Thomson Reuters has disclosed a cybersecurity incident involving its C-Track case management platform, which is used by courts to manage digital records. The incident affected court systems across 11 U.S. states, the U.S. Virgin Islands and Canada.

According to Thomson Reuters, an unauthorized party accessed certain C-Track files in March. The company’s investigation later found that some court records were affected and that the files contained names and other personal information.

The incident affected court systems in Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire and Wyoming, as well as the U.S. Virgin Islands. Thomson Reuters’ West Publishing unit created a website to provide information about the incident and the affected court systems.

The incident also involved Ontario, Canada. The chief justices of the Court of Appeal for Ontario, the Ontario Superior Court of Justice and the Ontario Court of Justice said Thomson Reuters detected unauthorized activity in one of its cloud environments. The company worked with Ontario’s Ministry of the Attorney General and the affected courts to contain the incident.

Thomson Reuters said it responded by taking steps to contain the activity, bringing in external cybersecurity experts, notifying law enforcement and securing the C-Track environment. The company also said customers affected by the incident have been notified.

Despite the security incident, Thomson Reuters said there has been no operational disruption to C-Track. The company said its products and services remain fully operational and safe to use. Independent cybersecurity experts also assisted with the investigation and reviewed the security measures implemented after the incident.

READ
How to Find Vulnerable WordPress Plugins on Your Website

However, the exact scope of the potentially compromised information remains unclear. Ontario’s chief justices said people involved in court proceedings or mentioned in court documents could have had personal information connected to them involved in the incident.

Thomson Reuters has not publicly identified who was responsible for the incident, and Reuters said it could not independently determine who carried out the attack or exactly what information was compromised.


Buy ExpressVPN with PayPal or Credit Card

Thomson Reuters Canada said it will respond to inquiries about the incident and plans to operate a contact center beginning September 4. The company is also responding to questions from affected parties in both the United States and Canada.

Advertisement