Thomson Reuters has disclosed that an unauthorized party obtained files from its C-Track court case management platform in March 2026, affecting court systems in 11 US states, the US Virgin Islands, and three Ontario courts. The breach was detected on June 30. Court records were among the files accessed, and the company said some records included names and personal information, according to the company's breach notification website and a joint statement from the chief justices of Ontario's Court of Appeal, Superior Court of Justice, and Court of Justice.
The affected US jurisdictions are Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, and Wyoming. Thomson Reuters said there has been no operational disruption to C-Track and that products and services remain fully operational. A contact center will be active from September 4 to handle inquiries in both the US and Canada.
Independent cybersecurity experts assisted in the investigation and validated the remediation measures.
What is not yet clear is the full scope of what was compromised. The chief justices' statement said individuals involved in court proceedings - or simply mentioned in court documents - could have had personal information relating to them involved in the incident. Reuters could not independently determine who was responsible or what specific information was accessed.
The Thomson Reuters breach is not a conventional enterprise cyber incident. C-Track is a case management platform used by courts - meaning the personal information at risk belongs to individuals who never consented to their data being held by Thomson Reuters and who have no direct commercial relationship with the company. That distinction matters for the liability picture.
Third-party data liability - coverage for the personal information of individuals held by or processed through an insured organization - is consistently among the most common cyber insurance claim categories. IBM's 2026 Cost of a Data Breach Report, based on a study of 604 organizations across 17 industries and 16 countries and released July 29, put the global average cost of a data breach at a record USD 4.99 million and the US average at USD 11.5 million, according to PKWARE's analysis of the report. For a breach affecting courts across 11 states and two countries, with an unknown number of individuals' personal information at risk, the liability exposure - notifications, legal costs, regulatory scrutiny, and potential litigation from affected individuals - sits at the high end of that range before any claim is formally quantified.
The Thomson Reuters incident illustrates the exposure precisely. The court systems that used C-Track did not suffer a breach of their own infrastructure. They suffered a breach of a vendor's infrastructure, and their data was the asset compromised. Whether those courts' own cyber policies respond to that scenario depends entirely on whether their vendor management and supply chain cyber coverage is in place - and whether it was correctly specified.
The C-Track incident fits a pattern that has become more common in 2026. NYC Health + Hospitals confirmed in March that an unauthorized actor accessed its network through a compromise at a third-party vendor, according to PKWARE. Ernst & Young disclosed that an unauthorized party downloaded tax documents from a third-party IT service management platform. In nearly every case, the perimeter of the primary organization did not fail - attackers gained access through a vendor relationship.
The vendor access question is the one most likely to reveal gaps for brokers. The relevant questions to ask at any renewal: does the policy respond to a breach at a third-party platform that processes or stores the client's data? Is there a sublimit on third-party or supply chain incidents that reduces coverage below the headline limit? Does the notification and crisis management coverage extend to incidents where the client's data is compromised by a vendor rather than by a direct attack?
Court records are a specific category of sensitive data. Unlike a credit card number - which can be cancelled and reissued - a person's appearance in a court document is a permanent fact. Once court record data is exfiltrated, the liability it creates for the organizations holding it does not expire. PKWARE's 2026 breach analysis noted that three of July's five major breach incidents exposed identifiers that cannot be reissued, "creating liability with no expiration date."
That is the nature of the exposure the Thomson Reuters incident creates. The individuals whose personal information may have been in those court files cannot opt out of the risk retroactively. For brokers whose clients hold, process, or rely on similar categories of sensitive personal data - legal, medical, financial - the Thomson Reuters case is a concrete illustration of why the adequacy of cyber coverage is a more material question than its existence.