What Happened in the C-Track Data Exfiltration
Thomson Reuters has confirmed that an unauthorized party accessed and obtained files from its C-Track court case management system, a platform used by courts across the United States and in Ontario, Canada, to manage filings, dockets, and case workflows. The incident reportedly took place in March 2026, though public disclosure and notifications to affected courts didn't happen until months later, in September 2026.
So far, at least 11 states have reported impact, including Oregon, where the breach affected appellate courts, and Ohio, whose Supreme Court issued a statement confirming the incident involved the C-Track system. Some courts have said the exposed data included backup files, which often contain broader and older sets of records than active case files.
Importantly, this does not appear to be a ransomware attack. There has been no report of file encryption, no ransom note, and no posting on a known extortion group's leak site. Outlets covering the story, including The Hacker News and Reuters, have consistently described the event as unauthorized access and file exfiltration rather than a system lockup. In plain terms, the attacker seems to have copied data rather than held it hostage, which changes how affected individuals should think about risk. There's no evidence of a ransom demand, but the stolen files themselves are the concern, not disrupted court operations.
Why Court Records Are a High-Value Target for Data Theft
Court case management systems like C-Track sit on an unusual amount of sensitive information. Beyond basic docket entries, these platforms can store Social Security numbers, financial details submitted as evidence, and in some instances, sealed or restricted court documents that were never meant for public view.
That combination makes court software an attractive target for data thieves. Unlike a single retailer breach where the exposure is largely limited to payment card data, a court records breach can surface identity documents, family court filings, financial disclosures, and legal proceedings that individuals expected to remain confidential. The presence of sealed data in this incident is particularly notable, since it suggests the exposure may extend beyond what's already searchable in public court databases.
For attackers, this kind of data has long shelf life. Stolen court records can be used for identity theft, targeted phishing, or even leverage in scams that reference real case details to appear legitimate. This is one reason security researchers keep a close eye on legal-sector vendors, which often fly under the radar compared to healthcare or financial institutions despite handling comparably sensitive material.
Are You Affected: Who Had Exposure Across the 11 States
Determining direct impact is difficult right now because Thomson Reuters and the affected courts have not published a full list of impacted case types or individuals. What is known is that the exposure spans court systems in at least 11 states, with Oregon's appellate courts and Ohio's court system among those that have issued public confirmations.
If you have had any involvement with a state court system, as a plaintiff, defendant, witness, or party to a filing, since the system has been in use, there is a reasonable chance your records passed through C-Track at some point. Backup files were involved in at least some cases, which means the exposure window may reach further back than the March 2026 access date itself.
Because official notifications are still rolling out state by state, the safest approach is to assume potential exposure if you've had any recent or past interaction with a state court, rather than wait for a personalized notice that may take time to arrive.
Steps to Take Now: Monitoring, Credit Freezes, and Reducing Exposure
Even without confirmation that your specific records were taken, there are concrete steps worth taking given the sensitivity of the data involved:
- Freeze your credit with the major bureaus. This is free and prevents new accounts from being opened in your name using a stolen Social Security number.
- Monitor your credit reports and financial accounts closely over the coming months. Identity thieves don't always act immediately, so ongoing vigilance matters more than a one-time check.
- Watch for court-themed phishing. Because attackers now have access to real case details, expect potential scam emails or calls referencing actual filings to seem credible. Treat unsolicited contact about a legal matter with skepticism, and verify independently through official court channels.
- Check for official breach notifications from your state court system, and follow any specific guidance they issue, since some states may offer free credit monitoring or identity protection services in response.
These same fundamentals apply broadly whenever sensitive personal data is exposed in a breach. Our guide on the NYC Health + Hospitals breach walks through a parallel post-breach response, including how to approach credit freezes and monitoring step by step, and is worth reviewing if you want a more detailed walkthrough.
What This Means For You
The Thomson Reuters C-Track breach is a reminder that sensitive personal data doesn't only live with retailers, banks, or hospitals. Court systems, which most people rarely think about as a cybersecurity risk, hold identity-defining information that can be just as damaging in the wrong hands. The fact that this incident involved quiet data exfiltration rather than a loud ransomware attack means there's no dramatic system outage to alert the public, which makes it easier for the risk to go unnoticed. Anyone who has interacted with a state court system in an affected state should treat this as a prompt to check their credit, watch for suspicious contact, and stay alert to updates from their local court.
Key Takeaways
- The Thomson Reuters C-Track breach involved unauthorized access and file exfiltration, not ransomware or encryption.
- At least 11 states have reported impact, including confirmed statements from Oregon and Ohio courts.
- Exposed data may include sealed court records, Social Security numbers, and backup files with older case data.
- If you've had any court interaction in an affected state, freeze your credit and monitor accounts now rather than waiting for a formal notice.
- Stay alert for phishing attempts that reference real case details to appear legitimate.




