
In early September 2026, Ontario's three chief justices disclosed that an unauthorized party had gained access to C-Track, the digital case management system Ontario's courts use to store and manage court records. The intrusion ran from March to June 30, 2026, and may have exposed names and personal information, including, in some cases, confidential, redacted, or sealed information. Thomson Reuters, which owns the platform, says the number of Ontarians affected is unknown, and the courts are offering affected individuals a year of free credit monitoring.
Key takeaways
- C-Track is the case management platform used by the Court of Appeal for Ontario, the Ontario Superior Court of Justice, and the Ontario Court of Justice, all three were affected.
- Thomson Reuters detected the intrusion on June 30, 2026, but the unauthorized access began in March, roughly three months of exposure.
- Court records containing names and personal information were affected, and confidential, redacted, or sealed information "may have been impacted."
- The same intrusion hit courts in at least 12 U.S. states and the U.S. Virgin Islands; Ontario was the only Canadian jurisdiction affected.
- Free credit monitoring (TransUnion myTrueIdentity) is available for 12 months, enrolment closes December 31, 2026.
What is C-Track?
C-Track is an online case management platform owned by Thomson Reuters Canada that courts use to store, organize, and manage court documents and records digitally. The system is operated by West Publishing Corporation, a Thomson Reuters subsidiary. It is not a public records portal for casual browsing, it is the back-end infrastructure that court staff and legal professionals use to handle case files.
In Ontario, C-Track supports the three main courts: the Court of Appeal for Ontario (the province's highest court), the Ontario Superior Court of Justice (which handles serious criminal, civil, and family cases), and the Ontario Court of Justice (which handles the majority of criminal and family cases). Because case files by nature contain names, addresses, dates of birth, financial details, and other personal information, a breach of this system is categorically different from a breach of, say, an email list.
What happened, in order
March 2026. An unauthorized party obtains certain C-Track files. This is the earliest date investigators later attributed to the intrusion.
June 30, 2026. Thomson Reuters detects "unauthorized activity within one of its cloud environments," according to the statement from Ontario's chief justices. The company begins containment work, brings in external cybersecurity experts to investigate, and notifies law enforcement.
July 23, 2026. Thomson Reuters Canada Limited formally notifies Ontario's Ministry of the Attorney General about the incident, according to reporting on the company's Canadian notification materials.
September 2, 2026. Public disclosure. Ontario Chief Justice Michael H. Tulloch, Ontario Superior Court Chief Justice Patrick J. Boucher, and Ontario Court of Justice Chief Justice Sharon M. Nicklas publish a joint statement describing the breach. Reuters reports the same day that the intrusion affected courts in 11 U.S. states, the U.S. Virgin Islands, and Canada. Thomson Reuters sets up a dedicated information website (ctracknotification.ca) with details for affected individuals.
After September 2, 2026. Additional jurisdictions disclose their own exposure: Minnesota's Judicial Branch confirmed on September 2 that its appellate courts' data was exposed, and Oregon's Judicial Department confirmed its appellate courts were involved, pushing the known count of affected U.S. states to at least 12, according to technology press coverage.
What we know (facts)
- The intrusion was real and extended. Unauthorized access to C-Track files ran from March through June 30, 2026, roughly three months, before detection.
- Names and personal information were in the affected records. Thomson Reuters' own incident website states that some court records were "affected" and included names and personal information.
- Sealed information is in the mix. The company's notification materials warn that "certain confidential, redacted or sealed information may have been impacted for certain affected courts." For Ontario, that is the courts' own position too.
- No operational disruption. Thomson Reuters told CBC News that its "products and services remain fully operational and are safe to continue to use." The courts did not stop operating; the breach did not take the system offline.
- The blast radius goes well beyond Ontario. The same intrusion affected courts in Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming, and the U.S. Virgin Islands, with Minnesota and Oregon disclosing separately afterward.
- Credit monitoring is on offer. Thomson Reuters is offering 12 months of TransUnion myTrueIdentity credit monitoring at no cost, with a call centre (1-833-918-4543) for questions. Enrolment is open until December 31, 2026.
What we don't know (unknowns)
- How many Ontarians are affected. Thomson Reuters has not provided an estimate of the number of individuals whose information was accessed.
- What date range Ontario's records cover. A statement by the New Hampshire Judicial Branch says the breach affected records from 2002 to 2015 in that state, but it is not confirmed whether Ontario's records span a similar period.
- How the attacker got in. Thomson Reuters has not disclosed the method of unauthorized access.
- Who was responsible. No attribution has been made public.
- Whether the data was misused. There is no public evidence confirming that the accessed information has been used for fraud or identity theft, but its absence cannot be verified from public reporting either.
Was I affected? How to check and what to do
There is no public tool to search whether your records were among those accessed. Whether you should act depends on whether you have had dealings with Ontario's courts, as a party to a case, a witness, or in any role where your personal information appears in a court file.
If you believe your information may be involved, the practical steps available are:
- Consider the free credit monitoring. Thomson Reuters is offering 12 months of TransUnion myTrueIdentity monitoring at no cost, with enrolment open until December 31, 2026. A dedicated call centre (1-833-918-4543) is taking inquiries. Credit monitoring does not prevent identity theft; it alerts you to changes on your credit file so you can respond faster.
- Watch for phishing. Breaches of name-and-personal-information datasets are frequently followed by targeted phishing, emails or texts that reference real details (like a court case) to seem credible. Be wary of unexpected messages about your case or personal data, and verify through channels you initiate yourself.
- Report suspected fraud. If you suspect your personal information is being misused, you can report to the Canadian Anti-Fraud Centre (antifraudcentre-centreantifraude.ca) and contact your financial institutions.
- Remember the sealed-record angle. If you were involved in a case with sealed or redacted records, for example, certain family or youth proceedings, the fact that such material "may have been impacted" is worth knowing, even if there is no action to take from it today.
One important limitation, stated plainly: these steps reduce risk and improve detection; none of them can undo the exposure. Jurisdiction is Ontario, and the incident notification and credit monitoring offer are being administered by Thomson Reuters Canada.

Why this story matters beyond Ontario
October is Cyber Security Awareness Month in Canada, run through the federal Get Cyber Safe campaign, and the 2026 theme is "Your best defence is you", a reminder that everyday habits like multi-factor authentication, strong unique passwords, and pausing before clicking suspicious messages are the main defences most people control. The C-Track breach is a useful illustration of why that message matters: the compromised system was run by a large, well-resourced vendor, not by individual users, and yet the people exposed are ordinary court users who had no say in the security arrangements.
It also fits a broader pattern. Case management and legal-records systems concentrate highly sensitive personal data, exactly the kind of information that is valuable for identity theft. When that data sits in a single vendor's cloud environment serving courts across two countries, a single intrusion produces a continental-scale incident. For more on how AI-era threats are changing the security picture for people who build software, see our guide to AI coding agents and the security risks developers face.

The bottom line
The C-Track breach is not a hypothetical risk story, between March and June 2026, an unauthorized party had access to the case files of Ontario's three courts, including material that may have been sealed. What remains unresolved is scale: how many people are affected, and whether the data has been misused. Until those unknowns are answered, the sensible posture is the unglamorous one: enrol in the monitoring if you're concerned, tighten your defences, and treat this as a reminder that sensitive data you never chose to hand to a vendor can still end up exposed through one.
Sources
- MobileSyrup, Cyberattack hit Ontario courts, sealed information possibly accessed
- PYMNTS, Thomson Reuters Reveals Hack of Court Case Management System
- breached.company, Thomson Reuters C-Track Breach Hits Courts in 11 States
- tech-insider.org, Thomson Reuters C-Track Breach Hits 11 States (2026)
- Second Reading, Ontario's chief justices say court records were taken in C-Track breach
- Canada.ca, Cyber Security Awareness Month 2026
Quick answers
Frequently asked questions
01
What is C-Track?
C-Track is a digital case management platform owned by Thomson Reuters (operated by its West Publishing subsidiary) that courts use to store and manage court documents and records. Ontario's three main courts all use it.
02
Which Ontario courts were affected by the C-Track breach?
The Court of Appeal for Ontario, the Ontario Superior Court of Justice, and the Ontario Court of Justice, all three, per the joint statement of their chief justices.
03
When did the breach happen?
The unauthorized access began in March 2026 and continued until Thomson Reuters detected it on June 30, 2026. It was publicly disclosed on September 2, 2026.
04
Was sealed court information exposed?
Thomson Reuters says "certain confidential, redacted or sealed information may have been impacted for certain affected courts." The company has not specified which courts' sealed material this refers to.
05
How do I get the free credit monitoring?
Thomson Reuters is offering 12 months of TransUnion myTrueIdentity monitoring at no cost, with enrolment open until December 31, 2026. A call centre at 1-833-918-4543 is available for questions.



