Thomson Reuters disclosed that an unauthorized party accessed sensitive court records from its C-Track management platform, impacting judicial systems across 11 U.S. states, Ontario, and the Virgin Islands.
Key Points
- Unauthorized access occurred between March 1 and June 29, 2026, involving files stored on Thomson Reuters' cloud and backup servers.
- Compromised data may include Social Security numbers, driver's license details, medical information, and dates of birth.
- Affected jurisdictions include court systems in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, Wyoming, and Ontario.
- Thomson Reuters is providing 12 months of credit monitoring services to individuals whose personal information was potentially exposed in the breach.
- Minnesota’s judicial branch terminated its connection to the platform, citing concerns over the exposure of appellate court data.