Stock Markets September 2, 2026 11:11 PM

Thomson Reuters unit identifies unauthorized access to C-Track files across U.S., U.S. Virgin Islands and Canada

Company says some court records were affected; investigations and containment steps underway, contact center to open Sept. 4

By Derek Hwang
Share
Twitter Reddit Facebook LinkedIn
TRI

A Thomson Reuters business unit detected unauthorized activity affecting its C-Track case management platform on June 30, later finding that certain files were removed in March. The incident touched court systems in multiple U.S. states, the U.S. Virgin Islands and Canada; affected customers have been notified and the company engaged external cybersecurity experts, law enforcement and containment measures. It remains unclear which specific data elements were compromised.

Thomson Reuters unit identifies unauthorized access to C-Track files across U.S., U.S. Virgin Islands and Canada
TRI
Summarize with
ChatGPT Perplexity Claude Grok Gemini

Key Points

  • Thomson Reuters detected unauthorized activity in its C-Track case management platform on June 30 and determined that certain files were taken in March.
  • Court systems in 11 U.S. states, the U.S. Virgin Islands and Canadian courts that use C-Track were affected; some court records including names and personal information were identified as "affected."
  • Thomson Reuters engaged external cybersecurity experts, notified law enforcement, implemented containment and remediation measures, and set up a contact center to handle inquiries, with a call center in Canada scheduled to open on Sept. 4.

On Sept. 2, Thomson Reuters disclosed that a unit within the company discovered a cybersecurity incident impacting its C-Track case management platform in multiple jurisdictions on June 30. A follow-up investigation concluded that an unauthorized party had obtained certain C-Track files in March, the company said on a dedicated information website established in response to the incident.


Scope and jurisdictions

The unauthorized activity was reported to have hit court systems in 11 U.S. states, the U.S. Virgin Islands and Canada. The list of U.S. states named on the information website includes Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire and Wyoming. In Canada, the revelation prompted a joint statement from the chief justices of three Ontario courts that use the C-Track platform for managing digital court records.


What the investigation found

Thomson Reuters said its inquiry determined that certain C-Track files were obtained by an unauthorized actor in March. The company’s investigation also found that some court records were "affected," with those records including names and personal information, according to the incident information website. The chief justices’ joint statement reiterated that Thomson Reuters had detected unauthorized activity in one of its cloud environments and had taken steps to contain that activity.


Company and court responses

The West Publishing unit of Thomson Reuters set up a website to answer questions about the incident and to provide details on affected jurisdictions. Thomson Reuters confirmed that it implemented containment and security measures and that impacted customers have been notified. A company spokesperson said there has been no operational disruption to the C-Track platform as a result of the incident and that its products and services remain operational and safe to use. The company also said independent cybersecurity experts assisted with the investigation and validated remediation steps that were implemented.

The chief justices of the Court of Appeal for Ontario, the Ontario Superior Court of Justice and the Ontario Court of Justice said that Thomson Reuters responded by taking steps to contain the activity, engaging external cybersecurity experts to advise and investigate, notifying law enforcement, and securing the C-Track environment.


Uncertainties and next steps

The chief justices’ statement cautioned that it is unclear what specific information may have been compromised. They noted that individuals who are party to court proceedings or are named in court documents could have had personal information involved in the incident. Thomson Reuters indicated it was responding to inquiries in both the United States and Canada and confirmed a contact center would be established. The court officials said Thomson Reuters Canada would handle inquiries and that a call center would be active on Sept. 4.


Independent verification

Independent verification of the responsible party or of the exact nature and extent of the compromised information was not provided in the company’s public notices. The limits on available information leave open questions about the full scope and impact of the breach on individuals named in court records and on systems using C-Track.

Risks

  • Unclear extent of compromised data - the investigation found some court records were affected, but it is not known which specific information elements were exposed, creating privacy risks for individuals named in court documents (impacts legal, personal data sectors).
  • Attribution and threat actor unknown - the company and courts did not identify who was responsible for the incident, leaving uncertainty over potential motives or further actions (impacts cybersecurity and risk management functions across affected institutions).
  • Operational and reputational uncertainty for court systems and service providers - although Thomson Reuters reported no operational disruption to C-Track, affected courts and their users face ongoing uncertainty about data integrity and privacy, which could affect trust in digital court records management (impacts legal sector and digital records services).

More from Stock Markets

Mitsubishi Corp. Shares Jump After Berkshire's Abel Signals Bigger Stakes in Japan's Trading Houses Sep 3, 2026 Lynas Shares Tick Higher After Report of Earlier Takeover Discussions Sep 2, 2026 China Gold International Advances on Index Additions; H1 Profits Surge Sep 2, 2026 KEPCO Seeks Upfront Payments from Samsung and SK Hynix to Fund Grid Expansion Sep 2, 2026 PayPal Cuts About 600 Roles in India as Part of Global Cost Restructure Sep 2, 2026