Thomson Reuters has revealed that a vulnerability in its C-Track platform exposed information from courts in at least twelve US states and one Canadian province.

On September 2, 2026, Canadian software company Thomson Reuters announced that the breach of its C-Track court case management platform had resulted in the exposure of “sealed court information” and personal data. The incident affected courts in at least twelve US states and one Canadian province, mainly courts of appeal, as well as the Supreme Court and Superior Court of the US Virgin Islands.

Thomson Reuters provided no details on the origin of the vulnerability or any possible attribution of the attack, nor did it provide an estimate of the volume of data involved. The company said it discovered the “unauthorised activity” on June 30, 2026. The investigation established that the breach had begun in March 2026.

According to Thomson Reuters, the personal data concerned includes names, dates of birth, Social Security and driving licence numbers, as well as medical and health insurance information. The company emphasised that the vulnerability originated in its own environment and was not the result of a failure in the networks or information systems of the courts concerned.

Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.
Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.