Cybersecurity Breach Affects Court Systems in Multiple States
On June 30, a cybersecurity incident involving Thomson Reuters’ C-Track case management platform was reported in 11 U.S. states, the U.S. Virgin Islands, and Canada. This announcement was made through a notice from the company and a statement from the chief justices of three Ontario courts that utilize the platform for managing digital court records.
Thomson Reuters conducted an investigation and discovered that unauthorized individuals accessed certain files related to C-Track back in March. These files included court records that contained personal information. A dedicated website has been established to provide further details about the incident.
The hacker’s intrusion impacted court systems in Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming, and the U.S. Virgin Islands. The statement from the chief justices explained that the company detected unauthorized activities in one of its cloud environments and took immediate action to limit the impact. They collaborated closely with Ontario’s Ministry of the Attorney General and the courts to address the matter.
Thomson Reuters responded by engaging external cybersecurity experts for assistance and conducting a thorough investigation. They also notified law enforcement agencies and worked on securing the C-Track platform. The company confirmed that those affected have been informed.
Despite the seriousness of the breach, a spokesperson for Thomson Reuters assured users that there has been no disruption to the C-Track platform’s operations. “All our products and services are fully operational and safe to use,” the spokesperson stated, adding that cybersecurity professionals validated the steps taken to rectify the situation.
The chief justices noted that while the specifics of the compromised information remain unclear, individuals involved in court proceedings or referenced in court documents might be affected.
Currently, it’s uncertain who was behind the breach or what exact information was exposed. The chief justices announced that Thomson Reuters Canada would handle all inquiries related to the incident and set up a call center that would be operational starting September 4. The company also confirmed that it would address questions from both U.S. and Canadian customers.
(Reported by Kenneth Li and Chris Sanders; Edited by Edmund Klamann)
