Thomson Reuters just admitted a hacker read court files for months before anyone noticed.
Thomson Reuters said an intruder broke into a cloud environment running C-Track, its court case-management software, in March 2026. The company did not detect the breach until June 30, three months later, and only disclosed it this week. Courts in 11 US states - Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, and Wyoming - plus Ontario and the US Virgin Islands were affected. Thomson Reuters says C-Track stayed operational throughout, and it has found no evidence of identity theft or access to financial-transaction systems.
This is not just a Reuters problem. C-Track feeds directly into how courts manage filings, hearings, and case records, so a breach touches the sensitive legal paperwork of ordinary people caught up in the justice system - custody disputes, criminal cases, restraining orders - not corporate data. Thomson Reuters still cannot say what was taken or how many people were affected, which means the real scope of this one won't be known for a while.
For a company that sells legal-data infrastructure to governments, a three-month detection gap is the kind of detail that undercuts the pitch, whatever the eventual damage turns out to be.