Thomson Reuters Reveals Court Case Management System Hack | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Media/technology company Thomson Reuters has reported a cybersecurity incident involving its case management system.

The incident was detected in 11 U.S. states, as well as in Canada and the U.S. Virgin Islands and involved the company’s C-Track tool, used for managing court cases, Reuters — itself a division of Thomson Reuters — reported Thursday (Sept. 3).

The company confirmed for the news outlet that it had taken containment and security steps and notified affected customers.

“There has been no operational disruption to C-Track as a result of this incident,” a Thomson Reuters spokesperson said. “Our products and services remain fully operational and are safe to continue to use. ⁠Independent cybersecurity experts assisted in the investigation and validated the remediation measures implemented.”

According to the report, an investigation found that an unauthorized party accessed certain C-Track files in March, and that some court records were “affected,” including ones featuring names and personal information.

We’d love to be your preferred source for news.

Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

The breach impacted court systems of Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire, Wyoming and the U.S. Virgin Islands, along with those of the Court of Appeal for Ontario, the Ontario ​Superior Court of Justice and the Ontario Court of Justice.

A statement from those courts said Thomson Reuters discovered unauthorized activity in one of its cloud environments, and had taken measures to contain ⁠the activity, in cooperation with Ontario’s Ministry of the Attorney General ⁠and the courts.

“We are advised that Thomson Reuters responded by taking ​steps to contain the activity, engaging external cybersecurity experts to advise and investigate, notifying law ​enforcement, and securing the C-Track environment,” the statement said.

In other cybersecurity news, PYMNTS wrote about the way security needs are shifting at a time when companies have “built interconnected enterprises” but still use incident-response models that “largely assume discrete incidents.”

While traditional cyber planning centered around infrastructure questions like, “What systems could be compromised,” companies have spent years making vast webs of connections, including cloud environments, data platforms and payment systems.

“The emerging risk for CFOs and CISOs is therefore not simply a larger attack surface,” the report said.

“It is a larger obligation surface: every system an autonomous process touches can potentially bring another customer agreement, regulator, insurer, jurisdiction, disclosure requirement or business dependency into an incident. The administrative cost of a cyberattack correlates not only with the amount of data compromised, but with the connectivity of the company experiencing it.”

——————————————————-


Click Here For The Original Source.