CSIDB logo
Incident

Thomson Reuters

Incident posture

Attack window
Jun 2026
Location
Canada
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-03 17:31

Linked entities

Victim
Thomson Reuters
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Jun 2026
Disclosed
Sep 2026
Resolved
Pending

Summary

Thomson Reuters disclosed a cybersecurity incident affecting its C‑Track court management software, which led to unauthorized access to case data held by three Ontario courts and appellate courts in eleven U.S. states and the U.S. Virgin Islands. The compromised information may include names, Social Security numbers, driver’s license numbers, medical details, dates of birth and health insurance data, with possible exposure of confidential, redacted or sealed records. The company stated that no financial transaction systems were involved and there is currently no evidence that the data has been misused for fraud or other purposes, while investigations continue to determine the full scope of the breach.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Thomson Reuters disclosed a cybersecurity incident impacting its court management software, which resulted in a breach of sensitive case data across Canada and the United States. The company detected activity affecting information held in its C‑Track product on June 30. An investigation revealed that an unauthorized party obtained certain C‑Track Canada files associated with three Ontario courts: the Court of Appeal for Ontario, the Ontario Superior Court of Justice and the Ontario Court of Justice. Based on the investigation, a subset of court records were affected, some of which could contain individuals’ names and personal information. Certain confidential, redacted or sealed information may have been impacted for those courts. The incident also affected appellate courts in eleven US states and the US Virgin Islands, as disclosed by West Publishing Corporation, a US‑based provider of court management solutions owned by Thomson Reuters. The affected states are South Carolina, Nevada, New Hampshire, North Dakota, Ohio, Kentucky, Pennsylvania, Alabama, Montana, Tennessee and North Dakota.

West Publishing stated that the affected court records potentially contain individuals’ personal records, including names, Social Security numbers, driver’s license numbers, medical information, dates of birth and health insurance information. As with the Ontario courts, certain confidential, redacted or sealed information may have been impacted for the US courts. Ontario’s three Chief Justices issued a public statement warning that personal information relating to individuals involved in court proceedings or mentioned in court documents may have been exposed. Thomson Reuters said there is no evidence that systems used to process financial transactions were impacted by the incident. No details have been provided on how the C‑Track records were accessed, but the company emphasized that the incident was not caused by the courts’ networks, systems or data security. The investigation is ongoing to establish the specific content and types of information breached at each affected court and to determine the number of individuals whose information may have been impacted.

Court documents are known to be a target for a range of threat actors, including nation‑state groups seeking espionage, malicious actors attempting to disrupt or influence individual cases, and financially motivated cybercriminals using sensitive data to extort individuals and organizations. In August 2025 the US federal judiciary announced stronger cybersecurity protections for sensitive court documents following recent escalated cyber‑attacks on its case management system, a statement that followed reports of a breach exposing sensitive court documents in multiple US states. To date there is no evidence that the affected data from the Thomson Reuters incident has been misused for fraud or other purposes.

Sources

Sources available to members: 1 source.

CSIDB