< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 8 sources · 8 days · First seen · Last updated

Thomson Reuters C-Track data breach

Overview

Thomson Reuters disclosed a cybersecurity incident involving its C-Track case management platform, which affected court systems across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. An investigation determined that an unauthorized party accessed certain C-Track and E-Filing backup files between March 1 and June 29.

While much of the compromised data consisted of publicly available court docket information, some files contained personally identifiable information (PII), such as names, dates of birth, and driver's license numbers. Thomson Reuters reported that the breach originated on its own storage servers and was detected on June 30. The company implemented containment measures and engaged external cybersecurity experts.

Ontario’s chief justices later confirmed the province’s court system was impacted, noting that while the exact content of accessed files remains uncertain, personal information of individuals involved in court proceedings may have been compromised. As of the latest reports, there is no evidence of identity theft or impact on financial transaction systems, and Thomson Reuters has implemented additional security enhancements.

Entities

ENISA · Michael H. Tulloch · Thomson Reuters Canada · Thomson Reuters · European Union

Claims

What the coverage asserts, and how many sources carry each claim.

Timeline

  1. about 15 hours ago

    [TECHNOLOGY] 3 sources
    Ontario courts report data breach as EU enforces new cyber reporting rules

    Ontario courts report a data breach via the Thomson Reuters C–Track platform, while the EU's Cyber Resilience Act begins enforcing mandatory vulnerability reporting for digital product manufacturers.

  2. 8 days ago

    [TECHNOLOGY] 6 sources
    Thomson Reuters reports data breach affecting court records

    A cybersecurity breach at Thomson Reuters' C-Track platform exposed court records and personal data across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada.

Sources

channel12.ca · china.timesofnews.com · claimsjournal.com · cybernoz.com · iotsecurityfoundation.org · itnerd.blog · technadu.com · thehackernews.com