Thomson Reuters C-Track Breach Exposes Data Across North American Courts
A cybersecurity incident involving West Publishing's case management software affected the New Hampshire Supreme Court and 12 other U.S. states.
A major cybersecurity breach involving the C-Track case management platform has compromised data across multiple judicial jurisdictions in North America. The incident, which affected the New Hampshire Supreme Court and various other court bodies, highlights the systemic vulnerability of third-party software used to manage sensitive legal records.
Unauthorized parties accessed files within C-Track, a platform owned by West Publishing Corp., a unit of Thomson Reuters. The breach persisted from March 2026 through June 30, 2026, when West Publishing discovered the activity. According to confirmed reports, the breach impacted courts in 12 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. Affected entities were notified of the incident between July 23 and July 27, 2026.
The Scope of Exposure
The breach potentially exposed a wide array of highly sensitive personal identifiers. Confirmed reports indicate that Social Security numbers, driver's license numbers, and dates of birth may have been accessed. Furthermore, the breach may have compromised medical information and health insurance details, which are often contained within court filings and case records.
In response to the exposure, credit monitoring services have been offered to affected individuals. These services are being provided via Experian for those in the United States and the U.S. Virgin Islands, and through TransUnion for those in Canada.
Industry Implications
This incident underscores the critical risks associated with the centralization of judicial data through third-party vendors. Because C-Track serves as a primary management tool for court cases, a single point of failure at the vendor level can lead to a multi-jurisdictional crisis. The potential exposure of sealed or confidential court information poses a significant threat to judicial privacy and the integrity of legal proceedings.
Despite the scale of the data access, a spokesperson for Thomson Reuters stated that there was no operational disruption to the C-Track platform as a result of the incident, suggesting the breach was focused on data exfiltration rather than system sabotage.
Next Steps
As jurisdictions continue to assess the specific files accessed, the focus shifts to the long-term security of cloud-hosted judicial infrastructure. While the immediate window of unauthorized access has been closed, the full extent of the data theft remains a primary concern for the affected courts and the individuals whose private information may now be in the hands of unauthorized actors.