On Sept. 2, Thomson Reuters disclosed that a unit within the company discovered a cybersecurity incident impacting its C-Track case management platform in multiple jurisdictions on June 30. A follow-up investigation concluded that an unauthorized party had obtained certain C-Track files in March, the company said on a dedicated information website established in response to the incident.
Scope and jurisdictions
The unauthorized activity was reported to have hit court systems in 11 U.S. states, the U.S. Virgin Islands and Canada. The list of U.S. states named on the information website includes Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire and Wyoming. In Canada, the revelation prompted a joint statement from the chief justices of three Ontario courts that use the C-Track platform for managing digital court records.
What the investigation found
Thomson Reuters said its inquiry determined that certain C-Track files were obtained by an unauthorized actor in March. The company’s investigation also found that some court records were "affected," with those records including names and personal information, according to the incident information website. The chief justices’ joint statement reiterated that Thomson Reuters had detected unauthorized activity in one of its cloud environments and had taken steps to contain that activity.
Company and court responses
The West Publishing unit of Thomson Reuters set up a website to answer questions about the incident and to provide details on affected jurisdictions. Thomson Reuters confirmed that it implemented containment and security measures and that impacted customers have been notified. A company spokesperson said there has been no operational disruption to the C-Track platform as a result of the incident and that its products and services remain operational and safe to use. The company also said independent cybersecurity experts assisted with the investigation and validated remediation steps that were implemented.
The chief justices of the Court of Appeal for Ontario, the Ontario Superior Court of Justice and the Ontario Court of Justice said that Thomson Reuters responded by taking steps to contain the activity, engaging external cybersecurity experts to advise and investigate, notifying law enforcement, and securing the C-Track environment.
Uncertainties and next steps
The chief justices’ statement cautioned that it is unclear what specific information may have been compromised. They noted that individuals who are party to court proceedings or are named in court documents could have had personal information involved in the incident. Thomson Reuters indicated it was responding to inquiries in both the United States and Canada and confirmed a contact center would be established. The court officials said Thomson Reuters Canada would handle inquiries and that a call center would be active on Sept. 4.
Independent verification
Independent verification of the responsible party or of the exact nature and extent of the compromised information was not provided in the company’s public notices. The limits on available information leave open questions about the full scope and impact of the breach on individuals named in court records and on systems using C-Track.