Security News

Thomson Reuters Court Software Breach Exposes Sensitive Records Across US and Canada

Infosecurity Magazine · 3 Sept 2026
Key Takeaway Businesses that rely on third-party software vendors for sensitive data management should confirm those vendors' incident response plans and demand clear breach notification timelines as part of vendor risk management.

Thomson Reuters has disclosed a cybersecurity incident affecting its C-Track case management software, resulting in unauthorized access to sensitive court records in Canada and the United States. The company detected suspicious activity on June 30, and its investigation later confirmed that an unauthorized party accessed C-Track Canada files linked to three Ontario courts: the Court of Appeal for Ontario, the Ontario Superior Court of Justice, and the Ontario Court of Justice. Ontario's Chief Justices confirmed the breach, warning that personal information related to individuals involved in court proceedings may have been exposed.

The incident also affected appellate courts in 11 US states and the US Virgin Islands, according to West Publishing Corporation, a Thomson Reuters subsidiary. Potentially compromised data includes names, Social Security numbers, driver's license numbers, medical information, dates of birth, and health insurance details. In some cases, confidential, redacted, or sealed court information may have been exposed. Thomson Reuters said there is no evidence that financial transaction systems were affected, and emphasized that the breach did not stem from the courts' own networks or security practices.

The investigation into the scope of the breach is ongoing, with no details yet released on how the C-Track system was compromised or how many individuals are affected.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.