Thomson Reuters disclosed an investigation into unauthorized access to files from its C-Track court case-management platform. Reuters reporting said some affected records contained personal information. The company’s incident page provides its own updates and information for affected customers.
The incident underscores how a service provider can hold sensitive records on behalf of public institutions. The scope, affected customers and specific information involved should be taken from the company’s notices as its investigation proceeds; the initial report alone does not establish that every C-Track customer was affected.
What organizations should take from it
Customers using third-party case systems should know how quickly a vendor will notify them, what records are in scope and how access is being contained. They should also be prepared to follow their own notification and records-protection obligations if their data is implicated.
The investigation remains the key source
In a developing incident, early details can change. Thomson Reuters’ security update is the primary reference for new findings and customer guidance; Reuters’ report supplies independent coverage of the disclosure.

