Thomson Reuters court data breach (2026): what to do

Updated Corrections

September 16, 2026

We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.

What happened

Thomson Reuters disclosed a breach of C-Track, a cloud-hosted court case management platform owned by West Publishing Corporation, which does business as Thomson Reuters. The company said it discovered unauthorized activity on June 30, 2026 and determined that an unauthorized party had obtained certain C-Track files in March 2026. Montana's chief justice said access ran from March 1 to June 29, 2026. Courts were notified in late July, and affected courts announced the breach publicly on September 2, 2026.

According to Thomson Reuters' notice, the incident happened in its own environment and was not caused by the courts' networks or security, and C-Track stayed in operation. The affected files were court data Thomson Reuters held to provide technical support. Courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, Wyoming, and the U.S. Virgin Islands were named in the company's notice. Oregon's appellate courts and Minnesota's appellate courts also confirmed they were affected, as did Ontario's Court of Appeal, Superior Court of Justice, and Ontario Court of Justice.

Thomson Reuters has not said how the attacker got in, who was responsible, or how many people are affected. It said it has found no evidence of fraud or misuse and is offering affected people 12 months of Experian IdentityWorks credit monitoring.

Sources

What data was exposed

The following types of personal data were compromised:

  • Names
  • Addresses and phone numbers (per Montana's court system)
  • Case numbers and party names (per Montana's court system)
  • Social Security numbers (in some records)
  • Driver's license numbers (in some records)
  • Dates of birth (in some records)
  • Medical and health insurance information (in some records)
  • Confidential, redacted, or sealed court information (at some courts)

Breach details

Detail Value
Breach name Thomson Reuters C-Track
Date March 1 to June 29, 2026
Disclosed September 2, 2026
Accounts affected Not disclosed
Domain thomsonreuters.com

This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your personal data is involved, contact our support team.

We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by Thomson Reuters; it reflects a publicly reported security incident.

For whether your personal data was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you), not this page alone.

What to do now

Based on the data exposed in this breach, here are the steps you should take:

  • If you were a party to, or named in, an appellate case in one of the listed courts, place a free credit freeze with Equifax, Experian, and TransUnion. Some records included Social Security and driver's license numbers.
  • Be cautious of messages that cite a real case number, court name, or hearing date and ask you to confirm your identity or pay a fee. Contact the court clerk through the court's official website instead.
  • Review your credit reports and bank statements for new accounts you did not open.
  • If medical or insurance details may have appeared in your case files, check Explanation of Benefits statements for claims you don't recognize.
  • To enroll in credit monitoring or ask questions, use the Thomson Reuters notice at ctracknotification.com or the call center listed in your court's notice (Oregon listed 1-833-918-5294, engagement number B171847, Monday to Friday, 8am to 8pm Central).

Does the C-Track story mean my court case data is on people-search sites?

Neither that nor dump membership follows from this page. Thomson Reuters said an unauthorised party obtained certain C-Track support files holding court data, and whether your matter was included depends on notices from Thomson Reuters or your court. Court files can hold contact details and, in some records, Social Security or ID numbers, which is different from a people-search profile.

Frequently asked questions

Can Delist remove my data from C-Track, Thomson Reuters, or court systems?

No. Delist does not scrub a vendor’s court case management environment or sealed case archives. Open-web people-search removal is a separate thing.

How does this relate to whether my information is public?

People-search sites often already publish your name, address and phone from public sources. A court vendor incident adds phishing risk, because a message can cite a real case number, and identity-theft risk for the records that held ID numbers. It does not automatically create a new people-search listing.

What should notice recipients do first?

Use the enrolment contacts in your notice from Thomson Reuters or your court, freeze your credit if an SSN or licence number may apply, and treat any message citing a real case number and asking for codes or fees as possible phishing.

What to do after a breach

A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.

More breaches

Free personal data exposure scan

We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.