Thomson Reuters Court Software Breach Exposes Sensitive Case Records
Thomson Reuters has disclosed that an unauthorized party accessed files from C-Track, a court case management platform sold by its West Publishing Corporation subsidiary. The incident, which occurred in March 2026, affected courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Publishing said it identified the suspicious activity on June 30, 2026.
According to the disclosure, a subset of the affected court records may contain individuals' names and Social Security numbers, along with potentially sealed or otherwise sensitive case information. Because C-Track is used by court systems to manage case files, the breach raises concerns not just for individual privacy but for the confidentiality of legal proceedings that rely on restricted access to certain records.
While the direct impact of this breach falls on court systems and the people involved in legal cases, it highlights a broader risk for Australian small businesses: many organisations rely on third-party software vendors to manage sensitive data, and a breach at that vendor can expose your customers' or clients' information even if your own systems were never touched. Reviewing which vendors hold sensitive data on your behalf, and understanding their breach notification practices, is an important part of managing this risk.