Particle.news
Download on the App Store

Thomson Reuters Says Hacker Took Court Files From Its C‑Track Platform

The breach exposed vendor-held court backups to unauthorized access, prompting coordinated investigations, public notices, credit monitoring

Overview

  • Thomson Reuters discovered unauthorized activity on June 30, 2026 and says an attacker obtained C-Track files in March 2026, with the intrusion running through late June.
  • The incident touches appellate and other courts in at least 11 U.S. states plus the U.S. Virgin Islands and three Ontario courts, and the list of affected jurisdictions has continued to grow as courts disclose details.
  • Affected files may include names and sensitive personal data such as Social Security numbers, driver’s license numbers, dates of birth and medical information, and some courts warned sealed or redacted material could also be involved.
  • Thomson Reuters has engaged outside cybersecurity experts, notified law enforcement, set up hotlines and is offering 12 months of credit and identity monitoring while some courts have cut vendor access and begun audits.
  • Key questions remain about exactly which records were taken, whether production systems or backup copies were accessed, who is responsible and how many people were affected, and investigations are ongoing across jurisdictions.