Skip to content

This article features deals sourced directly by Gizmodo and produced independently of the editorial team. We may earn a commission when you buy through links on the site.

Deals

Your Social Security number might already be in the hands of hackers, and the software running US courts just admitted it

If your name has ever appeared in a court record in one of a dozen US states over the past few years, there's a real chance your Social Security number is now in the hands of an unknown attacker. Thomson Reuters, the company behind C-Track, the court case management platform used by appellate courts across the United States and Canada, disclosed on September 2 that an unauthorized third party had been inside its cloud environment for close to four months before anyone noticed.
By

Reading time 4 minutes

What Actually Happened at C-Track

According to Thomson Reuters’ own disclosure, the intrusion began in March 2026 and continued undetected until June 30, 2026, when the company’s security team finally spotted unauthorized activity in the cloud environment hosting C-Track. During that roughly four-month window, the attacker had access to files associated with appellate court systems in 12 US states, the US Virgin Islands, and three courts in Ontario, Canada.

The affected US jurisdictions include Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Oregon, Pennsylvania, South Carolina, Tennessee, and Wyoming. In Ohio alone, ten of the state’s twelve District Courts of Appeals were affected. The company stresses that the incident happened inside its own cloud infrastructure, not on any court’s own network. C-Track itself remained fully operational throughout, and the platform is still in active use today.

What Was in the Exposed Records

This is where the story stops being abstract. The files potentially accessed by the attacker contain, per Thomson Reuters’ notice, names, Social Security numbers, driver’s license numbers, dates of birth, medical information, and health insurance information. Court filings often contain exactly that combination, because case documents routinely include personal identifiers of parties, witnesses, and sometimes minors.

Some jurisdictions have flagged an even more sensitive concern. Minnesota’s Supreme Court warned that sealed or redacted documents may have been affected in some cases, meaning material that a judge had specifically ordered to remain private could have been pulled along with the rest. A sealed record is not just embarrassing data. It might be a protective order, a juvenile matter, a redacted medical filing, or a witness identity that a court decided must never surface publicly. In this incident, none of those safeguards traveled with the files.

Monitor your identity with NordVPN

Why You’re Only Finding Out Now

The gap between when this breach happened and when the public heard about it is one of the most striking parts of the story. The timeline runs like this: attackers were inside from March through late June, Thomson Reuters detected the activity on June 30, individual courts were notified between July 23 and July 27, and public disclosure came on September 2. That means five months elapsed between the initial intrusion and the day affected individuals could begin to react.

Thomson Reuters has said the delay allowed for a coordinated announcement across multiple jurisdictions, which prevented a fragmented rollout that would have been harder for the public to make sense of. Fair enough as a communication strategy, though it also meant that for two months after detection, the people whose data was exposed had no way of knowing they needed to freeze their credit or watch for suspicious activity. Some of the most fundamental questions about the incident, including who was responsible, how the attacker gained access, and how many people were actually affected, still have no public answer.

What to Do Right Now if You Think You Might Be Affected

Thomson Reuters is offering 12 months of free credit monitoring to potentially affected individuals: Experian IdentityWorks in the United States and the US Virgin Islands, and TransUnion myTrueIdentity in Canada. Enrollment is open until December 31, 2026, using the multi-use code and engagement number printed in the personal notification letters mailed by Thomson Reuters. A US hotline is available at 1-833-918-5294 (engagement number B171847).

Beyond enrolling in the free monitoring, the standard advice applies. Freeze your credit rather than only monitor it, because a freeze actually stops a new account from being opened while monitoring only tells you after the fact. Watch closely for phishing emails and text messages that reference the breach, because criminals reading the same news you are will already be drafting fake “court notification” or “credit monitoring signup” pages within days. And plan for what happens after December 31, 2026, when the free monitoring ends. Data that has been dumped once often keeps circulating for years.

Get NordVPN with Dark Web Monitor

Where NordVPN Fits in the Picture

Let’s be direct about what a VPN can and can’t do here. NordVPN could not have prevented the C-Track breach. The intrusion took place inside Thomson Reuters’ own cloud infrastructure, and your data was in those files long before you had any choice about it. What NordVPN does, and what makes it relevant in the aftermath of a breach like this one, sits on the other side of the timeline: monitoring what happens to your data once it leaves the vendor’s servers.

The Dark Web Monitor feature, included in NordVPN’s Advanced and Ultra plans, continuously scans leaked databases and cybercriminal forums for your personal information. If your email address, credentials, or identifiers appear in a new dump, you get an alert with details on which service was involved. That is exactly the kind of ongoing coverage you’ll want once the free 12-month credit monitoring window from Thomson Reuters closes. Threat Protection Pro, included in the same tiers, blocks phishing sites at the network level, which cuts down on the fake “credit monitoring signup” and “court notification” pages that will inevitably appear in the coming weeks.

Get NordVPN with full protection

The Basic Plan at $3.49/Month

NordVPN’s Basic plan is currently available at $3.49/month, which works out to $94.23 billed once for 27 months of service (24 + 3 free). That’s a 69% discount off the standard rate. Annual renewal continues at $139.08/year, cancelable from the account dashboard at any time.

The Basic plan covers the core VPN across up to 10 devices with applications for Windows, macOS, Linux, iOS, Android, browser extensions, and router installation. Dark Web Monitor and Threat Protection Pro, the two features most directly relevant to what happens after a breach like this one, sit in the Advanced and Ultra tiers.

Get NordVPN Basic at $3.49/month

30 Days to Test Everything, No Strings Attached

NordVPN backs every plan with a 30-day money-back guarantee. If the service doesn’t fit the way you use your devices, you can request a full refund within the first month. Refunds are processed through 24/7 chat support, and funds typically return within 5 to 10 business days depending on the payment method used.

That gives you a full month to install the apps across your setup, test the speeds on your home connection, run the phishing filter and dark web monitor against the traffic hitting your inbox in the wake of this breach, and see whether the service fits your workflow. A note on the subscription: the $3.49/month rate applies to the first 27 months. Auto-renewal then kicks in at the standard annual rate. If you would rather cancel or renegotiate before renewal, set a reminder in your calendar 7 to 10 days before the renewal date.

Share this story

Sign up for our newsletters

Subscribe and interact with our community, get up to date with our customised Newsletters and much more.