Full Report
For the latest discoveries in cyber research for the week of 7th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Thomson Reuters, a global information and technology company, has disclosed a breach of its C-Track court case-management platform affecting courts across 11 US states and Canada. An unauthorized party obtained C-Track files […] The post 7th September – Threat Intelligence Report appeared first on Check Point Research.
Analysis Summary
# Incident Report: Compromise of Thomson Reuters C-Track Court Management Platform
## Executive Summary
Thomson Reuters disclosed a significant security breach involving its C-Track court case-management platform, which serves judicial systems in the US and Canada. An unauthorized party gained access to the platform, resulting in the exfiltration of sensitive court records and personal identifiable information (PII). The breach has a broad geographical impact, affecting courts across 11 US states and various Canadian jurisdictions.
## Incident Details
- **Discovery Date:** September 3, 2026 (Disclosure date)
- **Incident Date:** Prior to September 3, 2026
- **Affected Organization:** Thomson Reuters
- **Sector:** Information Technology / Legal Services
- **Geography:** 11 US States and Canada
## Timeline of Events
### Initial Access
- **Date/Time:** Not specified (Pre-September 2026)
- **Vector:** Unauthorized access to the C-Track platform.
- **Details:** An unauthorized party bypassed security controls to access the C-Track environment.
### Lateral Movement
- **Details:** The threat actor navigated the C-Track platform to access files associated with multiple different court jurisdictions across North America.
### Data Exfiltration/Impact
- **Details:** The unauthorized party obtained C-Track files. These files contained sensitive court records, including names and other unspecified personal information.
### Detection & Response
- **How it was discovered:** Internal detection systems (implied by Thomson Reuters' disclosure).
- **Response actions taken:** Thomson Reuters initiated a disclosure process to notify affected jurisdictions and the public.
## Attack Methodology
- **Initial Access:** Unauthorized access to the C-Track application/platform.
- **Persistence:** Not disclosed.
- **Privilege Escalation:** Not disclosed.
- **Defense Evasion:** Not disclosed.
- **Credential Access:** Not disclosed.
- **Discovery:** Mapping of C-Track file structures and court records.
- **Lateral Movement:** Movement across multi-tenant or multi-jurisdictional data segments within the C-Track platform.
- **Collection:** Gathering of court records and PII.
- **Exfiltration:** Transfer of C-Track files to an unauthorized external location.
- **Impact:** Compromise of judicial data integrity and privacy of individuals involved in court cases.
## Impact Assessment
- **Financial:** Costs associated with forensic investigation, legal notification, and potential regulatory fines.
- **Data Breach:** Sensitive court records and PII (names, etc.) belonging to users in 11 US states and Canada.
- **Operational:** Potential disruption to court case management and legal proceedings.
- **Reputational:** High impact due to the sensitive nature of judicial data and the global scale of Thomson Reuters.
## Indicators of Compromise
- **Network indicators:** None disclosed in the summary report.
- **File indicators:** None disclosed.
- **Behavioral indicators:** Unusual access patterns to C-Track database files or bulk download activity.
## Response Actions
- **Containment measures:** Details not provided, but typically involve disabling compromised accounts and isolating affected servers.
- **Eradication steps:** Vulnerability remediation within the C-Track platform.
- **Recovery actions:** Notification of affected court systems and individuals; restoration of system integrity.
## Lessons Learned
- **Key takeaways:** Multi-tenant platforms used for sensitive government/judicial data are high-value targets.
- **What could have been done better:** Enhanced monitoring for bulk data exfiltration and stricter access controls between different jurisdictional data sets (siloing).
## Recommendations
- **Prevention measures:**
- Implement Multi-Factor Authentication (MFA) for all platform access.
- Conduct regular security audits and penetration testing specifically for the C-Track platform.
- Implement Data Loss Prevention (DLP) tools to flag or block the unauthorized export of large volumes of court records.
- Ensure robust encryption of data at rest and in transit.