4 SEP 2026 — Thomson Reuters has disclosed that an unauthorised party took files from C-Track, the court case management platform its subsidiary operates for courts in at least twelve United States states, the US Virgin Islands and Canada. Names, Social Security numbers, driver's licence numbers, medical information and health insurance details may be involved. Confidential, redacted and sealed court information may be involved too. The remedy offered is twelve months of credit monitoring, which does nothing about that half.

The timeline

The unauthorised access happened in March. Thomson Reuters discovered it on 30 June and brought in outside investigators and law enforcement. Officials in Montana and Ontario were notified on 23 July; public disclosure came on 3 September.

The affected jurisdictions named so far are Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Oregon, Pennsylvania, South Carolina, Tennessee and Wyoming, plus the US Virgin Islands and Canada, where Ontario is confirmed.

No group has claimed responsibility. Thomson Reuters has not said how the attacker got in, how much was taken, or how many people are affected. Nevada officials note that the data involved varies by jurisdiction. Each court system is therefore describing a different incident to its own residents while the underlying event is one.

~6 monthsFrom access in March to public disclosure
12+US states, plus the Virgin Islands and Canada
6 weeksFrom notifying officials to telling the public
SealedCourt information that may have been affected

Sealed records are a different kind of loss

Every element of the standard breach response assumes the exposed thing has a replacement or a monitoring service. A credit file can be frozen. A licence can eventually be reissued. A monitoring subscription will tell you when your Social Security number turns up.

A sealed court record has none of that. It was sealed because a judge decided the public should not see it. The categories that get sealed are the ones where exposure itself is the harm: juvenile matters, adoption files, protective orders carrying the address of the protected person, the identity of a minor victim, a cooperating witness.

There is no monitoring product for that. Nothing tells you when a sealed file has been read, and nothing puts it back. Twelve months of identity theft protection is a reasonable answer to the Social Security numbers and no answer to the other category. The disclosure does not distinguish between the two groups.

Redaction assumes the original stays put

The redacted material is the same problem in a subtler form. Redaction is not deletion. A redacted filing normally exists as a full document with a public version derived from it, and the machinery works only because the unredacted original is held somewhere trusted.

A case management platform is where that original lives. Whoever took files from C-Track may hold the version the court deliberately withheld, alongside the public one that shows exactly which passages were considered sensitive enough to remove.

That pairing is worse than either document alone, because it tells a reader where to look. Nobody has said whether it happened, because Thomson Reuters has not described what was taken.

Four months to discovery is the number to explain

Files were taken in March and the intrusion was found on 30 June. Whatever the attacker did in between, the platform did not notice.

Court systems are unusually well placed to detect this if anyone is looking, because access patterns are predictable. Clerks in one jurisdiction read cases in that jurisdiction, volume follows the court calendar, and bulk retrieval across states has no legitimate workflow behind it. A detection rule for that is not sophisticated.

The individual court systems should ask whether such a rule existed, and whether they or the vendor owned it. It goes to whether this recurs. Unlike the identity of the attacker, it is a question the customers can answer for themselves.

It also determines what the four months mean. If nobody was watching, the gap is an oversight with a fix. If something was watching and the retrieval looked like ordinary clerk traffic, the attacker had credentials that belonged to somebody. Then the fix is a different one.

The six weeks between the two notifications

Officials in Montana and Ontario were told on 23 July. The public found out on 3 September.

Some of that gap is legitimate and expected. Investigators ask for time, scoping across fourteen jurisdictions with different rules takes weeks, and notifying people before you know which people is its own harm.

The gap's cost is specific. Someone whose sealed protective order was in that set spent six weeks not knowing, and for that person the value of knowing early is not credit monitoring. It is the chance to make a decision about their own safety. A disclosure practice calibrated for financial identity theft handles the first group correctly and the second group not at all.

Why this reaches beyond North America

The structure is the story, not the geography. A single commercial platform operating case management for many separate court systems concentrates the records of all of them into one target. Each individual court gets a system it could not build alone.

That trade is being made across Southeast Asia now, in courts, land registries and identity systems, and the argument for it is sound: a shared platform is better run than fourteen bespoke ones. The exposure is that it fails once for everybody.

We made a version of this point about identity verification concentrating documents in one provider. The court variant is harder, because a leaked identity document is a fraud problem with known remedies and a leaked sealed file is a judicial decision that has been reversed by somebody with no authority to reverse it.