# What happened
Thomson Reuters disclosed a cybersecurity incident involving its C-Track case management platform. The company detected unauthorized activity on June 30 and later said an unauthorized party obtained certain C-Track files in March. The affected files are tied to court systems in 11 U.S. states, the U.S. Virgin Islands and Ontario, Canada.
# Who and where were affected
Thomson Reuters and related reporting list 11 U.S. states plus the U.S. Virgin Islands and Ontario courts. Ontario's Court of Appeal, the Ontario Superior Court of Justice and the Ontario Court of Justice issued a public statement confirming the incident affected their C-Track environment.
# What data may be exposed
Thomson Reuters' investigation found that a subset of court records were affected. That subset could contain individuals' names and personal information. The company and Ontario's chief justices warned that certain confidential, redacted or sealed information may have been impacted for some courts.
# Timeline
- March: An unauthorized party obtained certain C-Track files, according to Thomson Reuters' investigation.
- June 30: Thomson Reuters detected unauthorized activity in one of its cloud environments.
# Immediate practical steps for courts and legal professionals
- Treat affected case files as potentially public. Review filings and sealed-material notices to identify high-risk records.
- Audit access logs for C-Track instances and preserve forensic evidence.
- Notify parties to cases with potentially exposed personal or sealed information and offer guidance on next steps.
- Coordinate with local court administrators and, where applicable, provincial or state attorneys general and cyber incident response resources.
# Steps individuals named in court records should take
- Assume potential exposure of personal data tied to court records and monitor financial accounts and credit reports.
- Consider placing fraud alerts or credit freezes if required by local procedures.
- If a court filing contained highly sensitive identifiers (for example, Social Security numbers), ask the court clerk about protective filing options and whether redaction or sealed re-filing is available.
# What courts and vendors should review now
- Access controls and segmentation between vendor cloud environments and court systems.
- Procedures for handling sealed or redacted filings when using third-party case management systems.
- Vendor contractual obligations, incident notification clauses and evidence-preservation requirements.
# What to watch next
# Bottom line
A subset of C-Track files tied to multiple North American jurisdictions was obtained by an unauthorized party. Some affected records may include personal information and sealed or redacted material. Courts, legal professionals and individuals named in affected records should assume possible exposure and take immediate, practical steps to limit further harm.