C-Track Data Breach Affected Court Records in the U.S. and Ontario
An incident involving Thomson Reuters’ C-Track system may have exposed sensitive court-record data in 12 U.S. states, the U.S. Virgin Islands and Ontario.

The C-Track data breach, involving a court system owned by West Publishing Corporation, part of Thomson Reuters, affected court records in 12 U.S. states, the U.S. Virgin Islands and several courts in Ontario. On June 30, 2026, the provider discovered unauthorized activity in its environment. A subsequent investigation found that an unauthorized party had obtained certain C-Track files as early as March.
The scope of the incident is not yet publicly known. It has not been confirmed how many people are affected, which specific files were obtained from individual courts, or whether the data was later published or misused.
The C-Track data breach may have involved sensitive information
According to notices from C-Track and affected courts, the records may have included names, Social Security numbers, driver’s license numbers, dates of birth, medical information or health insurance information. At some courts, confidential, redacted or sealed information may also have been present in the affected materials.
The nature of court files makes the incident sensitive. Such documents can link identifying information with details about medical conditions, family circumstances or other personal matters. However, it has not been confirmed which sealed or otherwise sensitive documents were exposed.
The courts’ networks were not breached
Thomson Reuters and C-Track state that the incident did not result from a compromise of the affected courts’ networks. The unauthorized activity involved the C-Track provider’s environment. According to the company, service operations were not interrupted, and there is no evidence that financial transaction systems were affected.
The company also said it has no evidence so far that the obtained data was misused. This does not mean the exact impact has been determined: the forensic investigation is ongoing, and the extent of the data affected continues to be assessed.
The provider is offering credit monitoring
C-Track implemented additional security measures and engaged external experts and law enforcement authorities. It is offering potentially affected individuals 12 months of credit monitoring and identity theft protection.
The method of entry, the attacker’s identity and the volume of data obtained are unknown. It has also not been publicly confirmed whether the attacker obtained entire court files or only portions of documents.
What comes next
Further information should come through direct notices to people whom the provider determines may be affected. Clarifying the scope for individual jurisdictions will also be important, particularly regarding sealed documents and sensitive data categories.
The technical method of compromise, attribution of the attack and any evidence of further handling of the data will remain subjects of additional investigation. Possible actions by U.S. and Canadian courts or regulators against Thomson Reuters and West Publishing also remain open questions.
Sources
- C-Track Canada – The provider’s initial notice confirms the discovery of activity on June 30, the acquisition of files in March, the affected Ontario courts, the ongoing investigation and the absence of evidence of misuse.
- Ontario Courts – A joint statement from Ontario’s three chief justices confirms that Ontario court data was affected, that the scope is uncertain and that impact assessments are ongoing.
- South Carolina Judicial Branch – The official statement contains C-Track’s notice listing the affected U.S. courts, possible data categories, operational status and mitigations.
- The Record – Independently summarizes the incident’s scope, including at least 12 U.S. states, the U.S. Virgin Islands and Canada.
Verified and updated: 09/03/2026 15:21


