2 Remove Virus

Thomson Reuters C-Track breach affects court systems across US and Canada

Thomson Reuters has disclosed a cybersecurity incident involving its C-Track court management platform after an unauthorized party obtained files containing information connected to court proceedings.

 

 

The company detected suspicious activity on June 30th, but its subsequent investigation determined that an unauthorized party had acquired certain C-Track files months earlier, in March. The incident affected court systems across 11 US states, the US Virgin Islands and Ontario, Canada.

C-Track is a digital court case management system developed by Thomson Reuters. Courts use the platform to manage case information, documents, and other records associated with judicial proceedings.

Affected US jurisdictions include Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, and Wyoming. Court systems in the US Virgin Islands were also involved.

In Canada, the incident affected Ontario courts that use C-Track for digital court record management. The chief justices of the Court of Appeal for Ontario, Ontario Superior Court of Justice and Ontario Court of Justice issued a joint statement about the breach.

Thomson Reuters determined that some affected court records contained names and other personal information. However, the company has not provided a detailed breakdown of the compromised information or disclosed how many individuals may have been affected.

Ontario court officials similarly said the precise information involved remains unclear. People participating in court proceedings, as well as individuals mentioned within court documents, may have had personal information included in the affected files.

After discovering the unauthorized activity, Thomson Reuters took steps to contain the incident and secure the C-Track environment. External cybersecurity specialists were brought in to assist with the investigation, and law enforcement was notified.

The company has also contacted customers affected by the breach. In Ontario, Thomson Reuters worked with the Ministry of the Attorney General and the courts while responding to the incident.

Despite the unauthorized access, Thomson Reuters says C-Track remained operational throughout the response. The company reported no service disruption and said independent security experts reviewed the remediation measures introduced following the breach.

The identity of the attacker remains unknown. Thomson Reuters has not publicly attributed the intrusion to a particular cybercriminal group, and there has been no confirmed explanation of how the unauthorized party initially gained access to the affected cloud environment.

The company is establishing support channels for people seeking additional information. A contact center for inquiries related to the Canadian incident is scheduled to become active on September 4th, while Thomson Reuters is also responding to inquiries from affected parties in the United States.