TechNewsReel
Live

Ontario Court Records Exposed in Thomson Reuters C-Track Data Breach

A cybersecurity incident involving a third-party case-management system compromised sensitive judicial files across three major Ontario courts.

TechNewsReel Newsroom · September 11, 2026

A significant cybersecurity breach involving a third-party case-management platform has exposed sensitive records from three of Ontario's primary courts. The incident has raised serious concerns regarding the security of judicial data and the efficacy of court-ordered privacy protections.

The breach affected the Court of Appeal for Ontario, the Ontario Superior Court of Justice, and the Ontario Court of Justice. According to a notice posted on September 2, 2026, by Chief Justices Michael H. Tulloch, Patrick J. Boucher, and Sharon M. Nicklas, the vulnerability existed within C-Track, an online case-management system owned and operated by Thomson Reuters Canada Limited.

Investigations revealed a significant gap between the start of the intrusion and its discovery. Thomson Reuters detected "unauthorized activity" within one of its cloud environments on June 30, 2026. However, subsequent forensic analysis determined that the breach actually began months earlier, in March 2026. The exposed data includes general court records and personal information of individuals involved in the legal system.

The Risk to Sealed Records

The severity of this incident stems from the nature of the documents stored within C-Track. The Chief Justices warned that the breach may have compromised files that were explicitly marked as confidential, redacted, or sealed. In the judicial system, sealed records are legally protected from public view to ensure the safety of participants or to protect highly sensitive private information.

Because these protections are mandated by court order, the unauthorized exposure of such files represents a failure of the technical safeguards intended to uphold judicial mandates. The breach effectively bypasses the legal barriers designed to keep sensitive testimony, identities, and evidence out of the public domain.

Industry Implications

This incident highlights the systemic risk inherent in the judicial system's reliance on third-party SaaS (Software as a Service) providers for core infrastructure. While the courts utilize C-Track to streamline the storage and management of documents, the breach demonstrates that the security of the judiciary is only as strong as the vendors they employ.

For the legal industry, this serves as a critical reminder that cloud-based case management introduces a centralized point of failure. When a single platform serves multiple high-level courts, a single vulnerability can lead to a province-wide compromise of sensitive legal data, potentially impacting thousands of litigants and legal professionals.

Next Steps

Following the detection of the activity on June 30, Thomson Reuters contacted law enforcement and initiated an internal investigation. The courts continue to monitor the situation as the full extent of the accessed data is determined. It remains to be seen whether specific individuals will be notified of the exposure of their personal information or if further security audits of the C-Track platform will be mandated by the province.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.