A cybersecurity incident involving Thomson Reuters’ C-Track court-management platform has exposed an uncomfortable reality about modern justice systems: sensitive court information does not always remain inside courthouse-controlled networks. Ontario’s three main courts confirmed that information associated with their records was among data obtained by an unauthorized third party, with the activity discovered months after files were taken.
The incident reaches well beyond Ontario. Court systems across the United States and the U.S. Virgin Islands have also reported involvement, creating a cross-border breach tied to infrastructure operated by Thomson Reuters entities. Officials say court operations were not disrupted and there is no evidence so far of identity theft or compromised payment systems. Still, investigators have not publicly established exactly how many people were affected or precisely what Ontario information was exposed.
The Files Were Taken Months Before the Breach Was Discovered
The timeline is one of the most striking elements of the incident. Thomson Reuters Canada says C-Track detected unauthorized third-party activity on June 30, 2026. Its investigation subsequently determined that an unauthorized party had obtained certain C-Track Canada files associated with Ontario courts in March. That means the discovery came roughly three months after the affected files were taken.
Ontario’s Ministry of the Attorney General was informed on July 23 after Thomson Reuters determined that accessed material included information connected with the province’s courts. The ministry then began working with the judiciary, Thomson Reuters Canada and Ontario government cybersecurity specialists to assess the scope and consequences. The public disclosure came on September 2. For people whose names may appear in court records, that sequence matters because the breach investigation was already months old when the incident became broadly known.
All Three Major Ontario Court Systems Were Involved
The affected Canadian files were associated with the Court of Appeal for Ontario, the Ontario Superior Court of Justice and the Ontario Court of Justice. Together, those institutions handle an enormous range of matters, from appeals and major civil litigation to criminal proceedings and family cases. C-Track is used by the three courts to store and manage some court documents and records.
That does not mean every case, document or person who has interacted with an Ontario court was exposed. Officials have been careful not to make that claim. Thomson Reuters Canada is still determining the specific content involved at each court and the number of people whose information may have been affected. The distinction is important. The incident involves a subset of records stored through C-Track rather than a confirmed compromise of the entirety of Ontario’s judicial information. Even so, the participation of all three courts gives the investigation province-wide significance.
Some Confidential, Redacted or Sealed Information May Have Been Affected
The Canadian incident notice says a subset of court records was affected and that the files could potentially contain people’s names and personal information. More unusually, Thomson Reuters Canada says certain confidential, redacted or sealed information may also have been affected for some courts. Ontario officials have not yet disclosed the specific categories of personal information found in the affected provincial files.
U.S. notifications provide a clearer picture of what C-Track records can contain. There, the company said potentially affected records could include Social Security numbers, driver’s licence numbers, dates of birth, medical information and health-insurance information. Those U.S. categories should not automatically be assumed to exist in the affected Ontario files, but they demonstrate why case-management data can be particularly sensitive. Court records may combine ordinary identifying information with details arising from medical, family, employment, criminal or other deeply personal circumstances.
The Breach Happened in the Vendor’s Environment, Not Ontario Court Networks
Both Thomson Reuters and Ontario’s judiciary have stressed a critical technical distinction: the incident was detected within a Thomson Reuters cloud environment. Officials say it was not caused by weaknesses in the networks, systems or data-security measures of the affected courts themselves. C-Track remained operational, and the three Ontario Chief Justices said the incident did not impair the judiciary’s ability to continue hearing and deciding cases.
That distinction does not make the exposure insignificant. It instead highlights the dependence of modern public institutions on outside technology providers. Thomson Reuters markets C-Track as a web-based court-management platform capable of handling filings, case information, scheduling, docket materials, party information, reporting and document management. When a centralized provider manages information for multiple judicial systems, a security incident at that provider can potentially reach numerous institutions without attackers having to penetrate each courthouse network separately.
The “11 States” Count Has Become More Complicated
Initial reporting, including Reuters, described the breach as involving court systems in 11 U.S. states: Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire and Wyoming, along with the U.S. Virgin Islands. That is the footprint reflected in the headline and in Thomson Reuters’ main U.S. notification page at the time of reporting.
However, subsequent government disclosures complicate that number. The Oregon Judicial Department separately confirmed that information from the system used by Oregon’s Supreme Court and Court of Appeals was involved. A version of the C-Track notice republished by the North Dakota courts also lists Oregon Appellate Courts among affected systems. Recent cybersecurity reporting therefore describes the footprint as reaching at least 12 U.S. states. The evolving count illustrates why breach totals can change as vendors, customers and forensic investigators reconcile affected databases across different jurisdictions.
Court Services Continued Despite the Security Incident
Unlike cyberattacks that shut down government networks or force agencies back to paper-based processes, this incident did not produce a reported operational collapse. Thomson Reuters says C-Track experienced no operational disruption, while Ontario’s Chief Justices said the courts remained capable of carrying out their normal judicial responsibilities. U.S. court systems including North Dakota and Nevada similarly reported that their services were continuing.
That is reassuring from an access-to-justice perspective, but availability is only one measure of cybersecurity. Information can be accessed or copied without making a system unusable. In this case, the central concern is confidentiality rather than a prolonged service outage. Thomson Reuters also says it has found no evidence that systems processing financial transactions related to court proceedings were affected. The investigation therefore differs from a ransomware scenario in which attackers primarily encrypt systems or stop operations, although the company has not publicly identified who accessed the files or described the attacker’s motive.
The Incident Shows How Third-Party Risk Can Cross Borders Quickly
C-Track’s footprint helps explain why a compromise involving one supplier can become an international issue. Thomson Reuters offers the software to appellate, trial and specialty courts, with functions ranging from document storage to docketing and case-management workflows. The same broader technology ecosystem can therefore hold information belonging to many separate courts and governments.
Canada’s Centre for Cyber Security has repeatedly identified suppliers and service providers as an important part of cyber-risk management. Its guidance recommends assessing the security practices of contractors, reviewing supply-chain risks and planning for the possibility that an external provider could be compromised. The C-Track incident provides a concrete example of that challenge. Ontario courts did not need to suffer a direct network intrusion for provincial information to become involved. Once court data was stored in an outside environment, the security of that environment effectively became part of the courts’ own information-security perimeter.
Ontario’s Privacy Rules Make the Unanswered Questions Important
Ontario strengthened privacy-breach requirements for provincial public institutions under the Freedom of Information and Protection of Privacy Act in July 2025. Institutions must assess whether a breach creates a “real risk of significant harm,” and certain incidents must be reported to the Information and Privacy Commissioner of Ontario while affected people must be notified as soon as feasible when the legal threshold is met.
Determining that risk requires information that remains incomplete in the C-Track case. Thomson Reuters Canada and the courts have not publicly established the total number of affected individuals, the precise personal information contained in each compromised Ontario file or whether particular people will require direct notification. Those details can materially change the seriousness of a breach. A file containing only a name carries a different risk profile from one combining identity information with confidential medical, family or legal records. The continuing forensic review is therefore central to Ontario’s response.
Thomson Reuters Says It Has Added Safeguards and Found No Misuse So Far
Thomson Reuters says it responded to the discovery by containing the activity, securing the C-Track environment, involving outside cybersecurity specialists and notifying law enforcement. The company also says additional safeguards and security enhancements were implemented to reduce the risk of another similar incident. Ontario’s courts are working with the provincial government’s Cyber Security Division to review those measures and assess C-Track’s ongoing security.
Officials have also emphasized what investigators have not found. Thomson Reuters Canada says there is no evidence to date that the incident has resulted in identity theft, while its broader notifications say there is no known fraud or misuse of the affected information. Those statements are encouraging but should not be interpreted as proof that exposed information can never be misused. Data obtained during a breach may remain valuable for long periods, particularly where identifying details do not change easily. The investigation and monitoring therefore remain important even without confirmed fraud.
Potentially Affected Canadians Are Being Offered Additional Protection
Thomson Reuters Canada established a dedicated information site for people concerned about the incident and announced plans for a Canadian toll-free contact centre staffed by trained representatives. The centre was scheduled to begin operating on September 4. The Canadian notification also says potentially affected individuals can receive a complimentary 12-month membership in TransUnion’s myTrueIdentity credit-monitoring and identity-theft protection service, with enrollment information provided through the incident-response process.
For someone who has participated in an Ontario court proceeding—or has simply been named in court documents—the uncertainty may be the most frustrating part. Officials currently cannot say that every such person was affected, and the courts specifically warn only that personal information “could” have been involved. Until individual impact is established, the most practical approach is to rely on the dedicated C-Track information channel, remain alert for suspicious financial or identity activity and treat unsolicited breach-related messages cautiously. The next major development will be greater clarity about exactly whose information was taken.