A Thomson Reuters unit has disclosed a cybersecurity incident involving its C-Track case management platform across 11 US states, the US Virgin Islands and Canada. The company detected the incident on June 30 and later found that an unauthorized party had obtained certain C-Track files in March.
C-Track is used by courts to manage digital case records and related information. Thomson Reuters said some affected files contained court records with names and other personal information.
West Publishing, a Thomson Reuters unit, established a website with information about the incident. It identified affected court systems in Alabama, Pennsylvania, Kentucky and Montana, along with Nevada and North Dakota.
South Carolina, Tennessee and Ohio were also listed. New Hampshire, Wyoming and the US Virgin Islands completed the group of US jurisdictions identified by the company.
Canadian courts were affected as well. The chief justices of the Court of Appeal for Ontario, Ontario Superior Court of Justice and Ontario Court of Justice said Thomson Reuters detected unauthorized activity inside one of its cloud environments.
The company worked with Ontario’s Ministry of the Attorney General and the courts after identifying the activity. According to the chief justices, Thomson Reuters took steps to contain the incident and secure the C-Track environment.
External cybersecurity specialists were brought in to support the investigation. Thomson Reuters also notified law enforcement and implemented additional security measures following the discovery.
We are advised that Thomson Reuters responded by taking steps to contain the activity, engaging external cybersecurity experts to advise and investigate, notifying law enforcement, and securing the C-Track environment.
the Ontario chief justices
Toronto-based Thomson Reuters confirmed that affected customers have been notified. The company said its investigation found no operational disruption to C-Track following the incident.
“There has been no operational disruption to C-Track as a result of this incident,” a Thomson Reuters spokesperson said. The company added that its products and services remain operational and available for continued use.
Independent cybersecurity specialists also reviewed the remediation work. Thomson Reuters said those experts validated the measures implemented after the incident.
The exact scope of exposed information remains unclear. Ontario’s chief justices said people involved in court proceedings, or individuals named in court documents, could have had personal information involved.
Thomson Reuters has said affected court records included names and personal information, though it hasn’t publicly detailed every data category involved. The number of individuals whose information was affected also hasn’t been disclosed.
The source of the cyberattack remains unknown publicly. Reuters couldn’t independently determine who carried out the incident or establish the specific information obtained by the unauthorized party.
Reuters News operates as a division of Thomson Reuters. Reporting on the incident therefore involved a breach affecting another business within the same corporate group.
Thomson Reuters Canada plans to respond directly to questions from people concerned about the incident. The Ontario chief justices said the company would establish a call center beginning September 4.
A Thomson Reuters spokesperson confirmed that the company is handling inquiries in both the US and Canada. A dedicated contact center will provide additional information to people seeking details about whether their records were involved.









