Thomson Reuters disclosed a breach in its C-Track records platform that exposed sealed court information and personal data tied to courts in at least 12 U.S. states, the U.S. Virgin Islands, and Canada. The company said it found unauthorized activity on June 30 and later determined certain C-Track files were obtained in March.
The breach happened in Thomson Reuters’ environment, not inside the courts’ own networks. That matters because C-Track is a shared case-management hub: if one vendor-side compromise reaches it, sealed filings and sensitive records from multiple jurisdictions can be exposed even when local court systems were not breached and the service kept running.
Thomson Reuters has not said how the access began or how much data was taken, and the incident still leaves open who else may have seen the records. For courts using shared records platforms, the exposure sits with the vendor layer as much as with any single courthouse, which changes the privacy and notification burden after the fact.