A unit of Thomson Reuters identified a cyber incident affecting its C‑Track platform, with unauthorized access to court records in multiple U.S. states and Canada.
Thomson Reuters disclosed a cybersecurity incident that compromised its C‑Track platform, granting an unauthorized party access to court records across several U.S. states and Canada.
Scope of the breach
The incident was detected by a Thomson Reuters unit responsible for the C‑Track service, a tool used by legal professionals to monitor court filings and docket information.
According to the company, the unauthorized access involved files containing public court documents, but no confidential client data or proprietary internal systems were reported as compromised.
Affected jurisdictions
The breach impacted records from multiple U.S. states, though specific states were not enumerated, as well as court filings from Canadian jurisdictions.
Thomson Reuters emphasized that the accessed information is publicly available through court systems, and the breach does not appear to have altered or deleted any records.
Response and mitigation
Upon discovering the intrusion, Thomson Reuters immediately initiated its incident response protocol, involving internal security teams and external cybersecurity experts.
The company secured the affected systems, conducted a forensic investigation, and notified relevant authorities in the United States and Canada.
- Enhanced monitoring of C‑Track access logs
- Implemented additional authentication safeguards
- Conducted a comprehensive security audit of related platforms
Customers using C‑Track were informed of the incident and advised to review any accessed data for anomalies, though the company stated no evidence of misuse has been identified.
Thomson Reuters reiterated its commitment to protecting the integrity of legal information services and pledged to continue monitoring for any further suspicious activity.