Ontario’s court system is grappling with a cybersecurity incident that may have exposed personal information belonging to individuals who have appeared in court proceedings or been named in court documents. The province’s three chief justices disclosed the breach in a joint statement posted on September 2, confirming that unauthorized access to a court records platform had occurred more than two months earlier.
The incident traces back to June 30, when Thomson Reuters Canada detected what it described as “unauthorized activity” on its C-Track case management platform — a system used by Ontario courts to store and manage documents and records. Once the intrusion was identified, Thomson Reuters moved to contain it and began assessing what data had been accessed, ultimately determining that some court information was among the compromised material.
The scope of what was exposed remains uncertain.
“Because there remains uncertainty about the exact content of the files that may have been accessed, it is still unclear what information may have been compromised,” the justices wrote. “However, if individuals have been involved in court proceedings or may have been mentioned in court documents, it is possible that some personal information relating to them could have been involved in the incident.” That caveat covers a broad population — anyone who has ever appeared before an Ontario court, been a witness, or simply been referenced in a filing.
The statement was issued jointly by Michael H. Tulloch, Chief Justice of Ontario; Patrick J. Boucher, Chief Justice of the Ontario Superior Court of Justice; and Sharon M. Nicklas, Chief Justice of the Ontario Court of Justice. Their public acknowledgment, while measured in tone, signals the seriousness with which the judiciary is treating the breach, given that court records routinely contain sensitive personal details — addresses, financial disclosures, testimony, and family information — that carry real risks if misused.
On the financial side, the justices offered a degree of reassurance, noting that there is currently no indication that any systems used to process financial transactions related to court proceedings were affected. They also confirmed that, to date, there is no evidence the incident has resulted in identity theft.
Thomson Reuters has since implemented additional safeguards and security enhancements to the C-Track platform, the justices added. The investigation, however, remains ongoing, meaning the full picture of what was accessed — and by whom — has yet to emerge.
Courts are among the most sensitive repositories of personal information held by any public institution. A breach of this kind raises legitimate questions about how private-sector vendors that manage public judicial infrastructure are vetted, monitored, and held accountable when something goes wrong. The two-month gap between the June 30 incident and the September 2 public disclosure will also draw scrutiny, even if some delay is common while investigations are underway.
For now, Ontarians who have had any involvement in court proceedings — as parties, witnesses, or simply as named individuals — are left in a state of partial uncertainty, waiting for an investigation to tell them what, exactly, was taken.
