← Blog · · df00tech

Thomson Reuters' West Publishing Discloses Breach of C-Track Court Case Management Software

security-news breach

What happened

Thomson Reuters disclosed that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit. According to the disclosure, the activity occurred in March 2026 and was discovered by West Publishing on June 30, 2026. The incident affects courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. A subset of the exposed court records could contain individuals' names, and reporting indicates the exposure may include Social Security numbers and sealed court data, though the full scope of affected data types has not been fully detailed in the disclosure as summarized here.

Why it matters for defenders

C-Track is case management software used directly by court systems, meaning the exposure isn't limited to a single organization's employees or customers — it potentially touches litigants, defendants, and other individuals whose information passed through affected courts across multiple U.S. states and two other jurisdictions. Sealed court data is especially sensitive: exposure can affect protective orders, juvenile records, or other information courts deliberately restricted from public view, raising both privacy and safety concerns beyond typical PII breaches. The multi-month gap between the March 2026 intrusion and the June 30, 2026 discovery is also notable for defenders evaluating dwell-time risk in third-party government-facing software.

What defenders should watch for or do now

  • Organizations running or integrating with West Publishing/Thomson Reuters court systems, including C-Track, should review vendor communications for indicators of compromise and any recommended remediation or credential rotation steps.
  • Court IT and security teams should audit access logs to case management platforms for anomalous authentication or bulk data export activity spanning the March–June 2026 window.
  • Given the exposure of court-related identity data, downstream monitoring for identity theft, court-record-themed phishing, or fraudulent filings targeting affected individuals is prudent.
  • This incident is a reminder to inventory third-party SaaS platforms handling sensitive government or legal records and to confirm those vendors' breach notification and logging capabilities meet your requirements.

Developing story

This is a net-new disclosure and details are still emerging; df00tech has not independently verified the full scope of exposed data types. We will continue to track updates. Read the original report at The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.