Thomson Reuters C-Track Platform Experiences Data Breach Affecting U.S. Appellate Courts
Thomson Reuters' C-Track case management platform, used by appellate courts in a dozen U.S. jurisdictions and Ontario, Canada, experienced a cybersecurity incident. An unauthorized party accessed certain C-Track files in March, though the activity was not detected until June 30. Public disclosure of the breach occurred on September 2, more than five months after the initial access. The affected U.S. jurisdictions include Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, Wyoming, and the U.S. Virgin Islands. Minnesota's judicial branch also reported an exposure. The compromised files contain sensitive personal information such as names, Social Security numbers, driver’s license numbers, medical information, dates of birth, and health insurance information. Some confidential or sealed documents may also have been accessed. Thomson Reuters has stated that the platform itself remained operational and that they engaged outside cybersecurity experts a...