
Personal, confidential and potentially sealed court information may have been accessed in third-party cloud compromise
Ontario’s court system is dealing with the fallout from a significant cybersecurity incident involving C-Track, a case-management platform operated by Thomson Reuters Canada Limited.
The platform is used by the Court of Appeal for Ontario, Ontario Superior Court of Justice and Ontario Court of Justice to store and manage certain court documents and records. Ontario’s three chief justices publicly disclosed the incident on September 2, 2026.
The breach did not originate from the courts’ own networks. Instead, unauthorized activity was detected within a Thomson Reuters cloud environment used by C-Track.
That distinction is important from a cybersecurity perspective. Organizations can have strong internal security controls and still face serious exposure when highly sensitive information is entrusted to an external cloud or software provider.
Attackers obtained C-Track files months before detection
Thomson Reuters detected unauthorized activity on June 30, 2026 and launched an investigation involving external cybersecurity specialists and law enforcement.
The investigation subsequently determined that an unauthorized party had obtained certain C-Track files months earlier, in March.
Ontario’s Ministry of the Attorney General was advised on July 23 that information associated with Ontario courts was among the affected data.
The exact amount of information accessed remains unclear.
Thomson Reuters says its investigation is continuing to determine the specific records involved, the types of personal information contained in them and the number of affected individuals.
Confidential, redacted and sealed information may have been exposed
The nature of court records makes this incident particularly sensitive.
According to the incident notification, affected files may contain names and other personal information. Certain confidential, redacted or sealed information may also have been involved.
Ontario’s courts have warned that anyone who has participated in a court proceeding — or who was simply mentioned in court documents — could potentially have personal information contained within the compromised records.
That potentially expands the affected population well beyond plaintiffs and defendants.
Court files can contain information involving witnesses, children, relatives, employers, medical professionals, financial institutions and other third parties.
Why stolen court data could be particularly valuable to attackers
The security risk goes beyond traditional identity theft.
Depending on the type of proceeding, court documents can contain addresses, dates of birth, financial information, medical information, family details, legal allegations and other information that would normally be difficult for a cybercriminal to obtain.
This information can be extremely useful for social engineering.
An attacker who knows the name of someone’s lawyer, the court handling their case, the nature of a proceeding or other non-public details could potentially create convincing phishing emails or impersonation attempts.
Instead of receiving an obvious generic scam, a victim could receive a message containing accurate information about an ongoing or previous legal matter.
That can make phishing much harder to recognize.
September 10 update: Court sign-in returning Microsoft authentication error
There is now another development worth watching.On September 10, 2026, an attempt to access an Ontario court case-management interface showed that the case list itself remained accessible, but attempting to authenticate through Microsoft resulted in a Microsoft Entra ID error.
The Microsoft sign-in page returned:
AADSTS700016 — Application with identifier was not found in the directory.
Microsoft describes AADSTS700016 as an authentication error indicating that the requested application could not be found within the specified Microsoft Entra tenant. Microsoft says this can occur when the application has not been installed or consented to, when its identifier has been misconfigured, or when an authentication request is being directed to the wrong tenant.
In this instance, the error references application identifier:
82052379-f4dc-4a82-bede-c743e13b3ca9
and Microsoft tenant:
b947250f-8b0e-43ad-a2a3-ee46b4802066
The error suggests that the authentication configuration used by the court portal is currently unable to locate the application it expects within that Microsoft tenant.
Is the sign-in problem related to the cyberattack?
At this stage, there is no public evidence confirming that the Microsoft authentication problem is directly related to the C-Track breach.
The timing nevertheless makes the issue notable.
Following a significant cybersecurity incident, organizations commonly rotate credentials, disable applications, change identity configurations, restrict access or rebuild integrations as part of containment and remediation.
It is therefore possible that the authentication error is the result of security changes being made following the incident.
It could also be an unrelated configuration problem.
Without confirmation from Ontario Courts or Thomson Reuters, the two issues should not be presented as definitively connected.
C-Track breach extends beyond Canada
Ontario was not the only jurisdiction affected.
The C-Track incident also affected court systems across multiple U.S. states as well as the U.S. Virgin Islands. Public disclosures have identified affected systems in jurisdictions including Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire and Wyoming.
U.S. notifications have indicated that information potentially involved in some jurisdictions includes highly sensitive data such as driver's licence numbers, Social Security numbers and medical information.
The specific data involved differs between jurisdictions and does not establish that the same categories were present in affected Ontario records.
Additional security measures introduced
Thomson Reuters says it contained the unauthorized activity and implemented additional safeguards and security enhancements following the incident.
Ontario’s courts say they are also working with the Ontario government's Cyber Security Division to review the response and assess the ongoing security of C-Track.
The official position remains that C-Track itself is operational and considered safe to use.
Thomson Reuters has established a Canadian information site and telephone support service for potentially affected individuals. It is also offering eligible individuals 12 months of TransUnion myTrueIdentity credit monitoring and identity-theft protection.
What potentially affected people should watch for
Anyone who has been involved in an Ontario court proceeding should be especially cautious about unexpected communications referring to a court case.
Be skeptical of emails, phone calls or text messages requesting passwords, Microsoft verification codes, banking information, payments or urgent action — particularly when the sender attempts to establish credibility by referencing genuine information about a legal proceeding.
Anyone who receives a direct breach notification should review the information provided, consider enrolling in the offered credit monitoring and watch financial and online accounts for unusual activity.
Multi-factor authentication should also be enabled on important accounts, and passwords used for sensitive services should never be reused elsewhere.
A reminder that third-party systems are part of the security perimeter
The C-Track incident illustrates one of the defining cybersecurity challenges facing governments and businesses.
Sensitive information no longer resides exclusively within an organization's own network.
Cloud services, case-management platforms, identity providers and other third-party systems effectively become part of the organization's security perimeter.
In this case, Ontario's courts say their networks were not responsible for the breach, but information entrusted to a technology provider was still exposed.
The continuing uncertainty surrounding the contents of the stolen files makes the incident particularly concerning.
And with court users now encountering an apparent Microsoft Entra authentication configuration problem only days after the breach became public, the technical response to the incident may still be evolving.
For affected individuals, the most important unanswered question remains the same:
Exactly what information did the attackers obtain?
Until that is known, anyone whose personal information may appear in Ontario court records should remain alert for phishing, impersonation and identity-related attacks that could make use of stolen court data.
0 Comments