news.mlab.sh
Back to the feed
threat-intel

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

High
Summary

A data breach at Thomson Reuters' C-Track court case management platform exposed sensitive information, including Social Security numbers, driver's license numbers, and medical data, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. The breach occurred between March and June 2026, and a criminal investigation is underway. Affected individuals are being offered credit monitoring services, and courts are taking steps to enhance security and change passwords.

A data breach at Thomson Reuters' C-Track court case management platform has led to the exposure of sensitive information, including Social Security numbers, driver's license numbers, dates of birth, medical information, and potentially sealed data, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. The breach occurred between March 1 and June 29, 2026, and a criminal investigation is currently active.

Thomson Reuters disclosed the incident on Wednesday, stating that a subset of court records could contain individuals' names, addresses, phone numbers, charge and docket entry descriptions, and, for some individuals charged with a crime, driver’s license numbers and dates of birth. The breach was discovered on June 30, 2026, and the affected courts include the Alabama Appellate Courts, Kentucky Appellate Courts, Montana Supreme Court, Nevada Appellate Courts, New Hampshire Supreme Court, North Dakota Supreme Court, Ohio Appellate Courts, Pennsylvania Commonwealth of Pennsylvania Environmental Hearing Board, Court of Common Pleas of Washington County, Fifth Judicial District of Pennsylvania, and the Court of Common Pleas of Monroe County, South Carolina Supreme Court, Tennessee Appellate Court Clerk’s Office, and Wyoming Judicial Branch. The U.S. Virgin Islands courts reported that the accessed data related to their 2018 system implementation project.

Several courts have taken immediate action, including terminating Thomson Reuters’ access to their electronic environments (Minnesota), changing passwords (Minnesota Supreme Court), and receiving enhanced security measures details (Ohio). Kentucky’s trial court e-filing system was unaffected because the state does not use third-party vendors for it. The incident involved only North Dakota Supreme Court data, with the state’s district courts and its Odyssey system unaffected, and there is no evidence nCourt, the system used to process financial transactions, was impacted.

Affected individuals are being offered 12 months of Experian IdentityWorks credit monitoring in the U.S. and 12 months of TransUnion myTrueIdentity monitoring in Canada, with enrollment open until December 31, 2026, using a multi-use code. A hotline is available at 1-833-918-5294. As of September 3, 2026, no party had published a count of affected individuals, the method by which the files were obtained, or the identity of whoever was responsible. The investigation is ongoing, and the vendor, Thomson Reuters, considers the platform safe to keep using, despite the breach.

Read the full article at The Hacker News