Industry News

Thomson Reuters Reports Data Breach Affecting Court Case Management System

Reuters · 3 Sept 2026
Key Takeaway If your business relies on third-party platforms to store sensitive records, ask vendors about their breach notification processes and regularly review what data you've shared with them.

Thomson Reuters has disclosed a cybersecurity incident affecting its C-Track case management platform, a system used by courts to manage digital case records. The company said an unauthorized party accessed files, with the incident detected on June 30 and impacting jurisdictions in 11 U.S. states, the U.S. Virgin Islands, and Canada.

The breach was significant enough to prompt a joint statement from the chief justices of three Ontario courts, which rely on the C-Track platform for handling digital court records. While details on the exact scope of accessed data have not been fully disclosed, the incident highlights the risk posed to organisations that depend on third-party software vendors for critical record-keeping functions.

For small and medium businesses, this incident is a reminder that even large, well-resourced vendors can be compromised, and that any organisation using shared or outsourced case management, legal, or record-keeping platforms should stay alert for vendor breach notifications and review what data those platforms hold.

data breach third-party risk Thomson Reuters
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Reuters. We link back to every original so you can read it yourself.