Kentucky Appellate Court data stolen in vendor breach

Published September 3, 2026

Someone broke into a cloud system run by Thomson Reuters and copied court case files from its C-Track platform. Kentucky's Appellate Courts had case data stored there, so some of that data was taken along with records from courts in other states and Canada.

Report priority
Medium
Involves
C-Track

What is known

An unauthorized party got into a Thomson Reuters cloud environment that stores C-Track data and copied files out of it, and the intrusion ran undetected from March 2026 until Thomson Reuters spotted it on June 30, 2026.

What to do

Check if your case was handled by Kentucky's appellate courts between 2016 and 2023. If so, monitor your email and credit reports for signs of stolen data, and consider freezing your credit if you're concerned.

Reported details

Thomson Reuters stores C-Track case files, including Kentucky's appellate court records, in a cloud environment. An unauthorized party gets into that environment in March 2026 and copies out files from courts in multiple states and Ontario, Canada. Thomson Reuters does not notice the intrusion until June 30, 2026, and then works with outside investigators to confirm what was taken.

Thomson Reuters (via West Publishing, doing business as Thomson Reuters Court Management Solutions) detected unauthorized activity in a cloud environment hosting C-Track on June 30, 2026, and determined the access began in March 2026. The exposed files came from courts in about eleven US states plus Ontario, Canada; Kentucky's exposure is limited to Appellate Court data. In Montana's disclosure of the same incident, reviewers found some driver's license numbers and dates of birth mixed in with otherwise public court records. C-Track itself stayed operational throughout, and no group has claimed the data or threatened to leak it as of this writing.