Key facts
- Thomson Reuters experienced a cybersecurity incident affecting its C-Track case management platform.
Thomson Reuters has disclosed a cybersecurity incident involving its C-Track case management platform, impacting court systems across 11 U.S. states, the U.S. Virgin Islands, and Canada. An unauthorized party gained access to certain files in March, potentially compromising personal information of individuals involved in court proceedings.

The incident highlights ongoing cybersecurity risks to critical infrastructure, including legal and judicial systems, and raises concerns about the potential exposure of sensitive personal information of individuals involved in court proceedings.
Thomson Reuters has reported a cybersecurity incident impacting its C-Track case management platform, which is used for digital court record management. The company detected unauthorized activity on June 30, and a subsequent investigation revealed that an unauthorized party accessed certain C-Track files in March. This breach potentially affected court records containing names and personal information of individuals involved in court proceedings.
The incident affected court systems across 11 U.S. states, the U.S. Virgin Islands, and Canada. The chief justices of three Ontario courts confirmed the unauthorized activity and stated that Thomson Reuters took immediate steps to contain the breach, engaged external cybersecurity experts, and notified law enforcement.
Thomson Reuters confirmed that containment and security measures were implemented and that affected customers have been notified. The company stated that the C-Track platform experienced no operational disruption and that its products and services remain safe to use. Independent cybersecurity experts validated the remediation efforts. It remains unclear what specific information was compromised, but individuals involved in court proceedings or mentioned in court documents could have had their personal information affected.