Thomson Reuters Breach Exposes Sealed Court Data Across US and Canada
A significant data breach at **Thomson Reuters** has compromised sealed court information and sensitive personal data from a records platform affecting courts in at least 12 U.S. states, the U.S. Virgin Islands, and Canada. The incident, involving the **C-Track** court case management platform, exposed a range of personally identifiable information and confidential legal documents.
Court systems across North America are grappling with the fallout from a data breach impacting **Thomson Reuters**' **C-Track** platform. The company publicly disclosed the incident, which saw an unauthorized party access sensitive court records.
### Scope of the Breach
The breach, discovered on June 30, allowed unauthorized access to **C-Track** files as early as March. While **Thomson Reuters** has not specified the attacker's identity, the method of access, or the total volume of data exfiltrated, the implications are significant. The company emphasized that the breach occurred within its own environment, not due to vulnerabilities in court systems.
Affected jurisdictions include appellate courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, South Carolina, Tennessee, and Wyoming. Additionally, several Pennsylvania courts, 10 Ohio district courts of appeals, the U.S. Virgin Islands Supreme Court and Superior Court, and appellate courts in Oregon and Ontario, Canada, have been impacted.
### Data Compromised
The exposed data may include names, Social Security numbers, driverβs license numbers, medical information, dates of birth, and health insurance information. Critically, confidential, redacted, or sealed court information may also have been compromised in some courts. While **Thomson Reuters** states there's no current evidence of fraud or misuse, the potential for harm is considerable given the sensitive nature of court records.
Montana's Supreme Court, in a separate disclosure, indicated that the unauthorized access persisted from March through June, suggesting a prolonged presence by the attackers within the system.
### Response and Mitigation
**Thomson Reuters** initiated an investigation immediately upon discovering the unauthorized activity, engaging external cybersecurity experts and law enforcement. The company has since implemented new security measures, which have been reviewed and approved by undisclosed third-party experts.
Despite the breach, the **C-Track** platform remains operational and was not disrupted. **Thomson Reuters** is offering affected individuals 12 months of free credit monitoring and identity theft protection.
### Notification Delays and Jurisdiction Specifics
Some court officials received notification weeks after **Thomson Reuters** discovered the breach. For example, Montanaβs court administrator and Ontarioβs Ministry of the Attorney General were informed on July 23.
Officials in Nevada cautioned that the type of data involved varies by jurisdiction, urging against assumptions that information exposed in one state was universally compromised. Montana officials noted that much of their affected information was already publicly available, though some driver's license numbers and dates of birth were also exposed.
In a joint statement, the chief justices of Ontario's Court of Appeal, Superior Court of Justice, and Ontario Court of Justice acknowledged the ongoing uncertainty regarding the exact information compromised and the number of individuals affected.