Skip to content

The Edge of the Cyber World See the latest

Apps

NH Court Breach: 13 Years of Case Files Exposed [2026]

New Hampshire’s highest court has confirmed that a stranger had access to more than a decade of case records before anyone noticed. The state’s Judicial Branch says names and addresses tied to cases filed between 2002 and 2015 sat exposed inside a vendor-run system for roughly three months this year, part of a wider breach that Thomson Reuters subsidiary West Publishing disclosed on September 3, 2026. New Hampshire is one of at least 11 U.S. states, the U.S. Virgin Islands, and three courts in Ontario, Canada caught up in the incident, according to reporting from The Hacker News and Help Net Security.

The breach did not touch New Hampshire’s own judicial computer systems. It touched C-Track, a case-management platform built and hosted by West Publishing, and used by dozens of courts nationwide to track filings, dockets, and case status. That distinction matters for how courts, vendors, and the public should read this incident, and it is the part of the story that has gotten the least attention outside New Hampshire itself.

What New Hampshire’s Judicial Branch Says It Found

According to reporting by New Hampshire Public Radio and the Concord Monitor, West Publishing told the state’s Judicial Branch in July 2026 that New Hampshire data had been part of the unauthorized access. The state received the actual breached files for review in mid-August, and after going through them, officials said the exposed material was limited to names and addresses of people connected to cases filed between 2002 and 2015.

The Judicial Branch’s information technology team told NHPR: “The Judicial Branch’s information technology team is continuing to review the New Hampshire data to confirm that access was limited to what West Publishing disclosed, but at this point we have no indication that any sensitive personal information from New Hampshire was accessed.” That is a narrower exposure than what other jurisdictions in the same breach have reported, and New Hampshire officials have been careful to draw that line.

Unlike some of the other affected jurisdictions, New Hampshire has so far found no evidence that Social Security numbers, driver’s license numbers, dates of birth, or medical information tied to its cases were part of the exposure. Whether that holds up after West Publishing’s fuller forensic review wraps up is still an open question, and it is one the state’s court system says it is still working through.

Why a Court Vendor, Not the Court, Got Hacked

C-Track is not part of New Hampshire’s internal network. It is a hosted product sold by West Publishing, a Thomson Reuters subsidiary, to state and provincial court systems that don’t want to build and maintain their own case-management software. New Hampshire’s Judicial Branch has stated that the breached data was stored in a system owned by the software company and was separate from the branch’s own systems and networks, which is why the courthouse itself never went dark and case processing was not disrupted.

That third-party structure is exactly why this incident is worth more scrutiny than a typical single-agency breach. When a court outsources docket management to a vendor, it also outsources a slice of its security posture to that vendor’s engineering and monitoring practices. New Hampshire didn’t choose when West Publishing’s systems got probed, when the intrusion was caught, or how long the investigation would take before the state even learned its own residents’ records were involved. That lag is now a running theme across 2026’s biggest breaches, and it is one worth comparing against other vendor-side incidents this site has already covered, including the breach at Thomson Reuters’ C-Track platform affecting all 11 states.

Timeline: From a March Intrusion to a September Disclosure

The gap between when the intrusion started and when the public found out is one of the more striking parts of this story. Based on West Publishing’s own disclosure and subsequent reporting, the unauthorized access began in March 2026 and ran undetected for roughly three months.

Date Event
March 2026 Unauthorized access to West Publishing’s C-Track platform begins, per company disclosure
June 30, 2026 West Publishing discovers the unauthorized access
July 2026 West Publishing informs New Hampshire’s Judicial Branch that state data was among the files accessed
Mid-August 2026 New Hampshire Judicial Branch receives the breached files and begins its own review
September 3, 2026 Thomson Reuters/West Publishing issues public disclosure; NHPR and other outlets report on New Hampshire’s exposure
September 4-5, 2026 Concord Monitor, Valley News, and the Union Leader publish follow-up coverage confirming Montana and other states are affected
December 31, 2026 Deadline for affected individuals to enroll in the credit monitoring offered by Thomson Reuters

Five months passed between the start of the intrusion and the first public word of it, and New Hampshire residents specifically waited even longer, since the state didn’t get confirmation its own data was involved until July, a full month after West Publishing caught the breach. For a case-management system holding decades of court filings, that is a long window for anyone with access to move, copy, or sell records before defenders even knew to look.

The Multistate Scope: 11 States, Canada, and the Virgin Islands

New Hampshire is far from alone. Help Net Security and The Hacker News both report that the exposure spans court systems in 11 U.S. states, the U.S. Virgin Islands, and three courts in Ontario, Canada. The Union Leader separately confirmed that Montana’s Supreme Court joined New Hampshire on the list of confirmed jurisdictions, and North Dakota’s court system posted its own public notice describing the incident as a “C-Track Data Incident.”

Jurisdiction Confirmation Status What Was Found (as publicly reported)
New Hampshire Confirmed by NH Judicial Branch Names and addresses tied to cases filed 2002-2015; no SSNs or medical data identified so far
Montana Confirmed via state Supreme Court statement Not individually itemized in public reporting as of Sept 9, 2026
North Dakota Confirmed via court system’s own incident notice Court has posted a dedicated public notice; details under review
Remaining ~8 U.S. states, U.S. Virgin Islands, 3 Ontario, Canada courts Included in West Publishing’s overall disclosure Not individually named in public reporting reviewed for this article; broader disclosures reference possible exposure of Social Security numbers, driver’s license numbers, dates of birth, medical and health insurance information, and sealed filings in some jurisdictions

That last row matters because it shows how uneven the disclosure has been. Some states, like New Hampshire, have published detailed findings about exactly what was and wasn’t exposed. Others have said far less publicly, which leaves residents in those jurisdictions with less to go on than New Hampshire’s own case files review provided.

New Hampshire’s Own Breach Notification Law Now Applies

New Hampshire has had a data breach notification statute on the books for years, RSA 359-C:20, which requires organizations that own or license personal information to notify affected state residents following unauthorized acquisition of that data. The state’s Department of Justice maintains a public breach notification log where companies disclosing incidents involving New Hampshire residents are required to file. Whether West Publishing’s disclosure triggers a formal filing tied specifically to New Hampshire residents, separate from its broader multistate notice, is something state officials are still sorting through as their review of the C-Track files continues.

This is a useful reminder that “the court got breached” is a legally different event from “a state resident’s personal data was breached.” New Hampshire’s own statute is written around the latter, and the Judicial Branch’s public statements so far have been careful to stick to what it can verify about New Hampshire residents specifically, rather than repeating the broader, more alarming language used to describe the incident in other states.

Thomson Reuters’ Response: Credit Monitoring and an Outside Investigation

Thomson Reuters says it has brought in outside cybersecurity investigators and coordinated with law enforcement since discovering the intrusion. For individuals whose information was confirmed exposed, the company is offering 12 months of Experian IdentityWorks credit monitoring, with enrollment open through December 31, 2026, using a multi-use code published in its breach notice. Affected individuals with questions have been directed to a dedicated hotline, which requires an engagement number tied to the incident to access details.

Thomson Reuters has said there is no evidence to date of fraud or misuse connected to the exposed data. That is a common early-stage statement in breach disclosures, and it is worth noting it describes the absence of confirmed misuse rather than a guarantee that misuse won’t eventually surface, since stolen records often take months or years to show up in fraud cases or on dark web marketplaces.

The Litigation Risk Building Around West Publishing

Data breach law firms have already begun soliciting affected individuals for potential claims, a pattern that shows up almost immediately after any large-scale disclosure involving Social Security numbers or sealed court records. Aardwolf Security’s reporting on the incident noted that sealed court filings, records typically shielded from public view by a judge’s order, may have been exposed for months before anyone caught the intrusion, which raises the legal stakes well beyond a typical names-and-addresses leak.

New Hampshire’s narrower confirmed exposure, names and addresses only, so far, gives it a comparatively weaker basis for individual claims than states where sealed filings or Social Security numbers were confirmed. But that could change once West Publishing’s full forensic review of New Hampshire’s files is complete, and the state’s own IT team has been explicit that its review is ongoing rather than finished.

How This Compares to Other 2026 Data Breaches Hitting Sensitive Records

Court records sit in an unusual category of sensitive data: they are partly public by design, since most filings are open records, but they also routinely include sealed materials, minors’ names, and financial details that were never meant for broad circulation. That mixed sensitivity makes the C-Track breach harder to compare directly to a straightforward healthcare or financial breach, but the scale and vendor-side nature of the incident put it in the same conversation as this year’s other major third-party breaches.

Incident Sector Records/Scope Root Cause Type
Thomson Reuters / C-Track (NH and 10+ other jurisdictions) Judiciary / court records 11 U.S. states, U.S. Virgin Islands, 3 Ontario courts Third-party vendor platform breach
McKesson breach Healthcare distribution Reported in the hundreds of millions of records Ransomware-linked extortion demand
MCNA Dental settlement Dental/healthcare 8.9 million individuals Prior-year breach reaching settlement in 2026
DaVita settlement Healthcare/dialysis 2.4 million patients Prior-year breach reaching settlement in 2026

What separates the C-Track incident from those healthcare cases is the involvement of the judiciary itself. Court systems carry unique institutional trust: people expect that when their name appears in a court filing, that record is controlled by the court, not sitting in a third-party company’s infrastructure they’ve never heard of. This breach is a reminder that a large share of state court data actually lives with private vendors like West Publishing, not with the courts themselves.

Market and Reputational Impact for Thomson Reuters

Thomson Reuters is a large, diversified information and legal-services company, and West Publishing is one of its core legal-data businesses, best known outside the legal industry for owning Westlaw. A breach touching a dozen government court customers is a reputational problem for a company whose entire pitch to courts and law firms is that it can be trusted to securely hold sensitive legal data at scale. Multiple state court systems now have to explain to their own residents why a private vendor, not the court, controlled data that ended up exposed, and that dynamic could shape how courts negotiate future vendor contracts, security audit requirements, and data residency terms with West Publishing and its competitors.

For New Hampshire specifically, the reputational exposure is smaller than for states where sealed records or Social Security numbers were confirmed exposed. But the state’s own review is not finished, and any revision to its current “names and addresses only” finding would change that calculus quickly.

Historical Context: Judiciary Systems as a Soft Target

Court IT systems have long been considered under-resourced relative to the sensitivity of what they hold. State judicial branches typically operate on budgets set by legislatures focused on courtroom operations, not cybersecurity, and many rely on decades-old case-management software or, as in New Hampshire’s case, outsource that function entirely to a commercial vendor. That outsourcing decision made sense operationally, courts get modern docket software without building it themselves, but it also concentrates risk: a single vendor breach can now touch a dozen unrelated state court systems at once, rather than requiring an attacker to compromise each state individually.

This incident fits a broader pattern this site has tracked through 2026, in which breaches at shared vendors and platforms, rather than breaches of any single victim organization’s own network, account for a growing share of the year’s largest disclosures, from healthcare claims processors to identity verification vendors.

What This Means for Other State Court Systems

New Hampshire’s situation offers a template other affected states may follow: get the vendor’s files directly, run an independent internal review rather than taking the vendor’s word for what was exposed, and communicate specifically about what was and wasn’t confirmed for residents of that state, rather than repeating the vendor’s broader multistate language. That approach produced a narrower, more defensible public statement than a state that simply forwarded West Publishing’s disclosure without its own review.

It also raises a procurement question every state court system now has to answer: how much visibility does the state actually have into a vendor’s security practices before a contract is signed, and does that contract require the vendor to notify the state within a set number of days of any confirmed intrusion, rather than the months-long gap seen here.

Predictions: Where This Breach Goes From Here

  • West Publishing’s fuller forensic report will likely prompt several affected states, potentially including New Hampshire, to revise their initial findings as review work continues into the fourth quarter of 2026.
  • Data breach law firms will keep building consolidated claims against Thomson Reuters/West Publishing, with the strength of any New Hampshire-specific claim depending heavily on whether the state’s “names and addresses only” finding holds.
  • Other state court systems using C-Track or similar third-party case-management platforms will face pressure from state legislatures to review vendor security requirements and breach-notification timelines in upcoming budget or procurement cycles.
  • Expect renewed scrutiny of how quickly vendors like West Publishing are contractually required to notify government customers after detecting an intrusion, given the roughly three-month gap between detection and New Hampshire’s own notification.
  • Thomson Reuters will likely face continued media and regulatory questions in the coming months as more states complete their own reviews and either confirm or rule out exposure of more sensitive categories of data, such as Social Security numbers or sealed filings.

What New Hampshire Residents Should Do Now

Anyone who was party to a New Hampshire court case filed between 2002 and 2015 should watch for direct notice from either the state Judicial Branch or Thomson Reuters, since that is the population the state has identified as potentially affected so far. Beyond that, the standard breach-response steps apply: monitor bank and credit card statements for unfamiliar activity, consider a credit freeze with the major bureaus if eligible for the offered monitoring, and treat any unsolicited calls or emails referencing the breach with caution, since breach disclosures like this one are frequently followed by phishing attempts that impersonate the company offering the credit monitoring.

New Hampshire’s own review is not finished. Residents with older case filings, particularly those involving family court, criminal, or otherwise sensitive matters from the 2002-2015 window, may want to watch for updates directly from the Judicial Branch rather than assuming the current “names and addresses only” finding is final.

Frequently Asked Questions

Was the New Hampshire Supreme Court itself hacked?

No. The New Hampshire Judicial Branch has said the breach occurred inside C-Track, a case-management system owned and operated by West Publishing, a Thomson Reuters subsidiary, that is separate from the Judicial Branch’s own internal systems and networks.

What New Hampshire data was exposed?

Based on the state’s review of the breached files in August 2026, the exposed New Hampshire data consists of names and addresses of individuals involved in cases filed between 2002 and 2015. The state has said it has no current indication that Social Security numbers or other sensitive personal information tied to New Hampshire were accessed.

When did the breach happen and when was it discovered?

The unauthorized access began in March 2026 and was discovered by West Publishing on June 30, 2026, roughly three months later. New Hampshire’s Judicial Branch was told its data was involved in July 2026 and received the actual files for review in mid-August 2026.

Which other states and jurisdictions were affected?

The breach spans court systems in 11 U.S. states, the U.S. Virgin Islands, and three courts in Ontario, Canada, according to Help Net Security and The Hacker News. Montana and North Dakota have publicly confirmed their inclusion alongside New Hampshire; most of the remaining affected jurisdictions have not been individually named in public reporting as of this writing.

Is Thomson Reuters offering any compensation or protection to affected people?

Thomson Reuters is offering 12 months of Experian IdentityWorks credit monitoring to confirmed affected individuals, with enrollment open through December 31, 2026, via a multi-use code included in its breach notice, along with a dedicated support hotline.

Does New Hampshire have its own data breach notification law?

Yes. New Hampshire’s RSA 359-C:20 requires organizations that own or license personal information to notify affected New Hampshire residents following unauthorized acquisition of that data, and the state Department of Justice maintains a public log of filed breach notifications.

Could sealed court records have been exposed?

Reporting on the broader breach, including coverage from Aardwolf Security, has indicated that sealed filings in some affected jurisdictions may have been accessible during the intrusion. New Hampshire’s own review, as of its current public statements, has not identified sealed-record exposure specific to its own case files.

Is there evidence the exposed data has been misused?

Thomson Reuters has said there is no evidence to date of fraud or misuse connected to the exposed data. That statement reflects the absence of confirmed misuse rather than a guarantee, since stolen records from breaches often surface in fraud cases well after initial disclosure.

Related Coverage

Source: Tech Insider