Ontario’s chief justices are warning people in the province who have been involved in the court system that their personal information may have been stolen in a cyberattack.
A statement notifying the public about the incident was posted online on Sept. 2, by Ontario Chief Justice Michael H. Tulloch, along with Patrick J. Boucher, chief justice of the Ontario Superior Court, and Sharon M. Nicklas, chief justice of the Ontario Court of Justice.
It says the breach involved an online case-management platform called C-Track, which is owned by Thomson Reuters Canada Limited.
The Court of Appeal for Ontario, the Ontario Superior Court of Justice and the Ontario Court of Justice all use C-Track to store and manage court documents and records, according to the notice.
The company detected “unauthorized activity” within one of its cloud environments on June 30. It contacted law enforcement and began its own investigation, which determined that the breach started months earlier, in March, and that court records related to the Court of Appeal for Ontario, the Ontario Superior Court of Justice and the Ontario Court of Justice were obtained by “an unauthorized party.”
The company notes that data from the courts was affected but the incident was not caused by the courts’ networks or data security.
AI can make cyberattacks faster and smarter
“Certain confidential, redacted or sealed information may have been impacted for certain affected courts,” the company says on a website it has launched about the incident.
Names and other personal information were potentially accessed, it says, but it doesn’t specify what kind of personal information or how many records were accessed. It also doesn’t indicate how far back the records go.
Additional cybersecurity measures are now in place to better protect C-Track systems and data, the company said.
“Our products and services remain fully operational and are safe to continue to use,” the company said in a statement provided to CBC News.
A spokesperson for the company was not available for an interview.
Eastlink says data breach affects 75,000 customers
Personal information stolen in data breach last year at Autism Services of Saskatoon
In addition to the website, a call centre is operating to take inquiries, and credit monitoring is being offered to affected individuals.
The company did not provide an estimate of how many Ontarians could be vulnerable because of the cyberattack.
The statement from the chief justices says there’s still uncertainty about the exact contents of the files that may have been accessed.
“However, if individuals have been involved in court proceedings or may have been mentioned in court documents, it is possible that some personal information relating to them could have been involved in the incident,” the statement said.
Hundreds of ransomware attacks stopped each year, says Canada’s cybersecurity chief
The three Ontario courts weren’t the only ones impacted by the same cybersecurity incident. Court systems using C-Track in Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming were also involved. The U.S. Virgin Islands was also affected.
A website set up in the U.S. for those affected by the breach notes that some of the personal information that may have been accessed includes driver’s licence numbers, social security numbers and medical information.
A statement issued by the New Hampshire Judicial Branch indicates that records in its system affected by the breach cover a period between 2002 and 2015.
The statement from Ontario’s chief justices seeks to reassure the public that privacy and security are taken seriously by the courts.
“We remain committed to transparency,” the statement reads.
“Throughout this process, our priority is to ensure support for potentially affected individuals, safeguard information entrusted to the courts, and work collaboratively with the government of Ontario to strengthen security measures and reduce the risk of similar incidents in the future.”









