<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/a-breach-at-thomson-reuters-reached-appellate-courts-in-twelve-us-jurisdictions-75pgbc8zv" -->

---
title: A breach at Thomson Reuters reached appellate courts in...
description: An unauthorised party accessed files from Thomson Reuters&#x27; C-Track court case management platform, exposing appellate court records across twelve US...
canonical: https://daily.dev/posts/a-breach-at-thomson-reuters-reached-appellate-courts-in-twelve-us-jurisdictions-75pgbc8zv
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: A breach at Thomson Reuters reached appellate courts in twelve US jurisdictions | daily.dev
og:description: An unauthorised party accessed files from Thomson Reuters&#x27; C-Track court case management platform, exposing appellate court records across twelve US...
og:url: https://daily.dev/posts/a-breach-at-thomson-reuters-reached-appellate-courts-in-twelve-us-jurisdictions-75pgbc8zv
og:image: https://api.daily.dev/og/posts/75pgbc8zV.png
og:image:alt: A breach at Thomson Reuters reached appellate courts in twelve US jurisdictions
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# A breach at Thomson Reuters reached appellate courts in twelve US jurisdictions

**[The Next Web](https://daily.dev/sources/tnw)** · 4 min read · 0 upvotes · 0 comments

## Summary

An unauthorised party accessed files from Thomson Reuters' C-Track court case management platform, exposing appellate court records across twelve US jurisdictions plus Ontario, Canada, and later Minnesota. The intrusion occurred in March but was not detected until 30 June, with public disclosure only on 2 September. Exposed data includes names, Social Security numbers, driver's licence numbers, medical information, dates of birth and health insurance details, with Minnesota warning some sealed documents may also be affected. Thomson Reuters says the platform remained operational throughout and is offering twelve months of credit monitoring. No attacker has claimed responsibility and the exact intrusion mechanism has not been disclosed.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thenextweb.com/news/thomson-reuters-ctrack-court-data-breach>

## Questions this post answers

### What personal data was exposed in the Thomson Reuters C-Track court records breach?

Exposed data included names alongside Social Security numbers, driver's licence numbers, medical information, dates of birth, and health insurance information. Minnesota's judicial branch also warned that some confidential or sealed court documents may have been accessed. The breach affected appellate courts in twelve US jurisdictions and Ontario, Canada, through Thomson Reuters' C-Track case management platform.

_Security teams tracking vendor breach fallout can follow developing coverage like this on daily.dev._

### How long did it take Thomson Reuters to disclose the C-Track breach after detecting it?

Thomson Reuters detected unauthorized access in its cloud environment on 30 June, but the files had actually been taken in March, three months earlier. Public disclosure did not happen until 2 September, when affected court systems issued notices simultaneously, more than two months after detection and over five months after the original intrusion.

_Anyone assessing vendor breach response timelines can stay current on incidents like this via daily.dev._

## Similar posts on daily.dev

- [LexisNexis Legal & Professional confirms data breach](https://daily.dev/posts/lexisnexis-legal-professional-confirms-data-breach-zcir7glbd) · The Register · 0 upvotes · 0 comments
- [Bug in jury systems used by several US states exposed sensitive personal data](https://daily.dev/posts/bug-in-jury-systems-used-by-several-us-states-exposed-sensitive-personal-data-guo5u8v86) · TechCrunch · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#data-privacy](https://daily.dev/tags/data-privacy), [#data-breach](https://daily.dev/tags/data-breach)

[View this post on daily.dev](https://daily.dev/posts/a-breach-at-thomson-reuters-reached-appellate-courts-in-twelve-us-jurisdictions-75pgbc8zv)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"A breach at Thomson Reuters reached appellate courts in twelve US jurisdictions","url":"https://daily.dev/posts/a-breach-at-thomson-reuters-reached-appellate-courts-in-twelve-us-jurisdictions-75pgbc8zv","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/a-breach-at-thomson-reuters-reached-appellate-courts-in-twelve-us-jurisdictions-75pgbc8zv"},"datePublished":"2026-09-03T08:07:22.229Z","dateModified":"2026-09-14T06:46:13.867Z","description":"An unauthorised party accessed files from Thomson Reuters' C-Track court case management platform, exposing appellate court records across twelve US...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4cf24f6bddb78611a9abc10115eeac3c?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4cf24f6bddb78611a9abc10115eeac3c?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The Next Web","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Next Web","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/tnw","url":"https://daily.dev/sources/tnw"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/a-breach-at-thomson-reuters-reached-appellate-courts-in-twelve-us-jurisdictions-75pgbc8zv","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,data-privacy,data-breach","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Next Web","item":"https://daily.dev/sources/tnw"},{"@type":"ListItem","position":3,"name":"A breach at Thomson Reuters reached appellate courts in twelve US jurisdictions"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/a-breach-at-thomson-reuters-reached-appellate-courts-in-twelve-us-jurisdictions-75pgbc8zv#faq","mainEntity":[{"@type":"Question","name":"What personal data was exposed in the Thomson Reuters C-Track court records breach?","acceptedAnswer":{"@type":"Answer","text":"Exposed data included names alongside Social Security numbers, driver's licence numbers, medical information, dates of birth, and health insurance information. Minnesota's judicial branch also warned that some confidential or sealed court documents may have been accessed. The breach affected appellate courts in twelve US jurisdictions and Ontario, Canada, through Thomson Reuters' C-Track case management platform. Security teams tracking vendor breach fallout can follow developing coverage like this on daily.dev."}},{"@type":"Question","name":"How long did it take Thomson Reuters to disclose the C-Track breach after detecting it?","acceptedAnswer":{"@type":"Answer","text":"Thomson Reuters detected unauthorized access in its cloud environment on 30 June, but the files had actually been taken in March, three months earlier. Public disclosure did not happen until 2 September, when affected court systems issued notices simultaneously, more than two months after detection and over five months after the original intrusion. Anyone assessing vendor breach response timelines can stay current on incidents like this via daily.dev."}}]}
```

