Sensitive court records and personal information were spilled from a data breach in the court system, which impacts at least 12 states in the U.S., including the U.S. Virgin Islands and Canada, Thomson Reuters announced on Wednesday.
The breach occurred in C-Track, a court case management software, run by one of Thomson Reuters’ subsidiaries.
The company remains silent on how the hackers accessed the program, who was responsible and how much data was compromised, as well as the number of individuals impacted.
Thomson Reuters stressed that the breach was within their own environment and “not related to security vulnerabilities in the networks, systems or data of the courts.”
The company discovered unauthorized access to its system on June 30, and it initiated an investigation alongside outside cyber security experts and law enforcement.
Their probe established that unauthorized intruders accessed some C-Track files in March.
Meanwhile, a separate disclosure by the Montana Supreme Court revealed that Thomson Reuters advised the state court officials that unauthorized access to C-Track persisted up to June, which means that hackers may have remained undetected within the system for several months.
The sensitive information spilled includes names, Social Security numbers, driver licenses, medical information, dates of birth, and health insurance.
Thomson Reuters added that confidential, redacted, or otherwise restricted information from court records may have been accessed in some jurisdictions, but the company confirmed that no abuse of the situation has occurred.
The data breach did not impact the operations of C-Track, which continues to function normally. Thomson Reuters implemented additional security measures, following the breach, after they were approved by outside cybersecurity experts, although the company did not disclose who they were.
The courts in the U.S. whose data is at risk, according to the company, are the appellate courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, South Carolina, Tennessee, and Wyoming. In addition, several Pennsylvania courts, 10 Ohio district courts of appeals, the Supreme Court, and the Superior Court of the U.S. Virgin Islands are also on the list.
The breach in Oregon Judicial Department added another state to the list, expanding the reach to at least 12 states.
Nevada officials reminded their residents that the types of data compromised differs from state to state, and that not all the data in each state is necessarily confidential or protected.
They added that, for example, in Montana, most of the data already was publicly available, but the state’s court system acknowledged the breach of the drivers’ licenses and dates of birth.
In addition, several of the jurisdictions were notified weeks after Thomson Reuters became aware of the security threat.
For example, the court administrator of Montana and the Ontario Ministry of the Attorney General were notified of the unauthorized access to the data on July 23.
The chief justices of Ontario agreed that it still remains unclear what information was at risk and how many people were impacted. Thomson Reuters notifies affected individuals that they can receive 12 months of free of credit monitoring and identity theft protection.
Read the original article: