CSIDB logo
Incident

Court of Appeal for Ontario

Incident posture

Attack window
Mar 2026
Location
Canada
Status
Unknown
CIA posture
Available to members
Updated
2026-09-11 06:38

Linked entities

Victim
Court of Appeal for Ontario
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2026
Discovered
Jun 2026
Disclosed
Sep 2026
Resolved
Pending

Summary

The Court of Appeal for Ontario, the Ontario Superior Court of Justice and the Ontario Court of Justice use the C‑Track case‑management platform owned by Thomson Reuters Canada Limited, which detected unauthorized activity in one of its cloud environments and determined that an unauthorized party had accessed court records from those Ontario courts as well as from C‑Track users in Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming and the U.S. Virgin Islands. The breach may have exposed names and other personal information, including possibly confidential, redacted or sealed data, though the exact scope and types of information remain unspecified. In response, the provider has implemented additional security measures, launched a informational website, opened a call centre and is offering credit monitoring to potentially affected individuals.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 30, 2026, Thomson Reuters Canada Limited detected unauthorized activity within one of its cloud environments that hosts the C‑Track case‑management platform used by the Ontario Court of Appeal, the Ontario Superior Court of Justice and the Ontario Court of Justice. The company promptly contacted law enforcement and launched an internal investigation, which determined that the breach had begun as early as March 2026 and that an unauthorized party had obtained court records from those Ontario tribunals. The investigation concluded that the compromise originated in Thomson Reuters’ systems and was not the result of any vulnerability in the courts’ own networks or data security controls. The company disclosed that certain confidential, redacted or sealed information may have been impacted for the affected courts, though it did not specify the exact categories or volume of data accessed.

The breach extended beyond Ontario, affecting C‑Track users in Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming and the U.S. Virgin Islands. A U.S.‑based website set up for victims noted that the potentially exposed personal information could include driver’s licence numbers, social security numbers and medical details, while the New Hampshire Judicial Branch indicated that its affected records spanned the period from 2002 to 2015. In Ontario, the chief justices’ statement acknowledged that names and other personal information were possibly accessed but did not quantify how many individuals might be at risk, and it emphasized that there remained uncertainty about the precise contents of the files that were compromised. To assist those potentially affected, Thomson Reuters established a call centre, began offering credit monitoring services and provided a dedicated website with information about the incident.

In response, the company implemented additional cybersecurity measures to better protect the C‑Track systems and affirmed that its products and services remained fully operational and safe to continue using. The Ontario chief justices issued a public notice urging transparency, committing to support potentially affected individuals, to safeguard information entrusted to the courts and to collaborate with the Ontario government to strengthen security measures and reduce the likelihood of similar incidents. Their statement reiterated the courts’ commitment to privacy and security while acknowledging the ongoing uncertainty surrounding the exact scope of the data accessed. The notice concluded by affirming that efforts would continue to address the breach and to reinforce protections for court‑related information.

Sources

Sources available to members: 1 source.

CSIDB