Software breach affects three Pa. courts and Environmental Hearing Board
West Publishing, a division of Thomson Reuters, said it detected unauthorized activity involving its C-Track case management system June 30.
Three Pennsylvania courts and the state Environmental Hearing Board were hit by a cybersecurity incident affecting case management software that may have compromised individuals personal information.
West Publishing, a division of Thomson Reuters, said it detected unauthorized activity involving its C-Track case management system June 30. It announced the breach, which had been ongoing since March, on Sept. 2.
It affected more than two dozen courts nationwide including the Allegheny County, Monroe County and Washington County common pleas courts and the state Department of Environmental Protection’s (DEP) Environmental Hearing Board, which handles appeals to environmental permitting decisions.
Court administrators in Allegheny, Monroe and Washington counties did not respond to requests for comment or referred questions to the Pennsylvania Administrative Office of the Courts (AOPC).
A spokesperson for the AOPC said questions about the breach, including the scope and potentially affected information,should be directed to Thomson Reuters. The DEP did not immediately respond to questions.
SUBSCRIBE: GET THE MORNING HEADLINES DELIVERED TO YOUR INBOX.
Thomson Reuters said in a statement that it has notified all affected customers.
“There has been no operational disruption to C-Track as a result of this incident. Our products and services remain fully operational and are safe to continue to use. Independent cybersecurity experts assisted in the investigation and validated the remediation measures implemented,” a company spokesperson said.
In a notice online, West Publishing said the company promptly started an investigation into the incident, engaging law enforcement and third-party experts, and took steps to contain the unauthorized activity and its systems.
Based on the investigation, West said, a subset of court records was affected which could include individuals’ names, Social Security numbers, driver’s license numbers, medical information, date of birth and health insurance information.
Confidential, redacted or sealed court information may also have been exposed in certain courts, according to the notice.
“While these courts’ data was affected, the incident was not caused by the courts’ networks, systems or data security. There is no evidence that systems used to process financial transactions were impacted by the incident,” West said.
The company said it has no evidence the incident led to any fraud or misuse of information and it has undertaken significant mitigation steps to minimize the risk of fraud or misuse.
West said it has undertaken additional security measures to improve the security of its systems and data. It also advised individuals who may have been affected to remain alert.
It offered support through a phone number, 833-918-5294, and complimentary access to the Experian credit reporting bureau’s identity protection service. More information is available at https://www.ctracknotification.com/