# Thomson Reuters C-Track data breach

> Live situation record from CLSTR: https://clstr.news/situations/thomson-reuters-c-track-data-breach
> Updated: 2026-09-10T23:55:02.000Z. Sources: 8. Developments: 2.

Thomson Reuters disclosed a cybersecurity incident involving its C-Track case management platform, which affected court systems across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. An investigation determined that an unauthorized party accessed certain C-Track and E-Filing backup files between March 1 and June 29.

While much of the compromised data consisted of publicly available court docket information, some files contained personally identifiable information (PII), such as names, dates of birth, and driver's license numbers. Thomson Reuters reported that the breach originated on its own storage servers and was detected on June 30. The company implemented containment measures and engaged external cybersecurity experts.

Ontario’s chief justices later confirmed the province’s court system was impacted, noting that while the exact content of accessed files remains uncertain, personal information of individuals involved in court proceedings may have been compromised. As of the latest reports, there is no evidence of identity theft or impact on financial transaction systems, and Thomson Reuters has implemented additional security enhancements.

## Claims

- The Ontario court system was affected by a data breach involving unauthorized activity on the Thomson Reuters Canada C–Track case management platform. (single source)
- Thomson Reuters Canada detected the unauthorized activity on its C–Track platform on June 30. (single source)
- There is currently no evidence that the data breach has resulted in identity theft. (single source)
- Financial transaction processing systems used for court proceedings were not affected by the incident. (single source)
- As of September 11, 2026, manufacturers of products with digital elements must comply with mandatory reporting for actively exploited vulnerabilities and severe security incidents under the Cyber Resi (single source)
- Manufacturers must provide an initial notification of an actively exploited vulnerability within 24 hours of becoming aware of it. (single source)
- A detailed vulnerability notification must be submitted within 72 hours following the initial report. (single source)
- A final report regarding corrective or mitigating measures is required no later than 14 days after such measures become available. (single source)

## Timeline

### 2026-09-10: Ontario courts report data breach as EU enforces new cyber reporting rules

Ontario courts report a data breach via the Thomson Reuters C–Track platform, while the EU's Cyber Resilience Act begins enforcing mandatory vulnerability reporting for digital product manufacturers.

3 sources. https://clstr.news/cluster/ontario-courts-report-data-breach-as-eu-enforces-new-cyber-reporting-rules

### 2026-09-03: Thomson Reuters reports data breach affecting court records

A cybersecurity breach at Thomson Reuters' C-Track platform exposed court records and personal data across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada.

6 sources. https://clstr.news/cluster/thomson-reuters-reports-data-breach-affecting-court-records

---
Cite as: Thomson Reuters C-Track data breach. CLSTR, https://clstr.news/situations/thomson-reuters-c-track-data-breach
