Zero Day Room
Live
Defence

Thomson Reuters breach exposes US and Canadian court data

A breach of Thomson Reuters' C-Track court management platform exposed sealed records and personal data from courts in at least 12 U.S. States, the U.S.

A breach of Thomson Reuters' C-Track court management platform exposed sealed records and personal data from courts in at...

A breach at Thomson Reuters has exposed sealed court information and sensitive personal data from judicial systems across the United States and Canada. The company publicly disclosed the incident on Wednesday, revealing that an unauthorized party obtained files from its C-Track court case management platform in March, with access potentially lasting until discovery in late June.

Thomson Reuters has not disclosed how the attacker gained access, who was responsible, or the total volume of data taken. The number of affected individuals also remains unclear. The company stressed that the breach occurred within its own environment and was not caused by any failure in the networks, systems, or data security of the impacted courts themselves.

Scope of the breach

The breach involved C-Track, a platform operated by a Thomson Reuters subsidiary. According to the company, the compromised data may have included names, Social Security numbers, driver's license numbers, medical information, dates of birth, and health insurance information. Confidential, redacted, or sealed court information may also have been affected at some locations. Thomson Reuters stated there is no current evidence that the exposed information has been used for fraud.

Court systems identified in the company's U.S. Notification include appellate courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, South Carolina, Tennessee, and Wyoming. The notice also names several Pennsylvania courts, 10 Ohio district courts of appeals, and the U.S. Virgin Islands Supreme Court and Superior Court.

Other judicial bodies have separately confirmed their involvement. The Oregon Judicial Department said its appellate courts were part of the breach, bringing the known tally of affected states to at least 12. In a separate disclosure, Montana’s Supreme Court said Thomson Reuters informed state officials that the unauthorized access spanned from March through June.

Varied data exposure

The nature of the exposed data appears to differ by jurisdiction. Nevada officials cautioned against assuming that information exposed in one state was also exposed elsewhere, noting the type of data involved varies. In Montana, state officials indicated that most of the affected information seemed to be already publicly available, though some driver's license numbers and dates of birth were also involved.

Some court administrators were notified weeks after Thomson Reuters discovered the unauthorized activity on June 30. The company told Montana’s court administrator and Ontario’s Ministry of the Attorney General on July 23 that court data had been accessed. In a joint statement, the chief justices of Ontario's Court of Appeal, Superior Court of Justice, and Ontario Court of Justice said it remained unclear exactly what information was compromised or how many people were affected.

Response and remediation

Thomson Reuters said the breach did not disrupt C-Track services and that the platform remains fully operational. The company stated it has implemented new security measures, which were reviewed and approved by outside cybersecurity experts. It did not identify those experts. As part of its response, Thomson Reuters is offering affected individuals 12 months of free credit monitoring and identity theft protection.

The company launched an investigation with outside cybersecurity experts and law enforcement after discovering the incident. That investigation determined the unauthorized party had obtained certain C-Track files in March. The Record, which first reported the breach, noted the company has published notification pages for affected users in both the U.S. And Canada.

Related coverage

More from Defence