A third party data breach at Thomson Reuters has exposed sealed and confidential court records. The exposure hit more than two dozen courts across North America. It included Social Security numbers, medical details and case files that were never meant to go public. Thomson Reuters disclosed the incident on 2 September 2026. That was roughly four months after the unauthorised access began.

Table of Contents
The third party data breach at a glance
The breach hit C-Track, a court case management platform. West Publishing Corporation, a Thomson Reuters subsidiary, sells it to state and provincial court systems. Thomson Reuters says someone accessed files sitting in its own cloud environment. The courts’ own networks and servers were not touched, according to the company.
Unauthorised access ran from 1 March to 29 June 2026. Thomson Reuters found the intrusion on 30 June. It then spent roughly three weeks working out what had been taken. Courts were told between 23 and 27 July. Public disclosure did not follow until early September. That gap will draw scrutiny of its own.
At least 24 court bodies have confirmed they were affected. They span eleven US states: Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee and Wyoming. The US Virgin Islands and three courts in Ontario, Canada, are also affected. This is based on reporting from TechNadu and notices the affected courts published themselves.
Names, numbers and sealed files
The exposed data reportedly includes names, Social Security numbers and driver’s licence numbers. It also covers dates of birth, medical and health insurance information, case numbers, addresses and phone numbers. Some files were confidential, redacted or sealed under court order. That means a judge had already decided the public should not see them.
Thomson Reuters has not published a total figure for how many people are affected. Ontario’s court system put it plainly in its own notice. Anyone who has appeared in, or even been mentioned in, a court filing across the affected jurisdictions could have had personal information exposed.
Nobody quite agrees on what was taken
One detail stands out once you compare the individual court notices, rather than Thomson Reuters’ own summary. Montana’s judiciary described the accessed material as backup data. These were copies kept for troubleshooting, not the live system courts use every day. Ohio described its own exposure differently. It referred to the “production platform” itself.
That inconsistency matters. If a vendor and its customers cannot agree whether live data or a stale backup was exposed, nobody had a clear map of where sensitive information actually lived. So a third party data breach like this one is harder to contain than a single, well-mapped system would be. For a system holding sealed criminal and family court records, that gap is not small.
Why a third party data breach is everyone’s problem
Every organisation that hands sensitive data to a third-party platform is trusting that vendor’s internal environment as much as its own. Thomson Reuters says C-Track kept running throughout, with no operational disruption. It also says it has seen no evidence yet of the stolen data being misused. That is a reasonable thing to say two months after discovery. It is not a guarantee. This site has urged the same doubt toward vendor severity ratings on newly disclosed bugs. So a vendor’s own account of its own breach deserves that same doubt.
UK businesses often assume vendor risk stops once due diligence is done at contract signing. This case argues otherwise. A vendor’s backups, staging tools and internal cloud storage are all part of the attack surface. That is true even when the live system a client logs into looks perfectly secure. Under UK GDPR, a business stays on the hook for its supplier’s security failures. Signing a contract is not where that duty ends.
Thomson Reuters is offering 12 months of free credit monitoring through Experian IdentityWorks. Enrolment is open to affected individuals until 31 December 2026, alongside a dedicated support line. That is a standard response. It does not undo four months of unmonitored access to files that courts had specifically sealed from view. It also joins a run of large, recognisable names whose breaches this year, including the M&S data breach, exposed customer data at scale, and shows that brand size is no proxy for security.
What businesses should do next
Firms that rely on third-party platforms for case files, HR records or customer data should ask suppliers a direct question. Where do backups and troubleshooting copies of our data actually sit, and who can reach them? A penetration test scoped only to the production login page will miss exactly this kind of internal storage.
It is also worth checking your incident response contracts now, before you need them. Ask suppliers what their breach notification timeline actually commits them to. Then check it against your own rules. UK firms must generally tell the ICO within 72 hours of finding a notifiable breach. A four-month gap before telling anyone sits very badly next to that. Any business that has not tested how a supplier would handle a third party data breach is just taking its word for it.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.