started · updated
Ontario courts report data breach as EU enforces new cyber reporting rules
Ontario’s chief justices have announced that the province’s court system was impacted by a data breach. The incident occurred on June 30 when Thomson Reuters Canada detected unauthorized activity on its C–Track case management platform, which is used to store and manage various court documents and records.
While the exact content of the accessed files remains uncertain, officials noted that personal information of individuals involved in court proceedings may have been compromised. However, there is currently no evidence of identity theft or any impact on systems used for financial transactions. Thomson Reuters has implemented additional security enhancements, and the investigation is ongoing.
In Europe, a significant regulatory milestone was reached on September 11, 2026, with the implementation of the Cyber Resilience Act (CRA). The act introduces mandatory reporting obligations for manufacturers of digital products regarding actively exploited vulnerabilities and severe security incidents. Under the new rules, manufacturers must notify ENISA and relevant CSIRTs within 24 hours of discovering an exploit, followed by a detailed report within 72 hours and a final report within 14 days of implementing corrective measures.
Entities
ENISA · European Union · Michael H. Tulloch · Ontario Courts · Thomson Reuters Canada
Claims
What the coverage asserts, and how many sources carry each claim.
- [○ 1 SOURCE] A detailed vulnerability notification must be submitted within 72 hours following the initial report. www.iotsecurityfoundation.org
- [○ 1 SOURCE] The Ontario court system was affected by a data breach involving unauthorized activity on the Thomson Reuters Canada C–Track case management platform. globalnews.ca
- [○ 1 SOURCE] Financial transaction processing systems used for court proceedings were not affected by the incident. globalnews.ca
- [○ 1 SOURCE] As of September 11, 2026, manufacturers of products with digital elements must comply with mandatory reporting for actively exploited vulnerabilities and severe security incidents under the Cyber Resi www.iotsecurityfoundation.org
- [○ 1 SOURCE] Thomson Reuters Canada detected the unauthorized activity on its C–Track platform on June 30. globalnews.ca
- [○ 1 SOURCE] There is currently no evidence that the data breach has resulted in identity theft. globalnews.ca
- [○ 1 SOURCE] Manufacturers must provide an initial notification of an actively exploited vulnerability within 24 hours of becoming aware of it. www.iotsecurityfoundation.org
- [○ 1 SOURCE] A final report regarding corrective or mitigating measures is required no later than 14 days after such measures become available. www.iotsecurityfoundation.org