What Happened
Thomson Reuters disclosed a breach of C-Track, the court case management platform sold by its West Publishing unit, found on June 30, 2026. The unauthorized access occurred in March 2026 and reaches 24 court bodies across 11 US states, the US Virgin Islands, and Ontario, including the Ontario Superior Court of Justice. A subset of the exposed files lists names, Social Security numbers, driver’s license numbers, dates of birth, and medical and health insurance information, and sealed-case records sit inside the archive at some affected courts. Thomson Reuters reports no evidence to date of fraud or misuse and offers affected individuals 12 months of free credit monitoring and identity theft protection. Details are available from Help Net Security.
Why This Matters for Canadian Organizations
Ontario Superior Court of Justice appears by name among the affected court bodies, placing Canadian litigants, defendants, and court staff directly inside a breach most coverage frames as a US story. C-Track sits inside the case management workflow at affected courts, so exposed files span whatever proceedings those courts route through the platform, filings carrying heightened confidentiality expectations in many jurisdictions. Under PIPEDA, an organization holding personal information tied to Canadians carries notification duties once breach scope comes into focus, and a vendor breach does not relieve the Ontario court system or linked agencies of their own obligations to affected individuals. Legal sector organizations and any Canadian business relying on Thomson Reuters or West Publishing products for records management should confirm what other Thomson Reuters platforms touch sensitive client or citizen data.
What to Do
Individuals connected to Ontario Superior Court of Justice proceedings during the exposure window should watch for direct notification from Thomson Reuters and enroll in the offered credit monitoring. Organizations relying on C-Track or related West Publishing tools should request a written accounting of which record types their instance stores, and confirm whether sealed or restricted case files sit inside the exposed scope. Privacy and legal compliance teams should review vendor contracts for case-management platforms for breach notification timelines and audit rights, since a March intrusion disclosed six months later shows how long detection and scoping take even at large vendors. Full details are available from Help Net Security and The Hacker News.






