Vendor Risk: Thomson Reuters C-Track Breach Exposes Sealed Court Records for 92 Days

Court case management is not public records infrastructure. It's the operational system clerks and judges use to track cases, store filings, and manage information that, by statute, never appears in a public docket. When Thomson Reuters C-Track was breached in March 2026, an unauthorized third party gained access to that data for 92 days — and that data included sealed, redacted, and confidential court information across 24 court organizations in 12 US states, the US Virgin Islands, and Ontario, Canada.

Thomson Reuters disclosed the breach in September 2026. Detection happened June 30, 2026. The breach started "in March 2026" — which could mean March 1 or March 31. Even the conservative reading puts it at 92 days of access. That's not an intrusion. It's residency.

## What Was Exposed

Names, Social Security numbers, driver's licenses, medical information, dates of birth, and health insurance records. That's the baseline PII — the data that enables identity theft and financial fraud.

But C-Track also holds sealed court records. Juvenile case files. Mental health commitment proceedings. Domestic violence protective orders with victim identities and locations. Grand jury proceedings. Witness identities in ongoing investigations. Adoption records. Cases involving minors as victims.

These are not "confidential because sensitive." They are sealed by court order, protected by law, and their disclosure is, in many jurisdictions, a criminal offense when done without authorization.

Someone had 92 days in that data.

## Dwell Time

Ninety-two days is long enough to identify high-value records, exfiltrate systematically without tripping alerts, and sell access to a second actor while the first one is still inside. It's long enough to pivot to connected systems if C-Track is the entry point.

The breach notice offers 12 months of free Experian IdentityWorks credit monitoring to affected individuals. That covers identity theft. It does not cover:

- A sealed juvenile record appearing in a background check five years later
- A witness in a gang prosecution being identified by name and address
- A domestic violence protective order with the victim's location being sold to the person the order was filed against
- A mental health commitment record from 2015 surfacing in a 2027 custody hearing

Credit monitoring is the baseline response for "we lost your Social Security number." It is not a response for "we lost your sealed court file."

## The Vendor-Risk Problem

Thomson Reuters C-Track is a SaaS platform. One vendor. Multiple jurisdictions. A single breach affects 24 court organizations, and every one of them is now writing notifications, fielding inquiries, and trying to figure out which cases were exposed.

This is supply-chain risk in government services. The courts did not get breached. Their vendor did. And the vendor had access to the most sensitive records the judicial system produces.

The courts chose C-Track. They signed contracts. They migrated case files into a cloud platform. They trusted that Thomson Reuters, a global legal-information conglomerate, had the security posture to protect judicial data.

And for 92 days, they didn't.

Court data is different. Payroll files, benefits records, tax filings — those carry PII, and when they leak, the damage is identity theft and financial fraud. Sealed court records carry something else: the power to destroy someone's life with information the law said should never be public.

Source: Thomson Reuters C-Track breach notification, September 2026; HelpNetSecurity and The Hacker News, September 3, 2026.