ThreatPaper
Data BreachHigh

Thomson Reuters C-Track Breach: Sealed Court Records in a Vendor's Backup Nobody Asked For

By pico picu · 12 Sept 2026 · 15 min read

Threat Actor: Unknown — unattributed; no group has claimed it · Target: West Publishing Corporation (Thomson Reuters) C-Track cloud environment; appellate and trial courts in Alabama, Kentucky, Minnesota, Montana, Nevada, New Hampshire, North Dakota, Ohio, Oregon, Pennsylvania, South Carolina, Tennessee, Wyoming, the US Virgin Islands and Ontario; litigants, witnesses and defendants in their records

Source: www.ctracknotification.com


Executive Summary

Between 1 March and 29 June 2026 an unauthorised party had access to a cloud environment operated by West Publishing Corporation, the Thomson Reuters subsidiary that sells C-Track, a case-management platform used by appellate and trial courts across North America. West Publishing discovered the activity on 30 June, told the affected courts between 23 and 27 July, and published a notice on 2 September. The notice lists 24 court bodies in eleven US states and the US Virgin Islands, plus the Court of Appeal for Ontario, the Ontario Superior Court of Justice and the Ontario Court of Justice. It says the files "could potentially contain" names with Social Security numbers, driver's licence numbers, medical information, dates of birth and health insurance information, and that "certain confidential, redacted or sealed information may have been impacted for certain affected courts."

The courts' own statements describe something the vendor's notice does not. Alabama's appellate courts say West Publishing later told them "a copy of some Alabama appellate court data was maintained in a backup file within the company's cloud environment," and that the courts "did not request West Publishing to store a backup copy of Alabama court data in its systems and were not aware that the company had such data." Wyoming says the breach "involves historical data from retired case management systems," covering people who came into contact with its courts between 2015 and 2025, shared with the vendor "so the company can provide technical support." Thomson Reuters' own list includes the Commonwealth of Pennsylvania Environmental Hearing Board with the annotation "(former client)." New Hampshire's exposed records reportedly span 2002 to 2015. What was taken was not, or not only, the live case system; it was the vendor's own retained copies of court data, some of it a decade old, some of it belonging to organisations that no longer used the product.

Thomson Reuters has not said how the intruder got in. The only description of the mechanism in the public record is Wyoming's, relaying what the vendor told it: "Bad actors accessed West Publishing Corporation's systems through a vulnerability in its infrastructure." No CVE, no vendor advisory and no forensic report has been published. No group has claimed the data and none has been reported for sale. The vendor's list is also incomplete: the Minnesota Judicial Branch and the Oregon Judicial Department each announced on 2 September that their appellate courts were affected, and neither appears on the notice.

The exposure that matters most is the one the vendor mentions in a single sentence. Courts seal records to protect people: victims of domestic violence whose addresses must not reach their abusers, informants, juveniles, defendants whose charges were dismissed. A sealed record is sealed on the court's system. It was, on the evidence of Alabama and Wyoming, also sitting in a support or backup copy on the vendor's cloud that the court did not know about, under the vendor's security rather than the court's, for a period the court did not set. Sixty-four days elapsed between discovery and public notice; the people in those records have been offered twelve months of credit monitoring.

Verification of Claims

  1. Claim: Unauthorised access ran from 1 March to 29 June 2026 and was discovered on 30 June. → Verified → West Publishing notice: discovered "On June 30, 2026"; files obtained "in March 2026." The full window is stated by the Alabama Appellate Courts, relaying the vendor. The notice itself gives only the start month.

  2. Claim: Courts in eleven states, the Virgin Islands and Ontario were affected. → Verified, and incomplete → The US and Canadian notices name the jurisdictions. Minnesota (Chief Justice Natalie Hudson, 2 September) and Oregon (Oregon Judicial Department) separately announced their appellate courts were affected; neither is on the vendor's list. Thirteen states is the supportable count.

  3. Claim: Sealed and confidential court records were exposed. → Verified as the vendor's own statement → Both notices: "Certain confidential, redacted or sealed information may have been impacted for certain affected courts." Which courts, and how many records, has not been stated.

  4. Claim: The data was in a backup the courts did not know about. → Verified for Alabama; consistent for Wyoming and Pennsylvania → Alabama Appellate Courts statement quoted above. Wyoming: "historical data from retired case management systems," shared for "technical support." Thomson Reuters' own list marks Pennsylvania's Environmental Hearing Board a "former client."

  5. Claim: The intruder exploited a vulnerability in West Publishing's infrastructure. → Weak evidence → Wyoming Judicial Branch FAQ, 4 September, relaying the vendor. Thomson Reuters has published no mechanism, CVE or advisory. No other court has repeated it.

  6. Claim: The breach occurred on the courts' production platform. → Contested → The Hacker News reports Thomson Reuters told Ohio courts "the unauthorized access took place on the Court's production platform," while Alabama was told the data was in a backup file. Both may be true for different courts; the vendor has not reconciled them.

  7. Claim: The incident was not caused by the courts' systems. → Verified as stated by all parties → Vendor notices and every court statement agree. Alabama Chief Justice Sarah Stewart: "This incident occurred within our vendor's systems, not our own."

  8. Claim: No fraud or misuse has resulted. → Unverified → The notice says the vendor "has no evidence" of misuse. Absence of evidence over ten weeks, for data that has not surfaced for sale, is not evidence of absence.

  9. Claim: The number of affected individuals is unknown. → Verified → No figure in either notice. Thomson Reuters told Canadian media it "could not provide an estimate." Wyoming and Alabama say they are still determining it.

Timeline

Date Actor Event Source
2002–2015 New Hampshire Supreme Court Period covered by exposed New Hampshire records. MobileSyrup, citing NH
2015–2025 Wyoming courts Period covered by exposed Wyoming records, from "retired case management systems." Wyoming Judicial Branch FAQ
1 March 2026 Unknown actor Unauthorised access to the C-Track cloud environment begins. Alabama Appellate Courts
29 June 2026 Unknown actor Access ends. Alabama Appellate Courts
30 June 2026 West Publishing Discovers "unauthorized activity"; engages third-party experts and law enforcement. West Publishing notice
23 July 2026 West Publishing Notifies Alabama Appellate Courts. Alabama Appellate Courts
Late July 2026 West Publishing Notifies Wyoming Judicial Branch. Wyoming FAQ
23–27 July 2026 West Publishing Notifies affected courts and Ontario's Ministry of the Attorney General. The Hacker News
August 2026 Wyoming Judicial Branch Reviews impacted data; determines "limited personal information" involved. Wyoming FAQ
After 23 July 2026 West Publishing Tells Alabama that a copy of its data was held in "a backup file within the company's cloud environment." Alabama Appellate Courts
2 September 2026 West Publishing; courts US and Canadian notices published. Statements from Alabama, Kentucky AOC, Minnesota, Oregon, Wyoming and the three Ontario chief justices. Notices; court statements
4 September 2026 Wyoming; TransUnion Wyoming FAQ updated with mechanism and 2015–2025 window. Canadian call centre opens. Wyoming FAQ; Canadian notice
31 December 2026 Enrolment deadline for Experian and TransUnion monitoring. Notices

Incident Anatomy

No intrusion chain has been published, so this section reconstructs what the courts and the vendor have said about where the data was and why.

Loading diagram...

What C-Track is

C-Track is West Publishing's case-management suite for courts: docketing, e-filing, document management and judicial workflow, sold to appellate courts and some trial courts, and hosted for many of them in the vendor's cloud. It was acquired by Thomson Reuters with the 2016 purchase of the C-Track product line. The appellate-court concentration in the affected list reflects the product's market; the Ohio entries alone cover ten of the state's twelve district courts of appeals.

Where the data was

Three courts have described the location, and none describes the live production database.

Alabama. The courts' systems were not accessed. West Publishing later disclosed that a copy of Alabama data "was maintained in a backup file within the company's cloud environment." The courts had not requested it and did not know it existed.

Wyoming. The exposed data is "historical data from retired case management systems of the Wyoming Supreme Court and Wyoming district courts." Asked why a vendor had state court data at all, the branch answered: "We share data with West Publishing Corporation so the company can provide technical support for its systems." The affected population is "those who came into contact with the district courts or Supreme Court between 2015 and 2025."

Pennsylvania. The Environmental Hearing Board is listed by Thomson Reuters as a former client. Its data was in the environment after the relationship ended.

Read together, the environment that was breached held support copies, backups and data from retired deployments, retained by the vendor on its own schedule. Ohio's report that access was on "the Court's production platform" is not inconsistent: a hosted production instance and a vendor-side backup can sit in the same cloud tenancy, and the vendor has not said whether the intruder reached one, the other, or both.

How the intruder got in

Wyoming: "Bad actors accessed West Publishing Corporation's systems through a vulnerability in its infrastructure." That is the entire public record on mechanism. It does not say what was vulnerable, whether it was a product or a platform, whether it was patched before or after 30 June, or whether the four-month window reflects persistent access or a single collection followed by late detection. Thomson Reuters, which files 10-Ks and answers to shareholders on cyber risk, has published nothing beyond the notice.

What was in the files

The notice's data categories are those that trigger state breach statutes. The court-specific statements add the substance: Alabama says "sensitive personally identifiable information"; Wyoming says names, addresses and dates of birth; Ontario's chief justices say "anyone involved in court proceedings or mentioned in court documents" could be affected. Sealed material is confirmed for "certain" courts, unidentified. The categories most at risk from a sealed-record exposure, protected addresses and identities, are exactly the ones a credit-monitoring product does not address.

Threat Actor Profile

  • Name / Alias: None. No claim of responsibility; no leak-site listing; no sale reported as of 12 September 2026.
  • Attribution: None by the vendor or any court. Law enforcement was engaged on 30 June; no agency has commented.
  • Motivation: Unknown. Four months of access to court records with no extortion, publication or sale in the ten weeks since detection is unusual for a financially motivated actor and is consistent with espionage, with a broker holding the data, or with a breach that was not what the intruder was looking for.
  • Sophistication: Unknown. Dwell time of four months in a Thomson Reuters cloud environment before detection is the only indicator.
  • MITRE ATT&CK techniques (verified on attack.mitre.org, 12 September 2026; minimal, as the intrusion is undescribed):
    • T1190 Exploit Public-Facing Application (assessed from Wyoming's "vulnerability in its infrastructure"; unconfirmed)
    • T1530 Data from Cloud Storage
    • T1213 Data from Information Repositories

Technical Indicators

# Neither Thomson Reuters nor any court has published indicators.
vendor: West Publishing Corporation (Thomson Reuters)
product: C-Track case management (hosted)
environment: vendor cloud, incl. backup / support copies
access_window: 2026-03-01 to 2026-06-29
discovery: 2026-06-30
mechanism: "vulnerability in its infrastructure" (Wyoming, relaying vendor); no CVE published
notification_sites:
  us: ctracknotification[.]com   # engagement B171847, Experian code JQBNV2NX3
  ca: ctracknotification[.]ca    # TransUnion myTrueIdentity
ip_addresses: []
domains: []
file_hashes: []

Vendor notification. The US notice functions as a substitute notice under state breach laws, with state-specific rider text for Connecticut, DC, Maryland, New York, North Carolina, Rhode Island, Texas, Iowa, Massachusetts, Oregon and others. West Publishing told Alabama it will notify individuals "whose sensitive personally identifiable information was accessed" as Alabama law requires. No count has been given for any jurisdiction. Sixty-four days from discovery to public notice; 23 to 27 days from discovery to notifying the courts.

Courts. Alabama, Kentucky's Administrative Office of the Courts, Minnesota, Oregon, Wyoming, and the chief justices of Ontario's three courts have issued statements. All say their own systems were not compromised. Minnesota's Chief Justice Hudson said she was "deeply troubled that our court users' data has been compromised." Alabama and Wyoming describe a "criminal investigation" and work with law enforcement.

Canada. Ontario's Ministry of the Attorney General was notified with the courts. The Canadian notice does not reference the Information and Privacy Commissioner of Ontario, and no IPC statement has been reported. Thomson Reuters Canada told media it could not estimate how many Ontarians were affected.

Regulators. No US state attorney general has announced an inquiry. No SEC filing by Thomson Reuters has been identified; the company is a Canadian issuer reporting under Form 40-F, and no material-change report referencing the incident was found.

Litigation. A search of CourtListener on 12 September 2026 found no class action naming West Publishing or Thomson Reuters over this incident. Given the fourteen suits filed against IDScan.net within eight days of its disclosure, the absence is notable and may reflect the difficulty of identifying a plaintiff without a count.

Impact Assessment

  • JurisdictionsConfirmed. 24 court bodies in 11 states and USVI (vendor list) plus Minnesota and Oregon (self-reported) and three Ontario courts.
  • Individuals affectedUnknown. No figure from the vendor or any court.
  • Data categoriesReported by vendor as possible. SSNs, driver's licence numbers, medical and health insurance information, dates of birth.
  • Sealed recordsConfirmed as possible by vendor for unidentified courts.
  • Time span of recordsReported. 2002–2015 (New Hampshire); 2015–2025 (Wyoming).
  • Vendor-retained copiesConfirmed (Alabama backup; Wyoming retired systems; Pennsylvania former client).
  • MechanismReported, single source: infrastructure vulnerability.
  • Dwell timeConfirmed. Four months.
  • Operational disruptionNone, per vendor.
  • MisuseUnknown. None reported.

Lessons and Defensive Recommendations

For courts and any organisation with a hosted case or records system

  • Ask the vendor, in writing, for every copy of your data it holds: production, backup, support, test, migration, and anything retained after a system was retired or a contract ended. Alabama and Wyoming learned the answer from a breach notice.
  • Retired system and former client are not exemptions from your data-protection duty; they are the highest-risk copies, because nobody is watching them. Contracts should require certified deletion at retirement, with a date.
  • Sealed records need a separate answer. If a vendor holds copies, the sealing order's protection extends only as far as the vendor's controls. Courts should know whether sealed material is segregated, encrypted separately, or excluded from support copies.

For vendors holding records on behalf of institutions

  • Support copies and backups are production data. Age them out on the customer's schedule, not on the convenience of the support team.
  • Ten weeks after discovery, the mechanism is still unpublished. Courts cannot assess their exposure or their own controls without it. Disclose it.

For security teams

  • Four months of undetected access to an environment holding this data set is the finding. Detection on the copies, not only on production, is the control that was missing.

Sources

  1. West Publishing Corporation. "Website Notification". 2 September 2026.
  2. Thomson Reuters Canada. "C-Track Security Incident Notice". 2 September 2026.
  3. Wyoming Judicial Branch. "West Publishing Corp. Data Breach" and FAQ. Updated 4 September 2026.
  4. ABC 33/40. "Alabama Appellate Courts Investigate Possible Data Exposure". September 2026.
  5. Kentucky Lantern. "Kentucky courts filing system part of 'cybersecurity incident,' judicial branch officials say". 2 September 2026.
  6. FOX 9. "MN court data breach: Private user data exposed after third-party vendor hacked". 2 September 2026.
  7. CBC News. "Ontario court records accessed in cybersecurity breach". September 2026.
  8. MobileSyrup. "Cyberattack hit Ontario courts, sealed information possibly accessed". 10 September 2026.
  9. The Hacker News. "Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data". 3 September 2026.
  10. Help Net Security. "Thomson Reuters reveals breach that exposed U.S. and Canadian court records". 3 September 2026.
  11. The Record. "US and Canadian court data exposed in Thomson Reuters breach". September 2026.
  12. MITRE ATT&CK. T1190; T1530; T1213. Accessed 12 September 2026.
Original Incident Report →

Related Research

A dark-web service called Nexus sold infrared and ultraviolet scans of 153 million North American driver's licences, traced by Krebs to identity-verification vendor IDScan.net. The vendor's own documentation shows its cloud retained every scan indefinitely by default.

Data BreachDarknet & Illicit MarketsIdentity Theft

For 17 days in August 2026 an attacker registered Lenovo IDs on other people's email addresses and signed straight into their Dropbox accounts. Lenovo's verification was the flaw; Dropbox's willingness to trust it without a password was the breach.

Data BreachIdentity Theft

Cl0p exploited an unauthenticated deserialization flaw in PTC Windchill as a zero-day in June 2026, deployed a purpose-built web shell that decrypts the application's keystore, and named 43 manufacturers, including Shell, Philips and GE. It was the second such flaw in three months.

Extortion & BlackmailOT & Industrial SystemsData Breach