Saturday, September 12, 2026

“Ontario Courts’ Data Breach Exposes Personal Details”

Share

Ontario’s top judges are cautioning individuals in the province who have interacted with the legal system that their personal details may have been compromised in a cyber breach. A notice informing the public about the incident was issued online on September 2 by Ontario Chief Justice Michael H. Tulloch, alongside Patrick J. Boucher, chief justice of the Ontario Superior Court, and Sharon M. Nicklas, chief justice of the Ontario Court of Justice.

The breach occurred on an online case-management platform named C-Track, owned by Thomson Reuters Canada Limited, which is utilized by the Court of Appeal for Ontario, the Ontario Superior Court of Justice, and the Ontario Court of Justice for storing and handling court documents and records.

On June 30, the company discovered “unauthorized activity” within one of its cloud environments, prompting them to involve law enforcement and initiate an investigation. The breach was found to have begun in March, with court records linked to the aforementioned Ontario courts being accessed by an unauthorized entity.

Although data from the courts was compromised, it was clarified that the breach did not originate from the courts’ networks or data security. The company’s website addressing the incident stated that certain confidential or sealed information may have been impacted for specific affected courts, potentially exposing names and other personal data. The extent of the accessed records and the nature of the personal information were not disclosed.

To enhance security, additional cybersecurity measures have been implemented to safeguard C-Track systems and data. Despite the breach, the company assured that its products and services remain operational and secure for continued use.

A call center has been set up to handle inquiries, and credit monitoring is being provided to affected individuals. However, the company did not disclose the exact number of people from Ontario who might be at risk due to the cyber incident.

Furthermore, the statement from the chief justices emphasized the ongoing uncertainty regarding the contents of the accessed files and the possibility of personal information being involved for individuals connected to court proceedings or documents. The statement also reassured the public of the courts’ commitment to transparency, privacy, and security, emphasizing collaborative efforts with the government of Ontario to bolster security measures and mitigate similar incidents in the future.

In a related development, the cybersecurity breach not only affected the three Ontario courts but also impacted court systems in various U.S. states and territories utilizing C-Track, including Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming, and the U.S. Virgin Islands. Personal data such as driver’s license numbers, social security numbers, and medical information may have been exposed in the U.S. breach. Statements from affected jurisdictions indicated that the compromised records spanned from 2002 to 2015 in some cases.

Read more

Local News