Thomson Reuters disclosed that an unauthorized party accessed files in C-Track, its cloud-based court case-management platform, exposing data tied to courts in at least 12 US states, the US Virgin Islands, and Canada. The intrusion began in March and was detected on June 30; Montana officials indicated unauthorized access may have persisted through June. Affected organizations include three Ontario courts, appellate courts in 11 US states, and the North Dakota Supreme Court, which was notified in late July.
The compromised files may contain names, dates of birth, Social Security and driver’s-license numbers, medical and health-insurance details, and confidential, redacted, or sealed court records. Thomson Reuters said affected courts’ networks were not the source of the incident, C-Track remained operational, and financial-transaction systems were unaffected. The company contained the activity, secured the environment, engaged external incident-response experts, notified law enforcement and customers, and is offering 12 months of credit monitoring and identity-theft protection; no misuse of the data has been identified so far.

See attribution, scope, and your downstream exposure.
11 events from the most recent confirmed update back to the earliest known activity.
Ontario’s chief justices for the Court of Appeal, Superior Court of Justice, and Court of Justice posted a public notice that court records in C-Track had been accessed. They said the precise contents of the accessed files remained uncertain and that they would work with the Ontario government to strengthen security measures.
Thomson Reuters notified Montana's court administrator and Ontario's Ministry of the Attorney General that court data in C-Track had been accessed.
The North Dakota Court System said it was informed in late July that the third-party C-Track breach may have affected data associated with the North Dakota Supreme Court.
Thomson Reuters detected unauthorized activity affecting information held in its C-Track court case-management platform and began investigating the incident.
Thomson Reuters determined that an unauthorized party obtained certain files from its C-Track cloud court-management environment beginning in March; Montana officials said access may have continued through June.
The Montana Supreme Court confirmed that backup data associated with Montana's court system was compromised in the C-Track intrusion. Officials said their review identified some personally identifying information, including driver's license numbers and dates of birth, and continued reviewing the data with Thomson Reuters.
Thomson Reuters said it will offer affected individuals 12 months of free credit monitoring and identity-theft protection following the C-Track breach.
Thomson Reuters said it secured the affected C-Track environment, engaged external cybersecurity experts, notified law enforcement and affected customers, and added security measures. It reported no operational disruption to C-Track and no evidence at that time of fraud or misuse of exposed data.
Minnesota Judicial Branch said appellate-court data and court-user data were compromised in the C-Track incident. It terminated Thomson Reuters access to its courts' electronic environments and directed appellate case-management users to change their passwords.
Thomson Reuters disclosed that its subsidiary West Publishing Corporation was also affected by the C-Track court-management software incident. The company said it had no evidence that financial transaction systems were compromised or that exposed data had been misused.
Thomson Reuters publicly disclosed that C-Track files associated with courts in Canada, at least 12 U.S. states, and the U.S. Virgin Islands were affected. Potentially exposed data includes personal information and, for some courts, confidential, redacted, or sealed records.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
15 references tracked. Mallory keeps watching after this page renders.
cbc.ca
Open sourceteiss.co.uk
Open sourcescworld.com
Open sourcecysecurity.news
Open sourcereuters.com
Open sourceontariocourts.ca
Open sourcectracknotification.ca
Open sourcectracknotification.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.