Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 8 sources · 8 days · First seen · Last updated
Thomson Reuters C-Track data breach
Overview
Thomson Reuters disclosed a cybersecurity incident involving its C-Track case management platform, which affected court systems across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. An investigation determined that an unauthorized party accessed certain C-Track and E-Filing backup files between March 1 and June 29.
While much of the compromised data consisted of publicly available court docket information, some files contained personally identifiable information (PII), such as names, dates of birth, and driver's license numbers. Thomson Reuters reported that the breach originated on its own storage servers and was detected on June 30. The company implemented containment measures and engaged external cybersecurity experts.
Ontario’s chief justices later confirmed the province’s court system was impacted, noting that while the exact content of accessed files remains uncertain, personal information of individuals involved in court proceedings may have been compromised. As of the latest reports, there is no evidence of identity theft or impact on financial transaction systems, and Thomson Reuters has implemented additional security enhancements.
Entities
ENISA · Michael H. Tulloch · Thomson Reuters Canada · Thomson Reuters · European Union
Claims
What the coverage asserts, and how many sources carry each claim.
- [○ 1 SOURCE] The Ontario court system was affected by a data breach involving unauthorized activity on the Thomson Reuters Canada C–Track case management platform. globalnews.ca
- [○ 1 SOURCE] Thomson Reuters Canada detected the unauthorized activity on its C–Track platform on June 30. globalnews.ca
- [○ 1 SOURCE] There is currently no evidence that the data breach has resulted in identity theft. globalnews.ca
- [○ 1 SOURCE] Financial transaction processing systems used for court proceedings were not affected by the incident. globalnews.ca
- [○ 1 SOURCE] As of September 11, 2026, manufacturers of products with digital elements must comply with mandatory reporting for actively exploited vulnerabilities and severe security incidents under the Cyber Resi www.iotsecurityfoundation.org
- [○ 1 SOURCE] Manufacturers must provide an initial notification of an actively exploited vulnerability within 24 hours of becoming aware of it. www.iotsecurityfoundation.org
- [○ 1 SOURCE] A detailed vulnerability notification must be submitted within 72 hours following the initial report. www.iotsecurityfoundation.org
- [○ 1 SOURCE] A final report regarding corrective or mitigating measures is required no later than 14 days after such measures become available. www.iotsecurityfoundation.org
Timeline
-
about 15 hours ago
[TECHNOLOGY] 3 sourcesOntario courts report data breach as EU enforces new cyber reporting rulesOntario courts report a data breach via the Thomson Reuters C–Track platform, while the EU's Cyber Resilience Act begins enforcing mandatory vulnerability reporting for digital product manufacturers.
-
8 days ago
[TECHNOLOGY] 6 sourcesThomson Reuters reports data breach affecting court recordsA cybersecurity breach at Thomson Reuters' C-Track platform exposed court records and personal data across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada.
Sources
channel12.ca · china.timesofnews.com · claimsjournal.com · cybernoz.com · iotsecurityfoundation.org · itnerd.blog · technadu.com · thehackernews.com