# Sealed Records, SSNs, and a Three-Month Blind Spot: Inside the C-Track Court Breach


When a hospital gets hit, the headlines write themselves. When the software managing your sealed court records gets hit — the restraining order you filed, the juvenile case your state expunged, the protected witness testimony — the damage is harder to explain and potentially worse to live with.


That's where we are with West Publishing Corporation, a Thomson Reuters subsidiary that disclosed this week that an unauthorized party accessed files from C-Track, its court case management platform, in March 2026. The breach touched courts across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. Thomson Reuters says it discovered the intrusion on June 30 — roughly three months after the fact.


## What the Courts Were Storing


C-Track isn't a niche product. West Publishing has spent decades embedding itself into the operational infrastructure of American jurisprudence — LexisNexis's main competitor, deeply integrated into how courts manage dockets, filings, and case histories. C-Track specifically handles case management at the court level, which means the data it holds is a cross-section of some of the most legally and personally sensitive records that exist.


The disclosure acknowledges that "a subset of court records could contain individuals' names" — a line that reads like it was drafted by legal counsel to say as little as possible. Read between it: court records routinely contain Social Security numbers collected for identification, financial information submitted during proceedings, addresses of parties in domestic violence cases, and records that courts have specifically ordered sealed to protect someone's safety or rehabilitation.


Sealed records aren't redacted versions of public filings. They're documents a judge determined should not be visible to the public at all — often because disclosure would endanger someone. An attacker who walked out with a bulk export of court case data doesn't just have names and SSNs. They potentially have a map of people courts have decided deserve privacy protection.


## Three Months Is a Long Time


The timeline here deserves scrutiny that the initial disclosure hasn't received.


March 2026: unauthorized access occurs. June 30, 2026: West Publishing discovers it. That's somewhere between 90 and 120 days of dwell time — a period during which the attacker had whatever they took, and the courts, the individuals in those records, and Thomson Reuters itself had no idea.


Three months of dwell time used to be embarrassing. Now it's just depressingly common in breaches that involve enterprise software vendors rather than direct targets. The attacker didn't need to maintain persistent access to a court network; they got what they needed from the software vendor's infrastructure and left. Detection becomes much harder when the data isn't sitting in your own SIEM.


This is the core problem with the third-party software model in critical infrastructure: courts don't have visibility into their vendor's environment. They're not running endpoint detection on West Publishing's servers. They're not getting telemetry from C-Track's cloud infrastructure. They handed over their data and trusted the contract.


## The Vendor Knows More Than It's Saying


Thomson Reuters' disclosure describes the affected parties as courts "in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada" — but doesn't name any of them. The company says it notified affected customers, which is fine as far as standard breach protocol goes. But the people actually harmed here aren't the courts. They're the individuals whose records live in those courts' case management systems.


If your sealed divorce proceeding was in a C-Track court in March 2026, you may not know it. The court may not proactively reach out. Thomson Reuters is not going to send you a letter. The notification chain for a breach at a court software vendor is genuinely broken — there's no direct relationship between West Publishing and the person whose SSN was in a case file.


This is the part of the breach nobody's writing about: the individuals with sealed records have almost no way to determine whether they're affected, and the entities that do know — West Publishing and the courts themselves — have limited obligation to find them.


## A Pattern the Legal Tech Sector Keeps Ignoring


This isn't the first time court management software has appeared in a breach disclosure, and the legal technology sector has been notably slow to treat itself as a high-value target despite obvious logic to the contrary.


Courts hold criminal records, financial disclosures, IP filings, custody arrangements, and information on protected individuals. For a threat actor interested in blackmail, financial fraud, identity theft, or even targeted physical harm, bulk court data is extraordinarily valuable. The legal industry's cybersecurity posture has historically lagged healthcare and financial services — sectors that got regulation (HIPAA, PCI-DSS) forcing minimum standards. Courts and their software vendors have operated in a comparatively unregulated environment.


West Publishing, for its part, is not a small startup. Thomson Reuters reported over $7 billion in revenue in 2025. The security investment expected of a company that size, handling data of this sensitivity, should be considerably higher than "we noticed three months later."


## HackWire Analysis


The C-Track breach is significant for reasons that extend well beyond the immediate victim count. What makes it structurally dangerous is the category of data at risk: sealed records represent the judicial system's explicit attempt to protect individuals from public exposure of their most sensitive circumstances. A domestic violence survivor whose address appears in sealed filings. A juvenile whose record was expunged. A cooperating witness in a criminal case. These aren't hypothetical edge cases — they're the precise reason courts have sealing procedures.


The three-month detection gap points to a visibility problem that courts and government entities won't solve without mandating security baselines for the vendors they contract with. Right now, a municipality can hand over its entire court record database to a software vendor with contractual assurances and almost no technical verification. The vendor's SOC 2 report, if one exists, was probably a year old at minimum.


What's missing from the broader coverage here: nobody has asked what Thomson Reuters' breach response looks like for the courts that can't identify which specific individuals are in the affected files. Court systems often don't maintain their own searchable indexes of who's in what sealed case — that's the point of sealing them. Reconstructing the victim population from a breach of this type may be genuinely difficult.


For defenders: any organization that hands case or record data to a SaaS vendor should be auditing those vendors' incident response commitments now, not after the next disclosure. Ask specifically how your vendor would notify affected individuals if the breach originates in their infrastructure, not yours. If the answer is "we'd notify you and let you handle it," that's an honest answer — and a gap you need a plan for.


For the courts themselves: this is a forcing function to demand contractual notification timelines from software vendors, and to push for data minimization in the records they're syncing to external platforms. Sealed records in particular should be subject to access restrictions that survive a vendor compromise.


— HackWire Editorial


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)