Thomson Reuters C-Track Software Breach Exposes US and Canadian Court Records
Thomson Reuters has disclosed a cyber incident impacting its C-Track court management software, potentially exposing sensitive court records across both Canadian and US jurisdictions.

Thomson Reuters has confirmed a significant cybersecurity incident that has compromised its C-Track court management software, a system used to manage legal proceedings and records for numerous courts.
The breach, disclosed by the legal and financial information giant, raises serious concerns about the confidentiality of sensitive legal data. While the full scope and nature of the exposed information are still under investigation, initial reports suggest that court records from both Canadian and US jurisdictions may have been accessed by unauthorized parties.
The C-Track software is designed to streamline court operations, including case management, scheduling, and record-keeping. Its compromise means that potentially a wide array of sensitive data, including case details, personal information of individuals involved in legal proceedings, and other confidential court documents, could be at risk.
Thomson Reuters has stated that it is working diligently to investigate the incident, assess the impact, and implement necessary security measures to prevent further unauthorized access. The company is cooperating with relevant authorities and has initiated a forensic investigation to determine the root cause and the extent of the data exposure.
This incident highlights the persistent threat of cyberattacks targeting critical infrastructure and sensitive data repositories. The legal sector, with its wealth of confidential information, remains a prime target for malicious actors seeking to exploit vulnerabilities for financial gain or disruption.
Further details regarding the specific types of data compromised, the number of affected courts or jurisdictions, and the timeline of the breach are expected to be released as the investigation progresses. The company has not yet provided specific details on the vulnerabilities exploited or the threat actors involved.
Organizations utilizing C-Track software are advised to remain vigilant and follow any guidance or remediation steps provided by Thomson Reuters. The incident underscores the importance of robust cybersecurity practices and regular security audits for all software systems handling sensitive data.
The breach, which impacted Thomson Reuters' C-Track platform, occurred between March and June, with unauthorized access continuing until discovery. While the company stated the incident did not disrupt C-Track's operations, it has since implemented new security measures reviewed by external experts. Affected individuals are being offered 12 months of free credit monitoring and identity theft protection.
Thomson Reuters has publicly disclosed the data breach impacting its C-Track court case management platform. The company has also published separate, detailed notifications for affected individuals in both the United States and Canada, outlining the scope of exposed sensitive court records and personal information.