Ontario's chief justices say court records from all three provincial courts were taken in a breach of Thomson Reuters' C-Track
Thomson Reuters says an unauthorized party held C-Track Canada files from March until the activity was detected on 30 June, and that confidential, redacted or sealed material may be among them; the Ministry of the Attorney General was not told until 23 July. CBC News reported the courts' warning on 9 September, a week after it was issued, without setting beside it the $166-million contract that put Ontario's case records on the vendor's platform in the first place.
What funded newsrooms reported
Canada's funded newsrooms - the outlets that draw on public or regulated money, from CBC's parliamentary appropriation to the Google payments the Globe and Mail and Postmedia receive under the Online News Act - had this one available to them from the start, because the wire moved it. Reuters carried Thomson Reuters' disclosure on 2 September, the same day Ontario's three chief justices published their statement, and the Reuters item named the Court of Appeal for Ontario, the Ontario Superior Court of Justice and the Ontario Court of Justice. It quoted the company saying “there has been no operational disruption to C-Track as a result of this incident” and that its products “remain fully operational and are safe to continue to use”.
CBC News reported it in its own right on 9 September, seven days later, under the headline “Ontario courts warn personal information may be caught up in cyberattack”. The piece is accurate and it carries the hard line: the company “detected ‘unauthorized activity’ within one of its cloud environments on June 30”; the three courts “all use C-Track to store and manage court documents and records”; and “certain confidential, redacted or sealed information may have been impacted”. It reports that credit monitoring is being offered and that a call centre is taking inquiries, and quotes the courts saying “we remain committed to transparency”. It also sets out the American side of the same intrusion - appellate courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee and Wyoming, plus the US Virgin Islands.
Searches this week did not turn up original Ontario reporting on the chief justices' statement from Global News, CTV News, the Globe and Mail, the Toronto Star or the Postmedia titles; if any of them ran it, it did not surface. That is a narrower charge than it sounds. A statement published on the Wednesday before the Labour Day long weekend, about a vendor rather than a government, is the kind of item newsrooms of every description miss.
What was already public
- 1.Ontario's three chief justices - Michael H. Tulloch of the Court of Appeal for Ontario, Patrick J. Boucher of the Superior Court of Justice and Sharon M. Nicklas of the Ontario Court of Justice - issued a joint public statement on 2 September 2026 saying Thomson Reuters detected unauthorized activity on 30 June 2026 and notified the Ministry of the Attorney General on 23 July 2026.Public Statement by Ontario's three Chief Justices Regarding a Cybersecurity Incident, 2 September 2026
- 2.The statement says that “if individuals have been involved in court proceedings or may have been mentioned in court documents, it is possible that some personal information relating to them could have been involved”, that there is “no evidence to date that the incident has resulted in any identity theft”, that no financial transaction systems were affected, and that C-Track “remains operational and safe to use”.Public Statement by Ontario's three Chief Justices Regarding a Cybersecurity Incident, 2 September 2026
- 3.Thomson Reuters' own notification page says that “in March 2026, an unauthorized party obtained certain C-Track Canada files”, that “a subset of court records were affected, some of which could potentially contain individuals' names and personal information”, and that “certain confidential, redacted or sealed information may have been impacted”.C-Track Canada notification, Thomson Reuters
- 4.The same page offers a 12-month subscription to TransUnion's myTrueIdentity service at no cost, tells people to “ensure you enroll by December 31, 2026”, and gives a call centre number, 1-833-918-4543, open Monday to Friday between 8:00 am and 8:00 pm Eastern.C-Track Canada notification, Thomson Reuters
- 5.In July 2023 the Ontario government announced it was investing $166 million to deliver legal services online and that Thomson Reuters had been awarded the contract to deliver the digital justice platform under the Courts Digital Transformation initiative, first announced in November 2021 as part of the Justice Accelerated Strategy; Attorney General Doug Downey said Ontario was “one step closer to a digital justice system that helps people resolve legal matters easier and faster”.Government of Ontario news release, Ontario Investing in Digital Justice Platform, July 2023
- 6.No count of affected individuals has been published: the investigation is still determining “the number of individuals whose information may have been impacted”.Infosecurity Magazine, US and Canadian Court Records Breached Following Thomson Reuters Incident, 2 September 2026
What the independents said
Outside that funding - no appropriation, no Heritage program, no journalism labour tax credit, no Online News Act money - the piece that put the breach next to the contract came from Juno News, which says on its own about page that it is “entirely 100% funded by our audience and our ad reads” and does “not take any grants or bailout money from the government”. Melanie Bennet's 7 September piece runs under the headline “Hackers obtain Ontario court files in $166M digitization project” and states plainly that “Ontario contracted Thomson Reuters to provide the $166 million Courts Digital Transformation project” and that “it includes C-Track, a web-based case management system that replaced the province's older platform”. Bennet notes the full scope of the breach remains unclear months after it happened.
The Canadian Bar Association's National Magazine got there first among Canadian outlets that treated it as a courts story rather than a corporate disclosure. Dale Smith reported the hack on 4 September - two days after the statement and five before CBC - and was alone in asking practitioners what it means for people whose files are in the system. Brent Arnold of INQ Law told him that “organizations are very dependent on their vendors, so it points to the real importance of having robust cybersecurity in those vendors”; Jessyca Greenwood, vice-president of the Criminal Lawyers' Association, was also quoted.
The contract itself drew independent scrutiny three years ago. Writing on Substack in August 2023, Sean Bray described Ontario “handing a juicy $166 million contract to Thomson Reuters” and called it part of “the Ford government's increasing privatization of supposedly public services”. That was a political argument about outsourcing, not a security prediction, and nothing in it anticipated this incident.
The gap
CBC's report, the only original Ontario account from a large funded newsroom that surfaced this week, did not include the $166-million contract that put the province's case records on a private vendor's platform, the 23 days between detection on 30 June and notification of the Ministry of the Attorney General on 23 July, or the 31 December enrolment deadline a reader would need in order to claim the credit monitoring.
The accounts outside that funding named the contract but did not carry the practical detail either - the call centre number, the credit-monitoring offer and its deadline - and none of them, funded or not, has established how many Ontarians are in the affected files, which is the number the whole story turns on.
The caveat — against our own framing
The case against this issue's own framing is a strong one. Nothing here shows a funded newsroom got anything wrong: CBC's piece was accurate, carried the sealed-records line and reached more Ontarians than every other account combined, and running a story seven days after a statement issued the Wednesday before the Labour Day weekend is lateness, not suppression. The $166-million contract is real, but its link to the breach is thematic rather than causal - nothing published so far suggests the intrusion exploited anything specific to the Ontario project rather than the shared C-Track cloud environment that also served appellate courts in eleven American states. And the sharpest independent line on that contract, Sean Bray's in 2023, was an argument about privatization that happens to read well in hindsight, which is not the same as having been right about security.
Sources
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
One story per issue. Every claim sourced.
No tracking pixels, no partner mail, one unsubscribe link in every issue.
By subscribing you agree to receive Second Reading by email. We store your address and the record of your consent, nothing else. Privacy.