Thomson Reuters reports cyber incident, says unauthorized party accessed files
Key Points
- The breach affected court systems in Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming, the U.S. Virgin Islands, and Ontario, Canada
- Thomson Reuters engaged external cybersecurity experts, notified law enforcement, and secured the C-Track environment, with no operational disruption to the platform
- A contact center will be established on September 4 to respond to inquiries, though the specific information compromised and the party responsible remain unclear
AI Summary
Thomson Reuters Reports Cybersecurity Breach Affecting Court Systems
Thomson Reuters disclosed a significant cybersecurity incident affecting its C-Track case management platform across 11 U.S. states, the U.S. Virgin Islands, and Canada. The unauthorized access was detected on June 30, though investigators later determined the breach occurred in March when an unauthorized party obtained certain C-Track files.
Affected Jurisdictions:
The breach impacted court systems in Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming, the U.S. Virgin Islands, and Ontario courts in Canada. The platform is used for digital court record management.
Compromised Data:
The investigation found court records were affected, including names and personal information of individuals involved in court proceedings or mentioned in court documents. Specific details about the extent of compromised information remain unclear.
Company Response:
Toronto-based Thomson Reuters confirmed it has taken containment and security measures, engaged external cybersecurity experts, and notified law enforcement. All affected customers have been notified. The company emphasized that C-Track remains fully operational with no service disruptions, and independent cybersecurity experts validated the remediation measures.
A dedicated call center will be activated on September 4 to respond to inquiries in both the U.S. and Canada.
Market Implications:
This incident raises concerns about data security in critical legal infrastructure and may prompt increased scrutiny of Thomson Reuters' cybersecurity protocols. The breach could lead to potential legal liabilities and reputational damage, though the company maintains operations remain unaffected.
The identity of the threat actors and full scope of compromised data have not been disclosed.
Model Analysis Breakdown
| Model | Sentiment | Confidence |
|---|---|---|
| GPT-5-mini | Bearish | 80% |
| Claude 4.5 Haiku | Bearish | 72% |
| Gemini 2.5 Flash | Neutral | 85% |
| Consensus | Bearish | 79% |