Thomson Reuters Discloses C-Track Court-System Data Breach

Files containing personal information were taken from a cloud environment serving courts in 11 US states, one territory and Canada.

By Sophie van Dijk • • Fintech

A dark glass archive with illuminated red fractures and floating file-like slabs, symbolising a court-system data breach.

Thomson Reuters has disclosed a cybersecurity incident affecting C-Track, its court case-management platform, after an unauthorised party obtained files from a cloud environment used by court customers. The company said the affected deployments span 11 US states, the US Virgin Islands and Canada and that some files contained names and other personal information.

The timeline is important. Thomson Reuters detected the incident on June 30 and determined during its investigation that files had been obtained in March. The public disclosure is new, but the intrusion was not recent. The company has not identified the attacker, described the volume of records involved or provided a complete list of compromised data fields.

C-Track remained operational, and Thomson Reuters said there was no disruption to court activity. It also said the incident was contained, outside cybersecurity specialists were engaged and law enforcement was notified. Those statements narrow the operational risk but do not resolve the privacy consequences for people whose information appeared in the files.

Court technology holds unusually sensitive and heterogeneous data. Depending on the jurisdiction and case type, records can include parties, lawyers, witnesses, schedules, addresses and documents that are public, restricted or sealed. A breach can therefore expose information with very different legal protections. The company said some affected material was court record information, but it has not publicly mapped the exposure by court or document category.

The incident illustrates the concentration risk created when many public institutions use a common cloud service. Central platforms can improve uptime, search and workflow consistency. They also create a shared attack surface. A compromise of one service environment can affect multiple jurisdictions even when local court networks remain untouched.

For courts, the next task is notification and assurance. Administrators need to know which files were accessed, whether sealed or confidential material was involved, and whether credentials or technical information could enable follow-on attacks. They must also coordinate with Thomson Reuters on notices to individuals and any legally required reports. The vendor planned to open a contact centre on September 4.

For individuals, the practical risk depends on the data. Names alone may create limited exposure, while combinations of identifiers, contact information and case context can support phishing, impersonation or harassment. Until notices specify the compromised fields, broad claims about identity theft would be premature.

The company’s response will be judged on more than restoration because service availability was not the central failure. Investigators will examine access controls, logging, data segmentation, the delay between the March access and June detection, and the time required to notify affected institutions. Public-sector customers may also review contractual security standards and incident-reporting obligations.

Why it matters

Digital courts depend on trust that sensitive information can be processed across jurisdictions without creating a single point of systemic vulnerability. The C-Track incident shows that operational continuity and data confidentiality are separate measures of resilience. A system can remain online while personal information leaves the environment.

The event also expands the stakeholder group beyond one company’s customers. Courts provide essential public services, and people often cannot choose whether their information enters a case-management system. That makes clear disclosure, narrow data retention and strong vendor oversight particularly important.

Several critical facts remain unconfirmed: the attacker’s identity and motive, the number of people affected, the precise data categories and whether any sealed records were taken. Thomson Reuters says the environment is secure and C-Track remains safe to use. The next disclosures should establish whether that assessment is supported by forensic scope and whether affected people receive actionable information.

That evidence will determine whether this remains a contained vendor incident or becomes a wider public-sector accountability problem.

Sources