ZeroHour
The Recordpublished ()ingested
Part of a story covered by 2 sources: “Thomson Reuters C-Track Breach Exposes US and Canadian Court Records” — merged summary and timeline →

US and Canadian court data exposed in Thomson Reuters breach

highData breach exploited in the wildimportance 75
AI summary · glm-5.3-flash

Thomson Reuters disclosed a breach of its C-Track court platform exposing sealed court records and personal data across 12+ US states and Canada.

Thomson Reuters disclosed that an unauthorized party obtained files from C-Track, its court case management platform, affecting courts in at least 12 US states, the US Virgin Islands and Canada. The company discovered the activity on June 30 and evidence indicates access ran from March through June; the intrusion method, attacker identity and number of affected people remain unknown. Exposed data may include names, Social Security numbers, driver's license numbers, medical information, dates of birth and health insurance details, including some sealed or redacted court records. Affected individuals are being offered 12 months of free credit monitoring and identity theft protection.

  • Unauthorized party accessed C-Track files from March to June 2026; discovery occurred on June 30.
  • Data may include names, Social Security numbers, driver's licenses, medical and health insurance information.
  • Affected systems include appellate courts in at least 12 US states, the US Virgin Islands and Canada.
  • No evidence of fraud or misuse so far; C-Track remained operational throughout the incident.
  • Access method and attacker attribution have not been disclosed.
Full article560 words · extracted from therecord.media · click to collapse

Sealed court information and sensitive personal data were exposed in a breach of a Thomson Reuters records platform affecting courts in at least 12 U.S. states, the U.S. Virgin Islands and Canada, the company publicly disclosed Wednesday.

Thomson Reuters has not said how the attacker gained access, who was responsible or how much data was taken. The number of people affected also remains unclear. The company stressed the breach occurred within its environment and was not caused by the networks, systems or data security of the affected courts.

The breach involved C-Track, a court case management platform operated by a Thomson Reuters subsidiary. The company has published notification pages for affected users in both the U.S. and Canada.

Thomson Reuters said it discovered the unauthorized activity on June 30, prompting an investigation with outside cybersecurity experts and law enforcement. The investigation found that an unauthorized party had obtained certain C-Track files in March.

In a separate disclosure, Montana’s Supreme Court said the company told state officials the unauthorized access occurred from March through June, suggesting the attackers were present in the court records system until their discovery.

Thomson Reuters said the incident may have contained names, Social Security numbers, driver’s license numbers, medical information, dates of birth and health insurance information.

Confidential, redacted or sealed information also may have been affected at some courts, the company added, although it said there is no evidence the incident has yet resulted in fraud or misuse of information.

The company said the breach did not disrupt C-Track and that the platform remains fully operational. It said it has added new security measures and that outside experts reviewed and approved of the changes, though it did not identify those experts.

Court systems identified in Thomson Reuters’ U.S. notice include appellate courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, South Carolina, Tennessee and Wyoming.

The notice also names several Pennsylvania courts, 10 Ohio district courts of appeals and the U.S. Virgin Islands Supreme Court and Superior Court.

Other court systems have separately disclosed that they were affected. The Oregon Judicial Department said its appellate courts were involved in the breach, bringing the known number of affected states to at least 12. 

In Nevada, officials said the type of data involved varies by jurisdiction and cautioned against assuming information exposed in one state was also exposed elsewhere.

In Montana, state officials said most of the affected information appeared to already be publicly available, although some driver’s license numbers and dates of birth were also involved.

Some court officials were notified weeks after Thomson Reuters discovered the breach. The company told Montana’s court administrator and Ontario’s Ministry of the Attorney General on July 23 that court data had been accessed.

In a joint statement, the chief justices of the Court of Appeal for Ontario, Superior Court of Justice and Ontario Court of Justice said it remained unclear exactly what information was compromised or how many people were affected.

Thomson Reuters said it is offering affected individuals 12 months of free credit monitoring and identity theft protection.

No previous article

No new articles

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/thomson-reuters-cyberattack-data