Thomson Reuters C-Track: unauthorised access to court case files across US states, USVI and Ontario
West Publishing Corporation (Thomson Reuters Court Management Solutions) notified courts that an unauthorised party obtained files from the C-Track appellate case-management platform in March 2026; activity was discovered 30 June 2026. The Supreme Court of Ohio public statement says ten of twelve Ohio Courts of Appeals use C-Track hosted by the Court and managed by TRCMS; the 8th and 10th districts do not and are unaffected; TRCMS told the Court on 31 August 2026 that unauthorised access hit the production platform. The Hacker News (3 Sep) summarises West’s 2 September notice: courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario may be in scope; a subset of records could include names, SSNs, driver’s licence numbers, dates of birth, medical and health-insurance information; sealed or redacted material may be impacted for some courts; TRCMS says no evidence of fraud or misuse to date and offers Experian IdentityWorks (US) / TransUnion myTrueIdentity (Canada) monitoring via engagement B171847 and https://www.ctracknotification.com. Distinct from other court or identity cards on this desk.
- Product
- Thomson Reuters / West Publishing C-Track court case management
- Exploited in Australia?
- unknown
- Patch to
- Courts and counsel: follow TRCMS notices; enrol monitoring if in scope; rotate any exposed credentials tied to C-Track filings
Primary: Supreme Court of Ohio C-Track incident statement · Vendor: TRCMS C-Track notification / credit-monitoring portal · The Hacker News (3 Sep 2026)
