Thomson Reuters said an unauthorized threat actor accessed files from its C-Track court case-management system in a cyberattack that affected courts across 11 U.S. states, the U.S. Virgin Islands and Ontario, Canada.
Thomson Reuters detected unauthorized activity in one of its cloud environments on June 30, 2026. An investigation determined that the intrusion had occurred in March 2026 and that the attacker obtained some C-Track files.
C-Track is used by courts to manage cases, filings, hearings and schedules. The incident exposed court records and personal information, but Thomson Reuters had not determined exactly what information was accessed or how many people were affected at press time.
Ontario’s three Chief Justices confirmed that Thomson Reuters notified Ontario’s Ministry of the Attorney General on July 23. A more detailed investigation is underway, and relevant authorities have been notified.
Thomson Reuters said there was no evidence of identity theft linked to the incident and no indication that systems handling court-related financial transactions were affected. C-Track remains operational, with no operational disruption reported. No threat actor has claimed responsibility or threatened to publish the files on the dark web.
A Thomson Reuters spokesperson said the company’s products and services remain operational. Independent cybersecurity experts assisted with the investigation and validated the remediation measures implemented.
Comments
0No comments yet. Be the first to comment.