Full Report
Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names
Analysis Summary
# Incident Report: Unauthorized Access to C-Track Court Management Platform
## Executive Summary
In March 2026, an unauthorized party gained access to and exfiltrated files from the C-Track court case management platform, managed by West Publishing Corporation (a Thomson Reuters unit). The breach impacted judicial systems across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada, potentially exposing individuals' names within court records. The activity went undetected for approximately three months until discovery in late June 2026.
## Incident Details
- **Discovery Date:** June 30, 2026
- **Incident Date:** March 2026
- **Affected Organization:** West Publishing Corporation (Thomson Reuters)
- **Sector:** Legal/Government Technology
- **Geography:** United States (11 states), U.S. Virgin Islands, and Ontario, Canada
## Timeline of Events
### Initial Access
- **Date/Time:** March 2026
- **Vector:** Unauthorized access (Specific technical vector not disclosed in initial report)
- **Details:** An unauthorized party gained access to the environment hosting the C-Track platform.
### Lateral Movement
- **Details:** Specific details regarding lateral movement within the West Publishing network were not disclosed in the provided text.
### Data Exfiltration/Impact
- **Details:** The threat actor obtained files from the C-Track platform. A subset of these court records contained personally identifiable information (PII), specifically individuals' names.
### Detection & Response
- **Discovery:** West Publishing identified the unauthorized activity on June 30, 2026, three months after the initial intrusion.
- **Response Actions:** Thomson Reuters initiated a public disclosure on the Wednesday following discovery and began notifying affected jurisdictions.
## Attack Methodology
- **Initial Access:** Unauthorized access to C-Track platform files.
- **Persistence:** Not disclosed; maintained access from March to at least June 2026.
- **Persistence/Evasion:** The actor remained undetected for ~90 days.
- **Collection:** Targeting of court case management records.
- **Exfiltration:** Unauthorized removal of files from the C-Track environment.
- **Impact:** Compromise of sensitive judicial data and PII.
## Impact Assessment
- **Financial:** Potential costs related to forensic investigation, legal notification requirements, and possible regulatory fines.
- **Data Breach:** Unauthorized acquisition of court records containing individuals' names.
- **Operational:** Impacted court systems in 13 distinct geographical jurisdictions.
- **Reputational:** Public disclosure by a major legal information provider regarding the security of a critical judicial platform.
## Indicators of Compromise
- **Network/File/Behavioral:** Specific IOCs (IP addresses, hashes) were not provided in the disclosure; however, the primary behavioral indicator was unauthorized file access/egress within the C-Track file repository.
## Response Actions
- **Containment:** West Publishing moved to secure the C-Track environment upon discovery.
- **Recovery:** Public disclosure and notification to the 11 U.S. states, Ontario, and U.S. Virgin Islands.
## Lessons Learned
- **Detection Gap:** The three-month dwell time (March to June) indicates a need for enhanced real-time monitoring and anomaly detection within cloud-based case management platforms.
- **Supply Chain Risk:** Judicial entities are heavily reliant on third-party providers like West Publishing, highlighting that a single platform breach can have multi-jurisdictional consequences.
## Recommendations
- **Enhanced Logging:** Implement robust File Integrity Monitoring (FIM) and access logging to alert on mass file downloads or unauthorized access to sensitive repositories.
- **Zero Trust Architecture:** Implement strict identity and access management (IAM) controls for the C-Track environment, including multi-factor authentication (MFA) for all access points.
- **Threat Hunting:** Conduct periodic proactive threat hunting sessions to identify dormant unauthorized presence that bypasses standard signature-based alerts.