Thomson Reuters confirmed that an unauthorized party accessed sensitive files from its C-Track case management platform, impacting appellate court systems across twelve US jurisdictions and Ontario, Canada.
Key Points
- The breach occurred in March, but Thomson Reuters did not detect the unauthorized cloud access until June 30.
- Compromised data includes Social Security numbers, driver’s license details, medical records, and potentially sealed or confidential court documents.
- Affected US jurisdictions include Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, Wyoming, and the US Virgin Islands.
- Minnesota’s judicial branch also reported an exposure, bringing the total number of impacted jurisdictions to at least thirteen.
- Thomson Reuters is providing twelve months of credit monitoring and identity theft protection to affected individuals.
- No group has claimed responsibility for the intrusion, and the company stated that C-Track operations remain functional.