Four months of unnoticed access
Thomson Reuters' West Publishing unit disclosed on September 2 that its C-Track court case management platform experienced unauthorized access between March 1 and June 29, 2026, a nearly four-month window before the intrusion was even detected on June 30. The platform is used by court systems to manage active case files, and the exposure touched 24 separate court bodies across Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, and Wyoming, plus the U.S. Virgin Islands and Ontario, Canada. That is a wide, multi-jurisdiction footprint for a single vendor platform to carry, and it means one intrusion produced two dozen separate breach notification obligations simultaneously.
What makes court case management systems a distinct category of risk is the sensitivity baked into the product itself. This is not a marketing database or a customer support ticketing tool logging names and emails. It holds Social Security numbers, driver's license numbers, dates of birth, medical information, health insurance details, and for certain proceedings, confidential, redacted, or sealed documents that judges specifically restricted from public view for legal reasons tied to the underlying case.
The disclosure timeline is the real story here
West Publishing notified affected courts between July 23 and 27, nearly a month after discovering the breach on June 30. Public disclosure did not follow until September 2, another five weeks after that. Laid end to end, the timeline runs roughly four months of undetected access, then a month before customers heard anything, then five more weeks before the public did. Each stage compounds the last, and by the time the public learned about it, the underlying intrusion was already six months in the past.
North Dakota's court system confirmed an active criminal investigation is underway. Minnesota's Supreme Court Chief Justice Natalie Hudson said publicly she is deeply troubled that court users' data had been compromised, a notably direct statement from a sitting chief justice, made sharper by reports that Minnesota was absent from some of the vendor's initial notification lists. A state's top judicial officer voicing frustration in public is a strong signal that a long-standing vendor relationship is under real strain.
Sealed documents are a different category of exposure
Most breach disclosures involve personal data that, however sensitive, follows familiar remediation paths: credit monitoring, fraud alerts, password resets, new account numbers. Sealed court documents follow none of those paths. A record gets sealed because a judge determined, for specific legal reasons, that it should stay out of public view entirely, often to protect a minor, a victim, an ongoing investigation, or a proceeding carrying statutory confidentiality protections that exist independent of any data-breach law.
Once such a document has been exposed to an unauthorized party for an unknown duration, no credit monitoring service can undo that exposure, and there is no equivalent of freezing a Social Security number to contain the damage. That distinction should reshape how enterprises and public institutions alike scope vendor risk assessments for any system storing legally protected or court-sealed information, treating it as a category with its own remediation ceiling rather than folding it into standard personally identifiable information handling procedures.
The vendor's response and its limits
West Publishing stated there is no evidence to date of fraud or misuse of the exposed information, and a Thomson Reuters spokesperson told reporters there has been no operational disruption to C-Track as a result of the incident. The company is offering 12 months of credit monitoring through Experian in the U.S. and TransUnion in Canada, the standard remediation package courts and vendors typically extend for this class of breach involving government-held personal records.
Those steps address only the personally identifiable information subset of what was exposed, though, and leave the sealed-document question entirely untouched. Credit monitoring does nothing for a sealed document that has already been copied by an unauthorized party during a four-month access window that nobody was watching closely. No attribution has been made public as of this writing, and it remains unclear whether the access was broad and opportunistic or targeted at specific case files of particular interest to the intruder.
The vendor concentration risk this exposes
Thomson Reuters is a dominant player in legal technology infrastructure, and C-Track sits embedded in court operations across multiple states and jurisdictions that each independently trusted the platform with sensitive case data. A single platform compromise cascading to two dozen separate government bodies is a clean illustration of concentration risk: when one vendor serves that many downstream institutions, one intrusion multiplies into dozens of parallel breach notifications, legal obligations, and reputational exposures all at once.
Enterprise legal and compliance teams working with any large legal-tech or gov-tech vendor should use this disclosure timeline as grounds to revisit contractual breach notification service levels specifically. A four-month detection gap followed by a seven-week notification delay and a further five-week public disclosure lag looks close to becoming the realistic default vendor breach cadence, and contracts negotiated years ago may set expectations well out of step with that reality.
What this means for legal-tech and gov-tech buyers
Organizations that license case management, e-discovery, or records infrastructure from large legal-tech vendors should treat this incident as a prompt to ask a specific question of their own vendors: what is the actual detection window on the systems handling our most sensitive records, and how has that number changed in the last two years. A four-month gap between intrusion and discovery turned out to be the documented outcome at one of the largest, most established names in the entire industry, which sets a realistic baseline for what any comparable vendor's actual detection capability may look like today.
It is also worth asking vendors directly whether sealed, confidential, or otherwise legally restricted records are stored, encrypted, and access-logged any differently than routine case data within the same platform. An honest answer here becomes useful evidence for any procurement or renewal conversation, and a reasonable basis to push for tighter contractual notification timelines proactively, well ahead of the next incident rather than in the scramble that follows one.



