“Based on the investigation, a subset of court records were affected, some of which could potentially contain individuals’ names and personal information,” Thomson Reuters wrote in a statement released on September 2.
What happened: C-Track records accessed, discovery timeline
Thomson Reuters disclosed that it detected activity affecting information held in its C-Track digital case management product on June 30. A subsequent investigation identified that an unauthorized party obtained certain C-Track Canada files tied to three Ontario courts: the Court of Appeal for Ontario, the Ontario Superior Court of Justice and the Ontario Court of Justice. Thomson Reuters issued its public statement on September 2.
Which Canadian and U.S. courts were named
In Canada, the three Ontario courts listed above confirmed the breach in a public statement by their three Chief Justices; they warned that personal information relating to individuals involved in court proceedings or mentioned in court documents may have been exposed.
In the United States, West Publishing Corporation — a U.S.-based provider of court management solutions owned by Thomson Reuters — said the incident also impacted appellate courts in 11 states and the U.S. Virgin Islands. West Publishing’s list named: South Carolina, Nevada, New Hampshire, North Dakota, Ohio, Kentucky, Pennsylvania, Alabama, Montana, Tennessee and North Dakota. The company said the affected records were associated with appellate courts in those jurisdictions and the U.S. Virgin Islands.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTypes of information potentially exposed
Both Thomson Reuters and West Publishing warned that a subset of court records may include individuals’ personal data. West Publishing specified that affected court records potentially contain names, Social Security numbers, driver’s license numbers, medical information, dates of birth and health insurance information. Thomson Reuters additionally said certain confidential, redacted or sealed information may have been impacted for some affected courts.
Investigation status, access pathway, and current findings
The firms said their investigations are ongoing to establish the specific content and types of information breached at each affected court, and to quantify the number of individuals whose information may have been impacted. Thomson Reuters said there is no evidence that systems used to process financial transactions were affected. There were no specifics provided on how the C-Track records were accessed; Thomson Reuters emphasized the incident was not caused by the courts’ networks, systems or data security. To date, both companies reported no evidence that the affected data has been misused for fraud or other purposes.
What this means for court administrators, security teams, and affected individuals
- Court administrators: The public statements from the three Ontario Chief Justices and the vendor disclosures place courts in the difficult position of notifying parties and assessing whether sealed or redacted materials were exposed. Courts will need to rely on the vendor-led investigation to determine which dockets and documents are implicated.
- Security teams and technologists: The incident centers on C-Track and West Publishing-managed systems; the vendors have said the breach was not caused by courts’ internal networks. Security teams will be watching the vendor investigations for forensic details — especially the access vector and whether copies of records left vendor-controlled environments.
- Affected individuals and litigants: Both vendors warned that personally identifiable information — including Social Security numbers, driver’s license numbers and medical and health insurance information — may be present in the exposed records. Those named or mentioned in court filings should expect notices from courts or vendors as investigations clarify which files were affected.
Context: court documents as a target and past federal actions
The vendors’ disclosures echoed a broader observation: court documents are a target for a range of threat actors, including nation‑state groups, malicious actors seeking to influence proceedings, and financially motivated cybercriminals who may use sensitive court data to extort individuals and organizations. The source material also notes that in August 2025 the U.S. federal judiciary announced stronger cybersecurity protections for sensitive court documents following “recent escalated cyber-attacks” on its case management system, after reports that a federal case filing system breach exposed sensitive court documents in multiple states.
The Thomson Reuters/West Publishing disclosures leave the record of affected content and scale incomplete while investigations continue. The immediate, verifiable facts: detection on June 30, public statements on September 2, named impacted Ontario courts and a list of U.S. appellate jurisdictions (and the U.S. Virgin Islands), vendor assertions that court networks were not the source of the incident, and vendor warnings that sensitive personal and sealed information may have been involved. The next concrete developments to watch will be the vendors’ forensic findings and any court-level notifications that identify specific dockets or individuals.
Source: https://www.infosecurity-magazine.com/news/us-canada-court-breach-thomson/




