Massive Court Data Breach Hits New Hampshire, Exposing Sensitive Personal Records

Context mode is active. Hover over any highlighted term to see its definition. Click a nested term to go deeper.
The New Hampshire Supreme Court is among at least 12 U.S. states and Canadian judicial systems reeling from a major cybersecurity breach. The incident, linked to Thomson Reuters' C-Track court case management platform, led to an unauthorized party accessing files containing sensitive personal information, including names and potentially Social Security numbers and medical details. This widespread data exposure highlights the growing risks faced by government entities relying on third-party technology vendors. Investigators found that files from the C-Track platform were accessed in March 2026, with the breach only detected on June 30, 2026, and publicly disclosed on September 2, 2026. While the New Hampshire Supreme Court confirmed exposure of case data from 2002 to 2015, more alarming is the potential compromise of highly confidential data like driver's license numbers, dates of birth, and health insurance information across multiple affected courts. Thomson Reuters, through its subsidiary West Publishing Corporation, confirmed that the breach occurred within its cloud environment, not the courts' direct systems, underscoring the critical importance of vendor security. Thomson Reuters has engaged external cybersecurity experts and notified law enforcement, assuring that C-Track operations remain uninterrupted and secure. The company is providing affected individuals with 12 months of complimentary credit monitoring and identity theft protection services. However, the full extent of the compromised data and the long-term implications for individuals whose deeply personal legal records are now exposed are still unfolding, urging vigilance from anyone involved in court proceedings across the impacted jurisdictions.