Thomson Reuters and its C-Track court case management platform have published notices after unauthorized activity was discovered on June 30, 2026. The investigation says an unauthorized third party obtained certain C-Track files in March 2026, with no reported disruption to the service.
The scope needs careful wording. C-Track notices list jurisdictions in 11 U.S. states, the U.S. Virgin Islands and Ontario. The Oregon Judicial Department separately says data from the C-Track system used by Oregon’s appellate courts was also involved, alongside at least 11 other states. The public perimeter is therefore multi-jurisdictional and still evolving, with impacts that vary by court system.
What C-Track announced
C-Track, owned by West Publishing Corporation in the United States and Thomson Reuters Canada Limited in Canada, describes an incident discovered on June 30, 2026. After detection, the company says it launched an investigation with external experts, involved law enforcement, contained the activity and secured its environment.
The investigation found that an unauthorized party had obtained certain C-Track files in March 2026. The U.S. notification names court systems in Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, New Hampshire, Ohio and Wyoming, along with the Supreme and Superior Courts of the U.S. Virgin Islands. The Canadian notice names the Court of Appeal for Ontario, the Ontario Superior Court of Justice and the Ontario Court of Justice.
The official C-Track list is not the whole public map. On September 2, 2026, the Oregon Judicial Department said data from the C-Track system used by the Oregon Court of Appeals and Supreme Court was involved. Its release states that Oregon’s circuit courts, Tax Court and Oregon Judicial Department systems were not involved, and that daily court operations were not affected.
This distinction matters. Saying “11 states” follows C-Track’s U.S. notification; saying “at least 12 states” accounts for Oregon’s public statement and The Record’s synthesis. Those two phrasings do not carry the same evidence. The responsible way to track the incident is to date each source, identify the jurisdiction and avoid applying one court’s data categories or impact to another.
Which data may be involved?
The U.S. notification says a subset of court records was affected. Those records may include names and, depending on the file, Social Security numbers, driver’s license numbers, medical information, dates of birth or health insurance information. It also says confidential, redacted or sealed information may have been impacted for certain affected courts.
The Canadian notice is more cautious on categories: it refers to court records that could contain names and personal information, and says confidential, redacted or sealed information may have been impacted for certain courts. In Ontario, the three Chief Justices said the exact content of the files and the number of potentially affected people remain under review. That uncertainty should stay visible: the incident does not prove that every record, every named person or every sealed document was exposed.
What is not publicly established
Several notices converge on important limits. Published documents say the incident was not caused by the networks, systems or security practices of the affected courts. Nevada goes further, saying its internal investigation has found no evidence that Nevada’s individual C-Track environment was accessed or compromised; the incident involved a separate vendor-owned system containing select database backup files.
The notices also say there is no evidence, so far, of fraud or misuse of information. Systems used to process financial transactions related to court proceedings were not indicated as affected. C-Track also remains described as operational. These limits do not make the incident harmless, but they prevent it from being misread as a general court outage or as proof of identity theft already observed.
Practical steps for people and professionals
For individuals, action starts with a verified notification. Anyone involved in a court matter, mentioned in a record, or connected to a named court system should monitor official court and C-Track channels, use the published websites or phone numbers, and avoid links in unexpected messages. The most likely scams will ask for payment, identity documents, codes or case confirmation under a false sense of urgency.
If a notice confirms that sensitive information about you was involved, follow the measures offered by C-Track or the relevant jurisdiction: credit monitoring, credit freezes, review of statements, fraud reporting and evidence preservation. Law firms, legal aid groups and administrative teams should also brief front-desk staff. Concerned people may call for guidance, and a consistent answer reduces the chance they will be pushed toward fake channels.
What organizations should learn from the vendor risk
This incident illustrates a familiar risk in hosted business platforms: sensitive data can be centralized with a provider even when each organization’s internal systems remain operational. Control cannot stop at the contract. Organizations entrusting court, HR, health or customer records to a third-party tool need to know which files are stored, which backups exist, who can administer access, how fast notices must arrive and what evidence the vendor must provide after an incident.
The response should be prepared before a crisis. Teams need the ability to cut or revoke vendor access, identify technical accounts, audit logs, encrypt backups, limit exports and test incident communications. Jurisdictions that publish clear updates also show the value of granular information: the scope varies by state or province, and a national notice does not replace local analysis.
The Soclyde connection
Soclyde does not protect C-Track, Thomson Reuters or the affected court systems, and it cannot determine which court files were accessed. Its value sits upstream of this kind of incident: helping a small organization generate unique secrets for its accounts, keep them in a local-first encrypted vault and quickly identify shared or vendor access that needs rotation.
In a chain involving courts, providers, law firms and administrative accounts, password reuse or secrets stored in shared files can turn a limited incident into a propagation risk. A well-maintained vault does not replace vendor audits, logs or legal notification, but it makes access rotation faster and easier to prove. To build that discipline, read our secure password generator guide or contact Soclyde.
Takeaway
The C-Track incident is confirmed, but its precise impact still needs to be read jurisdiction by jurisdiction. Public notices establish unauthorized activity detected on June 30, 2026, files obtained in March, potentially sensitive court records, and no public evidence of fraud or operational disruption so far. The careful wording is therefore a multi-jurisdictional incident affecting at least 12 U.S. states when Oregon is included, along with the U.S. Virgin Islands and Ontario.
For individuals, the priority is to rely on official channels and reject unverified urgent requests. For organizations, the lesson is vendor governance: data inventory, unique secrets, revocable access, audit evidence and dated communications. For more on access management and secret rotation, read our local-first password manager guide.



