Thomson Reuters has not disclosed the exact number of records accessed, the company warned that Social Security numbers and other personally identifying information may have been among the files viewed or copied. Sealed records, which are ordinarily restricted by court order, could also be at risk, potentially compromising the privacy protections afforded to parties in sensitive cases.
In response, Thomson Reuters said it has engaged forensic experts to determine the scope of the intrusion, is cooperating with law‑enforcement agencies, and is notifying the affected courts so they can take appropriate steps. The firm also indicated that it will provide guidance to court administrators on mitigating any further exposure and will review its security protocols to prevent similar incidents.
The breach adds to a growing list of cyber‑security challenges facing the legal technology sector, where vendors store large volumes of confidential data on cloud‑based platforms. Industry analysts note that heightened reliance on digital case‑management tools, especially after the pandemic‑driven shift to remote operations, has made these systems attractive targets for attackers. Regulators may scrutinize the incident for compliance with data‑protection statutes, and courts could consider additional safeguards, such as multi‑factor authentication and more stringent encryption, to protect sensitive information moving forward.
Comments (0)
Be the first to comment.
Join the discussion