Thomson Reuters
Image: George Oliver / Unsplash

US and Canadian court data exposed in Thomson Reuters breach

Sealed court information and sensitive personal data were exposed in a breach of a Thomson Reuters records platform affecting courts in at least 12 U.S. states, the U.S. Virgin Islands and Canada, the company publicly disclosed Wednesday.

Thomson Reuters has not said how the attacker gained access, who was responsible or how much data was taken. The number of people affected also remains unclear. The company stressed the breach occurred within its environment and was not caused by the networks, systems or data security of the affected courts.

The breach involved C-Track, a court case management platform operated by a Thomson Reuters subsidiary. The company has published notification pages for affected users in both the U.S. and Canada.

Thomson Reuters said it discovered the unauthorized activity on June 30, prompting an investigation with outside cybersecurity experts and law enforcement. The investigation found that an unauthorized party had obtained certain C-Track files in March.

In a separate disclosure, Montana’s Supreme Court said the company told state officials the unauthorized access occurred from March through June, suggesting the attackers were present in the court records system until their discovery.

Thomson Reuters said the incident may have contained names, Social Security numbers, driver’s license numbers, medical information, dates of birth and health insurance information.

Confidential, redacted or sealed information also may have been affected at some courts, the company added, although it said there is no evidence the incident has yet resulted in fraud or misuse of information.

The company said the breach did not disrupt C-Track and that the platform remains fully operational. It said it has added new security measures and that outside experts reviewed and approved of the changes, though it did not identify those experts.

Court systems identified in Thomson Reuters’ U.S. notice include appellate courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, South Carolina, Tennessee and Wyoming.

The notice also names several Pennsylvania courts, 10 Ohio district courts of appeals and the U.S. Virgin Islands Supreme Court and Superior Court.

Other court systems have separately disclosed that they were affected. The Oregon Judicial Department said its appellate courts were involved in the breach, bringing the known number of affected states to at least 12. 

In Nevada, officials said the type of data involved varies by jurisdiction and cautioned against assuming information exposed in one state was also exposed elsewhere.

In Montana, state officials said most of the affected information appeared to already be publicly available, although some driver’s license numbers and dates of birth were also involved.

Some court officials were notified weeks after Thomson Reuters discovered the breach. The company told Montana’s court administrator and Ontario’s Ministry of the Attorney General on July 23 that court data had been accessed.

In a joint statement, the chief justices of the Court of Appeal for Ontario, Superior Court of Justice and Ontario Court of Justice said it remained unclear exactly what information was compromised or how many people were affected.

Thomson Reuters said it is offering affected individuals 12 months of free credit monitoring and identity theft protection.

Recorded Future
No previous article
No new articles
Alexander Martin

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79