Thomson Reuters has reported a cybersecurity breach affecting its C-Track court management software, leading to the exposure of sensitive case data in Canada and the United States. The breach, detected on June 30, involved unauthorized access to files associated with three Ontario courts: the Court of Appeal for Ontario, the Ontario Superior Court of Justice, and the Ontario Court of Justice. This breach may have exposed personal information and confidential court records, including names, Social Security numbers, driver's licenses, and health data.
In addition to the Ontario courts, the breach has impacted appellate courts in 11 US states and the US Virgin Islands. These include states such as South Carolina, Nevada, and Ohio. The compromised data potentially includes sensitive personal records, and although the investigation is ongoing, there is no evidence yet that the data has been misused. Thomson Reuters has assured that the breach did not affect systems used for financial transactions and was not due to any vulnerabilities in the courts' networks or data security.
The breach underscores the need for heightened cybersecurity measures in the management of court documents. As cyber threats continue to evolve, court records remain a significant target for various threat actors, including those motivated by financial gain or espionage. In response to similar threats, the US federal judiciary has previously announced enhanced protections for sensitive court documents.


