TechNewsReel
Live

Thomson Reuters Breach Exposes Courtroom Data Across US and Canada

Unauthorized access to the C-Track case management platform affected 11 US states, the US Virgin Islands, and Ontario.

TechNewsReel Newsroom · September 3, 2026

Thomson Reuters has detected a cybersecurity breach involving courtroom data across the United States and Canada. The incident represents a significant security failure in the legal data infrastructure used by judicial systems in North America.

According to confirmed reports, the breach targeted the company's C-Track case management platform. The unauthorized access was detected on June 30, though investigators have traced the intrusion back to March. The scope of the incident is wide, affecting 11 US states, the US Virgin Islands, and the province of Ontario in Canada. Thomson Reuters is currently investigating the full extent of the data exfiltration and is in the process of notifying the affected parties.

The Role of Legal Infrastructure

Thomson Reuters provides critical legal research and data infrastructure, including platforms like Westlaw, which are essential tools for courts, law firms, and government agencies. The C-Track platform specifically handles case management, meaning it serves as a central hub for the administrative and procedural data that keeps courtrooms functioning. Because these systems integrate deeply with government operations, they are high-value targets for actors seeking sensitive legal information.

Implications for Judicial Integrity

Courtroom data is exceptionally sensitive, often containing private details about litigants, sealed documents, and confidential case records. A breach of this magnitude potentially compromises the privacy of thousands of individuals and could undermine the integrity of judicial processes in two major jurisdictions. When case management systems are compromised, the risk extends beyond simple data theft to the potential exposure of protected legal strategies or the leaking of documents that were legally mandated to remain private.

Next Steps and Unresolved Questions

While the geographic scope and the specific platform involved have been identified, the exact volume and nature of the exfiltrated data remain undetermined. Observers will be watching for a detailed accounting of what specific records were accessed and whether any sealed or privileged information was leaked. The company's ongoing investigation will likely determine if the breach was the result of a targeted attack or a systemic vulnerability within the C-Track architecture.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.